Skip to content

Elasticsearch emitter

The Elasticsearch emitter writes newline-delimited bulk requests to an Elasticsearch-compatible /_bulk endpoint. It is intended for search and operational analytics destinations that accept the native bulk protocol.

- name: elasticsearch-security
  type: elasticsearch
  endpoint: "https://elasticsearch.example.com/security-logs/_bulk"
  index: "logstrm-security"
  batch:
    max_bytes: 5242880
    flush_interval: "5s"
  auth:
    type: basic
    username: "${ELASTIC_USERNAME}"
    password: "${ELASTIC_PASSWORD}"
  tls:
    verify: true

Operating notes

  • Use HTTPS and verify certificates in production.
  • Keep the endpoint flexible enough to include the target index or proxy path required by the cluster.
  • Monitor HTTP status, item-level bulk failures, retry counts and DLQ growth.
  • Do not assume a successful HTTP response means every bulk item succeeded; inspect destination response semantics in your integration tests.
  • Keep credentials in the environment or a secret-backed deployment configuration.