---
title: "elasticsearch2: DEPRECATED - Send messages directly to Elasticsearch version 2.0 or higher"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# elasticsearch2: DEPRECATED - Send messages directly to Elasticsearch version 2.0 or higher

> **Warning:**
> This destination is deprecated and will be removed from a future version of AxoSyslog. We recommend using the [elasticsearch-http: Send messages to Elasticsearch HTTP Bulk API](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch-http/index.md) destination instead.

Starting with version 3.7 of AxoSyslog can directly send log messages to [Elasticsearch](https://www.elastic.co/products/elasticsearch), allowing you to search and analyze your data in real time, and visualize it with [Kibana](https://www.elastic.co/products/kibana).

Note the following limitations when using the AxoSyslog `elasticsearch2` destination:

- Since AxoSyslog uses Java libraries, the `elasticsearch2` destination has significant memory usage.

## Prerequisites

The Java implementation of this destination is no longer shipped with AxoSyslog: the `elasticsearch2` Java module isn’t part of the `axosyslog-mod-java` (Debian/Ubuntu) or `axosyslog-java` (RHEL and compatible distributions) package. Use the [elasticsearch-http: Send messages to Elasticsearch HTTP Bulk API](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch-http/index.md) destination instead.

## Declaration:

```shell
   @include "scl.conf"

    elasticsearch2(
        index("syslog-ng_${YEAR}.${MONTH}.${DAY}")
        type("test")
        cluster("syslog-ng")
    );
```

## Example: Sending log data to Elasticsearch version 2.x and above

The following example defines an `elasticsearch2` destination that sends messages in transport mode to an Elasticsearch server running on the localhost, using only the required parameters.

```shell
   @include "scl.conf"

    destination d_elastic {
        elasticsearch2(
            index("syslog-ng_${YEAR}.${MONTH}.${DAY}")
            type("test")
        );
    };
```

The following example sends 10000 messages in a batch, in transport mode, and includes a custom unique ID for each message.

```shell
   @include "scl.conf"

    options {
        threaded(yes);
        use-uniqid(yes);
    };

    source s_syslog {
        syslog();
    };

    destination d_elastic {
        elasticsearch2(
            index("syslog-ng_${YEAR}.${MONTH}.${DAY}")
            type("test")
            cluster("syslog-ng")
            client-mode("transport")
            custom-id("${UNIQID}")
            flush-limit("10000")
        );
    };

    log {
        source(s_syslog);
        destination(d_elastic);
        flags(flow-control);
    };
```

## Example: Sending log data to Elasticsearch using the HTTP REST API

The following example send messages to Elasticsearch over HTTP using its REST API:

```shell
   @include "scl.conf"

    source s_network {
        network(port(5555));
    };

    destination d_elastic {
        elasticsearch2(
            client-mode("http")
            cluster("es-syslog-ng")
            index("x201")
            cluster-url("http://192.168.33.10:9200")
            type("slng_test_type")
            flush-limit("0")
        );
    };

    log {
        source(s_network);
        destination(d_elastic);
        flags(flow-control);
    };
```

Verify the certificate of the Elasticsearch server and perform certificate authentication (this is actually a mutual, certificate-based authentication between the AxoSyslog client and the Elasticsearch server):

```shell
   destination d_elastic {
        elasticsearch2(
            client-mode("https")
            cluster("es-syslog-ng")
            index("x201")
            cluster-url("http://192.168.33.10:9200")
            type("slng_test_type")
            flush-limit("0")
            http-auth-type("clientcert")
            java-keystore-filepath("&amp;lt;path-to-your-java-keystore&amp;gt;.jks")
            java-keystore-password("password-to-your-keystore")
            java-truststore-filepath("&amp;lt;path-to-your-java-keystore&amp;gt;.jks")
            java-truststore-password("password-to-your-keystore")
        );
    };
```

- To install the software required for the `elasticsearch2` destination, see [Prerequisites](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/destination-elasticsearch2-prerequisites/index.md).
- For details on how the `elasticsearch2` destination works, see [How AxoSyslog interacts with Elasticsearch](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/destination-elasticsearch2-interaction/index.md).
- For the list of options, see [Elasticsearch2 destination options (DEPRECATED)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/reference-destination-elasticsearch2/index.md).

> **Note:**
> If you delete all Java destinations from your configuration and reload `syslog-ng`, the JVM is not used anymore, but it is still running. If you want to stop JVM, stop `syslog-ng` and then start `syslog-ng` again.

---

[Prerequisites](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/destination-elasticsearch2-prerequisites/index.md)

[How AxoSyslog interacts with Elasticsearch](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/destination-elasticsearch2-interaction/index.md)

[Client modes](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/destination-elasticsearch2-client-modes/index.md)

[Search Guard](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/syslog-ng-elasticsearch2-search-guard/index.md)

[Elasticsearch2 destination options (DEPRECATED)](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/configuring-destinations-elasticsearch2/reference-destination-elasticsearch2/index.md)

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
