# Can you put Logstash behind Nginx proxy?

**URL:** https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665
**Category:** Logstash
**Created:** [July 26, 2021, 8:15pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665 "2021-07-26T20:15:10Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [July 26, 2021, 8:15pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/1 "2021-07-26T20:15:10Z")

</div>

Hello,

Can you put Logstash behind Nginx proxy the same way you put Kibana behind an nginx proxy to use a custom domain with SSL? All this while also using HTTP Basic authentication with Nginx?

ElasticSearch, Kibana, and Logstash instances are v7.7 (single server), also runs Nginx with the proxy settings.

Filebeat also 7.7 on a different server that runs nginx where I want to "stash" the logs.

Both servers run Ubuntu.

I can access Kibana, and the elasticsearch Rest api via Nginx proxy just fine, but filebeat from the other server cannot connect to Logstash. (see my next reply)

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [July 27, 2021, 9:52am UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/2 "2021-07-27T09:52:23Z")

</div>

I've tried to put it into a Nginx stream block, but did not work.

```auto
stream {
    server {
        listen 443 ssl http2;
        server_name myserverdomain.tld;

        # ssl settings...

        proxy_pass http://127.0.0.1:5044;
    }
}

```

A filebeat (different server) that monitors Nginx access/error logs is reporting the bellow.

```
Jul 27 12:42:20 myhost filebeat[24668]: 2021-07-27T12:42:20.948+0300 INFO [publisher_pipeline_output] pipeline/output.go:111 Connection to backoff(async(tcp://myserverdomain.tld:443))

Jul 27 12:41:25 myhost filebeat[24668]: 2021-07-27T12:41:25.675+0300 ERROR [logstash] logstash/async.go:279 Failed to publish events caused by: lumberjack protocol error

Jul 27 12:40:49 myhost filebeat[24668]: 2021-07-27T12:40:49.485+0300 ERROR [logstash] logstash/async.go:279 Failed to publish events caused by: client is not connected
```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 27, 2021, 4:03pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/3 "2021-07-27T16:03:01Z")

</div>

That sounds like you are trying to use the HTTP protocol on one side of the proxy and the lumberjack protocol on the other. That is not going to work. You should be able to use a proxy or load balancer if you use HTTP, even with TLS, on both sides. It will then load balance connections.

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [July 27, 2021, 4:33pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/4 "2021-07-27T16:33:34Z")

</div>

I saw that about the load balancer on Nginx's website, but could not figure it out. Load balancer with just one instance? Is it just called "load balancer" ?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 27, 2021, 4:46pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/5 "2021-07-27T16:46:25Z")

</div>

If there is only one instance of logstash behind nginx then I think normal usage would be proxy rather than load balancer.

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [July 28, 2021, 6:30am UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/6 "2021-07-28T06:30:46Z")

</div>

Yes, I just cant figure it out. I keep getting that errors.

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [July 29, 2021, 12:32pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/7 "2021-07-29T12:32:05Z")

</div>

Can anyone shed some light ?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [July 29, 2021, 1:14pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/8 "2021-07-29T13:14:00Z")

</div>

Filebeat does not use HTTP, it uses a proprietary protocol over TCP, your proxy configuration is using HTTP, so it won't work, you need to change it.

I do not use nginx, but according to the [documentation](https://docs.nginx.com/nginx/admin-guide/load-balancer/tcp-udp-load-balancer/) you just need to remove any mention of http from your configuration. And as you are terminating the SSL connection at the nginx proxy, this is the [documentation](https://docs.nginx.com/nginx/admin-guide/security-controls/terminating-ssl-tcp/) about SSL.

Try the following configuration:

```auto
stream {
    server {
        listen 443 ssl;
        server_name myserverdomain.tld;

        # ssl settings...

        proxy_pass 127.0.0.1:5044;
    }
}

```

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [August 5, 2021, 8:34am UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/9 "2021-08-05T08:34:27Z")

</div>

Hey, thanks for your reply.

So... I'm still getting the errors. Is there a way I can confirm that the server running Filebeat can actually communicate with the server running Logstash? telnet or something?

