Send messages to Elasticsearch data streams

AxoSyslog can send messages and metrics to Elasticsearch data streams to store your log and metrics data as time series data.

Prerequisites

Configuration

Minimal configuration:

Terminal window
@include "scl.conf"
# ...

destination d_elastic_data_stream {
  elasticsearch-datastream(
    url("https://elastic-endpoint:9200/my-data-stream/_bulk")
    user("elastic")
    password("ba253DOn434Tc0pY22OI")
  );
};

Options

Usually you just set the url(), user(), and password() options.

Since this destination is based on the http() destination, you can use the options of the http() destination if needed.

Last modified August 5, 2026: Small fixes and deduplications (99cac43a)