---
title: "opensearch: Send messages to OpenSearch"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-opensearch/"
last_modified: "2026-08-05T15:08:09+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# opensearch: Send messages to OpenSearch

The `opensearch()` destination can directly post log messages to [OpenSearch](https://opensearch.org/) using its HTTP endpoint.

HTTPS connection, as well as password- and certificate-based authentication is supported. The content of the events is sent in JSON format.

## Prerequisites

- AxoSyslog version 4.4 or later.
- Install the `axosyslog-scl` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md). On [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md), the SCL files are part of the `axosyslog` base package.

  Your configuration must also contain `@include "scl.conf"`, which the default configuration file already does. If the SCL files are missing, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

  ```shell
  @include "scl.conf"
  ```

  The `opensearch()` driver is a reusable configuration snippet (SCL). For details on using or writing such configuration snippets, see [Reusing configuration blocks](https://axoflow.com/docs/axosyslog-core/4.28/chapter-configuration-file/large-configs/config-blocks/index.md). You can find its source in [scl/opensearch/opensearch.conf](https://github.com/axoflow/axosyslog/blob/main/scl/opensearch/opensearch.conf) on GitHub.
- This feature requires a separate module. Install the `axosyslog-mod-http` package on [Debian/Ubuntu](https://axoflow.com/docs/axosyslog-core/4.28/install/debian-ubuntu/index.md), or the `axosyslog-http` package on [RHEL and compatible distributions](https://axoflow.com/docs/axosyslog-core/4.28/install/rhel-fedora-almalinux/index.md). If the module isn’t installed, AxoSyslog fails to start with an [`unexpected LL_IDENTIFIER` error](https://axoflow.com/docs/axosyslog-core/4.28/chapter-troubleshooting-syslog-ng/unexpected-ll-identifier/index.md).

## Declaration:

```shell
@include "scl.conf"
# ...

d_opensearch {
    opensearch(
        index("<opensearch-index-to-store-messages>")
        url("https://your-opensearch-endpoint:9200/_bulk")
    );
};
```

## Example: Sending log data to OpenSearch

The following example defines an `opensearch()` destination, with only the required options.

```shell
@include "scl.conf"
# ...

destination opensearch {
    opensearch(
        index("<name-of-the-index>")
        url("http://my-elastic-server:9200/_bulk")
    );
};

log {
    source(s_file);
    destination(d_opensearch_http);
    flags(flow-control);
};
```

The following example uses mutually-authenticated HTTPS connection, templated index, and also sets some other options.

```shell
@include "scl.conf"
# ...

destination opensearch_https {
    opensearch(
        url("https://node01.example.com:9200/_bulk")
        index("test-${YEAR}${MONTH}${DAY}")
        time-zone("UTC")
        workers(4)
        batch-lines(16)
        timeout(10)
        tls(
            ca-file("ca.pem")
            cert-file("syslog_ng.crt.pem")
            key-file("syslog_ng.key.pem")
            peer-verify(yes)
        )
    );
};
```

---

[Batch mode and load balancing](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-opensearch/batch-mode/index.md)

[opensearch() destination options](https://axoflow.com/docs/axosyslog-core/4.28/chapter-destinations/destination-opensearch/reference-destination-opensearch/index.md)

Last modified August 5, 2026: [Small fixes and deduplications (99cac43a)](https://github.com/axoflow/axosyslog-core-docs/commit/99cac43a517770299b97c7ed360eb87af9fef5ab)