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [August 5, 2021, 10:59am UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/10 "2021-08-05T10:59:13Z")

</div>

@leandrojmp's reply is partially my solution.

I managed to connect Filebeat to Logstash via Nginx TCP SSL termination, I just couldn't use port 443 (nor 5044). I setup a random port to listen to and it started forwarding with SSL. Probably not possible to use the same port to listen to on Nginx while having the same port used by Logstash (same machine)... maybe configuring logstash to start on a different port and use 5044 as a listening port with Nginx. But this is not a problem for me right now.

Now I need to figure out why Logstash, which sits on the same machine with the Elastic instance, is getting:

```auto
Encountered a retryable error. Will Retry with exponential backoff {:code=>403, :url=>"http://127.0.0.1:9200/_bulk"}

```

Probably some authentication issue.

I used logstash\_system user, maybe it needs a new user not that system reserved one. Who knows..

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 5, 2021, 1:01pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/11 "2021-08-05T13:01:06Z")

</div>

You can not use the same protocol and port twice on a server, so if nginx and logstash are on the same machine you will need different ports.

I would use 5044 for nginx and 50044 for logstash and to avoid confusion I would not use port 443 as port 443 is normally used for https.

Your other error is probably related to authentication, but I would recommend that you create another post on the forum if you can not fix it.

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [August 5, 2021, 1:04pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/12 "2021-08-05T13:04:05Z")

</div>

Yes, already figured everything and I'm getting logs on my Elastic instance 😃  
Thanks!

---

<div class="post-metadata">

### Author: ![droplet](https://avatars.discourse-cdn.com/v4/letter/d/bcef8e/32.png) [@droplet](https://discuss.elastic.co/u/droplet)
#### Post date: [August 5, 2021, 3:51pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/13 "2021-08-05T15:51:25Z")

</div>

I'm leaving here the Nginx configuration I used that I figured out with the help of given answers.

First you'll need the latest _[NGINX Open Source compiled with the `--with-stream` and `with-stream_ssl_module` configuration parameters](https://docs.nginx.com/nginx/admin-guide/security-controls/securing-tcp-traffic-upstream/)_

Check your system with:

```auto
nginx -V 2>&1 | tr ' ' '\n' | grep stream

```

Next, inside /etc/nginx edit the nginx.conf file and append to the bottom:

```auto
include /etc/nginx/streams-enabled/*;

```

Create that folder if it doesn't exist

```auto
$ sudo mkdir /etc/nginx/streams-enabled

```

Create a file inside sites-available and name it what ever you want. `eg. logstash.proxy`

Edit the file and add the following basic configuration

```auto
stream {
	upstream logstash {
		server 127.0.0.1:5044;
	}

	server {
		listen 5544 ssl;
		proxy_pass logstash;
		
		# SSL
        ssl_certificate /etc/letsencrypt/live/YOURDOMAIN/fullchain.pem;
	    ssl_certificate_key /etc/letsencrypt/live/YOURDOMAIN/privkey.pem;
    }
}

```

Symlink that file into the streams-enabled folder

```auto
$ sudo ln -s /etc/nginx/sites-enabled/logstash.proxy /etc/nginx/streams-enabled/logstash-proxy

```

Test nginx with the `nginx -t` command. If everything's fine, you should be able to restart Nginx with this configuration and your beats will be able to communicate with your Logstash instance.

There are more steps to do with Logstash and \*beats configurations, but the above should cover the Nginx part.

> **Please be careful with the above and don't use it in Production. It is only meant for education and fiddling around.**

if you want to use it on a publicly accessible system (DigitalOcean, Linode, Whatever...), you should have a firewall up and only allow the machines running the beats through.

```auto
// Ubuntu with ufw
$ sudo ufw allow from your.beats.ip.address to any port 5544 proto tcp // or any port you used above
$ sudo ufw reload
$ sudo ufw status
Status: active

To Action From
-- ------ ----         
5544/tcp ALLOW your.beats.ip.address

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 2, 2021, 3:51pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665/14 "2021-09-02T15:51:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
