# Auditbeat sends unencrypted data

**URL:** <https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [July 31, 2020, 2:56pm UTC](https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366 "2020-07-31T14:56:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elk6/32/72282_2.png) [@elk6](https://discuss.elastic.co/u/elk6)\
**Post date:** [July 31, 2020, 2:56pm UTC](https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366/1 "2020-07-31T14:56:03Z")

</div>

I have two beats on each server. Filebeat and auditbeat. I set up filebeat output to logstash and auditbeat output to elasticsearch. Filebeat encryption works fine. Now I'm setting up auditbeat's encryption.

I have copied this output from filebeat to auditbeat.yml:

```
output.elasticsearch:               
  # Array of hosts to connect to.
  hosts: ["91.242.11.225:9200"] # Not the real IP

  # Protocol - either `http` (default) or `https`.
  #protocol: "https"

  # Authentication credentials - either API key or username/password.
  #api_key: "id:api_key"
  username: "elastic"
  password: "password" # Not the real password
  ssl.enabled: true
  ssl.certificate_authorities: ["/etc/elk/ca.crt"]

  # Certificate for SSL client authentication
  ssl.certificate: "/etc/elk/beats.crt"

  # Client Certificate Key
  ssl.key: "/etc/elk/beats.key"
  ssl.key_passphrase: "password" # Not the real password
  ssl.verification_mode: full

```

But when I ngep, I see it ships data to 9200 unencrypted. Am I missing something? Thanks ahead!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 4:56pm UTC](https://discuss.elastic.co/t/auditbeat-sends-unencrypted-data/243366/2 "2020-08-28T16:56:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
