# Sending JSON file to Elasticsearch via Logstash HTTP input plugin and Docker

**URL:** <https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967>\
**Category:** Logstash\
**Created:** [August 22, 2017, 7:29pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967 "2017-08-22T19:29:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![patchong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patchong/32/21352_2.png) [@patchong](https://discuss.elastic.co/u/patchong)\
**Post date:** [August 22, 2017, 7:29pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/1 "2017-08-22T19:29:03Z")

</div>

I have a JSON file I want to send to Elasticseaerch via Logstash’s Http input plugin. I also have Docker installed.

I'm just confused as to why I can't see the data I see the data I've sent in Kibana/Elasticsearch

This is my curl statement and response

![43 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37fb0139e93f0ca529931a2b608e0cc2dc4721b7.png)

This is my logstash.conf file

![22 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/6/96f24cbf761da39036246184e27b1ebb25082acf.png)

This is Docker

 ![00 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/6/462ba28737d4a66640d8abbb0118cfa4ee742670.png)

And VirtualBox

 ![07 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/6/3606e1008e49d4cd437ca49c166e27af00857f50.png)

---

<div class="post-metadata">

**Author:** ![patchong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patchong/32/21352_2.png) [@patchong](https://discuss.elastic.co/u/patchong)\
**Post date:** [August 23, 2017, 6:50pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/2 "2017-08-23T18:50:49Z")

</div>

@magnusbaeck @fbaligand

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [August 23, 2017, 9:54pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/3 "2017-08-23T21:54:47Z")

</div>

Some things :

- first, if you make a curl call with content referenced inside a file, you have to use @ char just before filename :  
`curl -v -H "content-type: application/json" http://localhost:12346 -d @'/path/to/file.json'`
- then I invite you in a first time to use this simple output to check what is logstash result (instead of elasticsearch) :

```auto
stdout {
		codec => rubydebug { metadata => true }
	} 

```

- then, are you sure your elasticsearch host is "elasticsearch:9200" and not "localhost:9200" ?
- finally, if you still have errors, check Logstash logs and provide it here.

---

<div class="post-metadata">

**Author:** ![patchong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patchong/32/21352_2.png) [@patchong](https://discuss.elastic.co/u/patchong)\
**Post date:** [August 25, 2017, 3:33pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/4 "2017-08-25T15:33:28Z")

</div>

This is my logstash.conf file now

 ![34 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b17925f2466161cc906d0a48ab2e2c8b9a8422cd.png)

And this is the curl command I'm using to send some dummy date

 ![04 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/3/637979f7c9b0115604351b56703cb209c19c3142.png)

I was reading, do I have to create an index first so the data can be stored somewhere. Right now, my endpoint is just 31311 but is that specific enough for when I'm posting.

Also how can I get the Logstash log. I installed ELK using Docker

Thanks

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [August 25, 2017, 8:52pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/5 "2017-08-25T20:52:16Z")

</div>

Docker documentation for Logstash is here :  
[https://www.elastic.co/guide/en/logstash/current/\_pulling\_the\_image.html](https://www.elastic.co/guide/en/logstash/current/_pulling_the_image.html)

You can see there that logs are generated here :  
/usr/share/logstash/logs

Concerning `stdout` result, you have to get Logstash process standard output.

Your http input configuration is enough for what you do.  
However, I invite you to clearly indicate header "Content-Type" in your curl request, it is important to indicate if your content is "text/plain" or "application/json". It is interpreted by logstash http input.

No you don't have to create an index first, because when you index a document in elasticsearch, if document index is missing, elasticsearch creates it automaticaly.

That said, I invite you to create index template first (to indicate mapping to elasticsearch), as indicated in my previous comment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2017, 8:52pm UTC](https://discuss.elastic.co/t/sending-json-file-to-elasticsearch-via-logstash-http-input-plugin-and-docker/97967/6 "2017-09-22T20:52:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
