# Using Elasticsearch as an input Errors

**URL:** <https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400>\
**Category:** Logstash\
**Created:** [November 12, 2015, 10:43am UTC](https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400 "2015-11-12T10:43:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andy.barton](https://avatars.discourse-cdn.com/v4/letter/a/f19dbf/32.png) [@andy.barton](https://discuss.elastic.co/u/andy.barton)\
**Post date:** [November 12, 2015, 10:43am UTC](https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400/1 "2015-11-12T10:43:11Z")

</div>

Hopefully someone will be able to help with this as it is driving me mad at the moment!

I have successfully managed to load 2.8m records into an elasticsearch cluster using sql server as the source. I am now trying to copy the data from one index to a new index. If i try and use elasticsearch input i get a generic error of:

Error: [400] {"error":{"root\_cause":[{"type":"action\_request\_validation\_except  
ion","reason":"Validation Failed: 1: scrollId is missing;"}],"type":"action\_requ  
est\_validation\_exception","reason":"Validation Failed: 1: scrollId is missing;"}

I have tried various setting but i have been unable to get an input working for logshash using elasticsearch as the input even if i use a match\_all query. The input i am using at the moment is:

input {  
elasticsearch {  
hosts =\> "localhost"  
query =\> ' "fields": [  
"screendataid",  
"accountid",  
"feedtypeid",  
"sourceid",  
"externalfeedid",  
"url",  
"title",  
"description",  
"screenhtml",  
"screentext",  
"articledate",  
"createddate",  
"rowversion",  
"translatorlanguagecodeid",  
"tweetdataid",  
"articleimageid",  
"urlhash",  
"externalfeedidhash",  
"expirydate",  
"removaldate",  
"displaydomain"  
],  
"query": {  
"match": {  
"\_index": "screendata"  
}  
},  
"filter": {  
"term": {  
"accountid": "3"  
}  
}'  
}  
}

Am I just missing something?

---

<div class="post-metadata">

**Author:** ![benben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benben/32/6660_2.png) [@benben](https://discuss.elastic.co/u/benben)\
**Post date:** [December 16, 2015, 9:42am UTC](https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400/2 "2015-12-16T09:42:03Z")

</div>

Hi Andy,

this happens because your index is not existing. If this is the case, Elasticsearch is not returning any scroll id. Just create the index and run it again, it should work then.

b

---

<div class="post-metadata">

**Author:** ![krlplm](https://avatars.discourse-cdn.com/v4/letter/k/9fc29f/32.png) [@krlplm](https://discuss.elastic.co/u/krlplm)\
**Post date:** [November 1, 2016, 1:44pm UTC](https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400/3 "2016-11-01T13:44:20Z")

</div>

Hi,

I am working on Logstash and Elasticsearch on both V 2.4.

I also encountered the same error as above and got it fixed as the Index was not yet there for my other config as below who pulls data using Elasticsearch as input.

```
input {
 #Read all documents from Elasticsearch matching the given query
  elasticsearch {
   hosts => "localhost"
   index => "proxy_new_hash_gz*"
   query => '{ "fields": ["Fld1", "Fld2", "Fld3", "Fld4"], "query": { "match_all" : {} } }'
   }
}

 output {
  file {
    path => "/logs/Hashlogs-%{+YYYY-MM-dd-H}.gz"
    gzip => true
  }
}

```

However, I get the below error in the logstash logs,

> {:timestamp=\>"2016-11-01T18:28:29.237000+0530", :message=\>"A plugin had an unrecoverable error. Will restart this plugin.\n Plugin: \<LogStash::Inputs::Elasticsearch hosts=\>["localhost"], index=\>"proxy\_new\_hash\_gz\*", query=\>"{ \"fields\": [\"Fld1\", \"Fld2\", \"Fld3\", \"Fld4\"], \"query\": { \"match\_all\" : {} } }", codec=\>\<LogStash::Codecs::JSON charset=\>"UTF-8"\>, scan=\>true, size=\>1000, scroll=\>"1m", docinfo=\>false, docinfo\_target=\>"@metadata", docinfo\_fields=\>["\_index", "\_type", "\_id"], ssl=\>false\>\n Error: undefined method `' for nil:NilClass", :level=\>:error}

Could anyone suggest how to fix this please?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:31am UTC](https://discuss.elastic.co/t/using-elasticsearch-as-an-input-errors/34400/4 "2017-07-06T04:31:45Z")

</div>


