# After applied the tutorial "Getting start with Elasticsearch security" Logstash receive Syslog data but Kibana can’t show it

**URL:** <https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 25, 2020, 1:54pm UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666 "2020-11-25T13:54:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thelmo\_Henrique\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thelmo_henrique_sant/32/62803_2.png) [@Thelmo\_Henrique\_Sant](https://discuss.elastic.co/u/Thelmo_Henrique_Sant)\
**Post date:** [November 25, 2020, 1:54pm UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666/1 "2020-11-25T13:54:51Z")

</div>

Hi buddies!

I getting a problem after applying "Getting start with Elasticsearch security" to my environment. I followed this entire procedure:

> **[Asegura Elasticsearch con encripción TLS y control de acceso basado en roles](https://www.elastic.co/es/blog/getting-started-with-elasticsearch-security)**
>
> Asegura tus clusters de Elasticsearch, y los otros componentes del Elastic Stack, con TLS de nodo a nodo y control de acceso basado en roles (RBAC). Estas y más características ahora están disponibles de forma gratuita con la distribución...

And everything works fine.

Elasticsearch protected with user and password:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0d75a8fa5fa8479874307c2e95a14ec75fade5b.png)

Kibana protected with user and password:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e32f395178f4030fe15a32d291b9c0e834fd67b8.png)

An user created with all privileges:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/8/087b4897249d3872e5c5768ef50ffffadc61f2d6.png)

Kibana receiving beats data and showing at Discovery view: (meatricbeats for example):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7febe50bb4ed52f6566bf1781efc213851f44f90.png)

As we can see, everything works fine, except for Logstash. My logstash is configured to receive syslog data. Before applying the security settings, my environment was working fine, and I could see the data entering in Kibana at the Discovery view (logstash\*- index). Now, after applying the security settings, when I go to Discovery view, and select the index logstash-\*, I can't see the data:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/7/872a55e44daac4e6a523e20d8dd2d0be2bfbce7a.png)

If I run Logstash, I can see that the plugins are working fine because I still receiving syslog data without any error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7ce223f15e2ee6180cf4d0506e4f0e9ba677ae14.png)

But I don't know why Kibana doesn't receive the output anymore.  
Before the security setting, I could see all syslog output in Kibana.

This is my syslog.conf file:

```auto
input {
tcp {
port => 514
type => syslog
}
udp {
port => 514
type => syslog
}
}

filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program} %{GREEDYDATA:syslog_message}" }
add_field => ["received_at", "%{@timestamp}"]
add_field => ["received_from", "%{host}"]
}
date {
match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}
}
}

output {
elasticsearch { hosts => ["localhost:9200"] }
user => "elastic"
password => "secret"
}
stdout { codec => rubydebug }
}

```

Any idea of where is the problem?

I've tried to delete and create again logstash index but doesn't work.

Thanks in advance for the help.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 26, 2020, 12:52am UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666/2 "2020-11-26T00:52:03Z")

</div>

> [@Thelmo\_Henrique\_Sant](#):
>
> This is my syslog.conf file:

~~That config doesn't have an output section.~~  
~~Where's your config to send the data to Elasticsearch?~~

Sorry, the preformatted section didn't scroll correctly for me.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 26, 2020, 3:56am UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666/3 "2020-11-26T03:56:44Z")

</div>

> [@Thelmo\_Henrique\_Sant](#):
>
> ```auto
> output {
> elasticsearch { hosts => ["localhost:9200"] }
> user => "elastic"
> password => "secret"
> }
> 
> ```

Do your elasticsearch nodes has TLS on the `http` port?  
Specifically is `xpack.security.http.ssl.enabled` true in your `elasticsearch.yml` ?

If so, then you need to specify that here, either by setting

```auto
ssl => true

```

or

```auto
elasticsearch { hosts => ["https://localhost:9200"] }

```

> **[Elasticsearch output plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl)**

---

<div class="post-metadata">

**Author:** ![Thelmo\_Henrique\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thelmo_henrique_sant/32/62803_2.png) [@Thelmo\_Henrique\_Sant](https://discuss.elastic.co/u/Thelmo_Henrique_Sant)\
**Post date:** [November 30, 2020, 11:42am UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666/4 "2020-11-30T11:42:09Z")

</div>

Hi TimV,

I am not using SSL certificate. What I did was to follow the procedure fo the tutorial "Getting start with Elasticsearch".

I have these lines configured in my elasticsearch.yml:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a8708320f540f822e1ecd8d66b40965b206491d7.png)

according to this part of the procedure:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/8/6816d7658b96f8c37b0c44e21153ffa6c2511806.png)

I've solved the problem changing my "TCP Input Plugin" configuration:

> **[Tcp input plugin | Logstash Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html)**

To this one: "Syslog Input Plugin":

> **[Syslog input plugin | Logstash Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html)**

This is my configuration file now for syslog:

```auto
input {
  syslog {
    port => 12345
    codec => cef
    syslog_field => "syslog"
    grok_pattern => "<%{POSINT:priority}>%{SYSLOGTIMESTAMP:timestamp}"
  }
}

output {
elasticsearch {
hosts => ["localhost:9200"]
user => "elastic"
password => "secret"
}
}

```

As we can see, with this plugin Kibana can receive the data from Logstash:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/3613dfe9c4bb746a4af821cbaf4aa909b819eec9.png)

I still need to set some filters with Grok in my configuration file, but at moment, it's working fine.  
I don't understand why TCP Input plugin doesn't work with the security configuration applied. Maybe I am doing something wrong. Apparently, I am not passing the credentials right to send the data to elasticsearch (output parameters):

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af9c02c69de9c6ad8408cc7ea4a515ad183af83a.png)

Anycase, now it's working with "Syslog Input Plugin", but I would like to know, how to make it work with "TCP Input plugin".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2020, 11:42am UTC](https://discuss.elastic.co/t/after-applied-the-tutorial-getting-start-with-elasticsearch-security-logstash-receive-syslog-data-but-kibana-can-t-show-it/256666/5 "2020-12-28T11:42:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
