# Attempted to resurrect connection to dead ES instance, but got an error... Received fatal alert: bad\_certificate"}

**URL:** <https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708>\
**Category:** Logstash\
**Created:** [January 18, 2022, 3:35pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708 "2022-01-18T15:35:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [January 18, 2022, 3:35pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708/1 "2022-01-18T15:35:22Z")

</div>

Hello,

I wanted to run the old logstash config that once was working.

It is not working anymore I guess that because now Elasticsearch is set up with

```auto
xpack.security.transport.ssl.verification_mode: certificate

```

Logstah output config

```auto
output {
# file {
# path => "/etc/logstash/conf.d/tests/snmp.txt"
# }
 stdout { codec => rubydebug }
  elasticsearch {
        hosts => ["https://fqdn.local:9200"]
        index => "network-devices-%{+YYYY.MM.dd}"
        user => "${es_log}"
        password => "${es_pwd}"
        cacert => "/path/elastic-ca.crt"
        ssl=> true
      }
}

```

Error log

```auto
]# /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ -f /etc/logstash/conf.d/hostname/SNMP-CPU-hostname.conf
Using bundled JDK: /usr/share/logstash/jdk
OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.
Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties
[2022-01-18T16:21:40,445][INFO][logstash.runner] Log4j configuration path used is: /etc/logstash/log4j2.properties
[2022-01-18T16:21:40,455][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"7.16.3", "jruby.version"=>"jruby 9.2.20.1 (2.5.8) 2021-11-30 2a2962fbd1 OpenJDK 64-Bit Server VM 11.0.13+8 on 11.0.13+8 +indy +jit [linux-x86_64]"}
[2022-01-18T16:21:40,790][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2022-01-18T16:21:41,969][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600, :ssl_enabled=>false}
[2022-01-18T16:21:42,932][INFO][org.reflections.Reflections] Reflections took 66 ms to scan 1 urls, producing 119 keys and 417 values
[2022-01-18T16:21:45,059][INFO][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["https://fqdn.local:9200"]}
[2022-01-18T16:21:45,466][INFO][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/]}}
[2022-01-18T16:21:45,955][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:21:46,084][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>12, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>1500, "pipeline.sources"=>["/etc/logstash/conf.d/hostname/SNMP-CPU-hostname.conf"], :thread=>"#<Thread:0x3984f460 run>"}
[2022-01-18T16:21:47,113][INFO][logstash.javapipeline][main] Pipeline Java execution initialization time {"seconds"=>1.03}
[2022-01-18T16:21:47,158][INFO][logstash.inputs.snmp][main] using plugin provided MIB path /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-snmp-1.2.8/lib/mibs/logstash
[2022-01-18T16:21:47,181][INFO][logstash.inputs.snmp][main] using plugin provided MIB path /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-snmp-1.2.8/lib/mibs/ietf
[2022-01-18T16:21:49,485][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
[2022-01-18T16:21:49,538][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
{
      "system.memory.used.norm" => 0.53,
     "system.memory.free.bytes" => 853880248,
                  "ip.observer" => "10.10.10.10",
     "system.memory.used.bytes" => 976386924,
                   "@timestamp" => 2022-01-18T15:21:49.589Z,
            "system.cpu.norm.1" => 0.36,
                      "host.ip" => "10.10.10.10",
      "system.memory.free.norm" => 0.47,
                "host.hostname" => "hostname",
                         "tags" => [
        [0] "snmp",
        [1] "metrics"
    ],
    "system.memory.total.bytes" => 1830267172
}
[2022-01-18T16:21:51,162][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:21:56,348][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:22:01,516][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:22:06,675][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:22:11,831][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}
[2022-01-18T16:22:17,015][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :message=>"Elasticsearch Unreachable: [https://%251B%255BA%251Blogstash_writter:xxxxxx@fqdn.local:9200/][Manticore::ClientProtocolException] Received fatal alert: bad_certificate"}

```

ELK version: 7.16-2  
Logstash version: 7.16-3 (the message was the same on 7.16-2)

How can I make it work again?

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [January 19, 2022, 12:36pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708/2 "2022-01-19T12:36:14Z")

</div>

How can I replicate the configuration that I can provide for example like for the beats?

```auto
  hosts: ["https://fqdn:9200"]
  username: "${ES_LOG}"
  password: "${ES_PWD}"
  ssl.certificate_authorities: ["/path/elastic-ca.crt"]
  ssl.certificate: "/path/beats.crt"
  ssl.key: "/path/beats.key"
  ssl.key_passphrase: "${KEY_PWD}"

```

---

<div class="post-metadata">

**Author:** ![Adriann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adriann/32/77780_2.png) [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Post date:** [January 20, 2022, 3:19pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708/3 "2022-01-20T15:19:05Z")

</div>

After reading the docs 10 times I noticed the solution.

```auto
  hosts: ["https://fqdn:9200"]
  username: "${es_log}"
  password: "${es_pwd}"
  cacert => "/path/elastic-ca.crt"

  keystore => "/path/logstash.p12"
  keystore_password => "${key_pwd}"

  ilm_enabled => false
  manage_template => false

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2022, 3:19pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-received-fatal-alert-bad-certificate/294708/4 "2022-02-17T15:19:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
