# What is better Transport protocol or http with SSL for communcation between logstash and elasticsearch?

**URL:** <https://discuss.elastic.co/t/what-is-better-transport-protocol-or-http-with-ssl-for-communcation-between-logstash-and-elasticsearch/53686>\
**Category:** Logstash\
**Created:** [June 22, 2016, 4:19pm UTC](https://discuss.elastic.co/t/what-is-better-transport-protocol-or-http-with-ssl-for-communcation-between-logstash-and-elasticsearch/53686 "2016-06-22T16:19:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shankar\_roy](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@shankar\_roy](https://discuss.elastic.co/u/shankar_roy)\
**Post date:** [June 22, 2016, 4:19pm UTC](https://discuss.elastic.co/t/what-is-better-transport-protocol-or-http-with-ssl-for-communcation-between-logstash-and-elasticsearch/53686/1 "2016-06-22T16:19:41Z")

</div>

## What is better Transport protocol or http with SSL for communcation between logstash and elasticsearch?

According to the documentation at [Using Logstash with Shield | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/logstash.html)

> Connecting with Transport protocol

> When you set the protocol option to transport, Logstash communicates with the Elasticsearch cluster through the same protocol nodes use between each other. This **avoids JSON un/marshalling and is therefore more efficient.**

> In order to unlock this option, it’s necessary to install an additional plugin in Logstash using the following command to also get Shield compatibility within the transport protocol:

> bin/plugin install logstash-output-elasticsearch\_java  
> bin/plugin install logstash-output-elasticsearch\_java\_shield  
> This is only necessary if you want to use the transport protocol within Logstash. However, **it is recommended to use the default http protocol** , which means that you do not need to install any plugins, nor do you need to use the elasticsearch\_java output.

I also saw the documentation at [Talking to Elasticsearch | Elasticsearch: The Definitive Guide [2.x] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/_talking_to_elasticsearch.html)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 25, 2016, 11:06am UTC](https://discuss.elastic.co/t/what-is-better-transport-protocol-or-http-with-ssl-for-communcation-between-logstash-and-elasticsearch/53686/2 "2016-06-25T11:06:26Z")

</div>

I'd say HTTP because it is simpler.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/what-is-better-transport-protocol-or-http-with-ssl-for-communcation-between-logstash-and-elasticsearch/53686/3 "2017-07-06T04:50:52Z")

</div>


