# Can't connect from fluentd: NotSslRecordException error

**URL:** <https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 12, 2019, 9:49am UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221 "2019-09-12T09:49:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_F](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_f/32/54065_2.png) [@Paul\_F](https://discuss.elastic.co/u/Paul_F)\
**Post date:** [September 12, 2019, 9:49am UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/1 "2019-09-12T09:49:38Z")

</div>

I have deployed Elastic stack on k8s [running with kops on AWS] with almost default configuration [just different namespace].

I have deployed a fluentd daemonset in the same namespace and I am trying to connect to Elastic, but from fluentd I am getting:  
[warn]: #0 [out\_es] Could not communicate to Elasticsearch, resetting connection and trying again. end of file reached (EOFError)

And from elastic instance I am getting:  
Caused by: io.netty.handler.ssl.NotSslRecordException: not an SSL/TLS record

What am I missing in my configuration? How can I make it work? My fluentd config is fairly default:

\<match \*\*\>  
@type elasticsearch  
@id out\_es  
@log\_level "info"  
include\_tag\_key true  
host "elastic-es-http.elastic-system.svc.cluster.local"  
port 9200  
path ""  
scheme http  
ssl\_verify true  
ssl\_version TLSv1  
reload\_connections false  
reconnect\_on\_error true  
reload\_on\_failure true  
log\_es\_400\_reason false  
logstash\_prefix "logstash"  
logstash\_format true  
index\_name "logstash"  
type\_name "fluentd"

---

<div class="post-metadata">

**Author:** ![sebgl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebgl/32/48702_2.png) [@sebgl](https://discuss.elastic.co/u/sebgl)\
**Post date:** [September 12, 2019, 12:32pm UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/2 "2019-09-12T12:32:20Z")

</div>

Hey @Paul_F,

You should probably configure fluentd to use HTTPS instead of HTTP. I don't know that much about fluentd configuration, but it looks like you have:  
`scheme http`  
Which should probably instead:  
`scheme https`

Also you need to either provide Elasticsearch TLS certificate or CA to fluentd so it can trust the connection, either bypass TLS certificate verification, I guess with:

`ssl_verify false`

---

<div class="post-metadata">

**Author:** ![Paul\_F](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_f/32/54065_2.png) [@Paul\_F](https://discuss.elastic.co/u/Paul_F)\
**Post date:** [September 13, 2019, 1:47pm UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/3 "2019-09-13T13:47:58Z")

</div>

You were right @sebgl , scheme should be https.

How can I find the right certificate though? My deployment is not "quickstart", but "elastic", so I was trying:

```
      - name: CLIENT_CERT
        valueFrom:
          secretKeyRef:
            name: elastic-es-http-certs-public
            key: tls.crt

```

But then I get this eror:  
"Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: unknown\_ca",

Am I referencing the right certificate? Is there something else that has to be added?

---

<div class="post-metadata">

**Author:** ![Kay\_Khan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kay_khan/32/45028_2.png) [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Post date:** [July 3, 2020, 9:46am UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/4 "2020-07-03T09:46:52Z")

</div>

Did you fix this?

---

<div class="post-metadata">

**Author:** ![SeanPlacchetti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanplacchetti/32/51652_2.png) [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Post date:** [July 5, 2020, 11:16pm UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/5 "2020-07-05T23:16:11Z")

</div>

@Kay_Khan I just got this working in our cluster by using the autogenerated certs stored in the secrets suffixed with `http-certs-internal`, this also depended on joining the networks between the daemonset and the deployed elastic cluster.

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [July 6, 2020, 7:11am UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/6 "2020-07-06T07:11:17Z")

</div>

@SeanPlacchetti the secret called `$CLUSTERNAME-es-http-certs-public` would be preferable, as the one you referenced is meant for internal use of the operator.

---

<div class="post-metadata">

**Author:** ![SeanPlacchetti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanplacchetti/32/51652_2.png) [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Post date:** [July 6, 2020, 1:06pm UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/7 "2020-07-06T13:06:15Z")

</div>

Good to know, thanks!

---

<div class="post-metadata">

**Author:** ![SeanPlacchetti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanplacchetti/32/51652_2.png) [@SeanPlacchetti](https://discuss.elastic.co/u/SeanPlacchetti)\
**Post date:** [July 10, 2020, 2:46pm UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/8 "2020-07-10T14:46:08Z")

</div>

@pebrc I went to try and and use `$CLUSTERNAME-es-http-certs-public` (as we've recently updated every ECK deployed resource to use the 1.2 branch from beta) to redirect our FluentD from the OpenShift 3.11 built-in EFK stack and found that the above secret does not include a key. Not sure why, but the FluentD setup for OpenShift 3.11 requires: [Sending Logs to an External Elasticsearch Instance](https://docs.openshift.com/container-platform/3.11/install_config/aggregate_logging.html#sending-logs-to-an-external-elasticsearch-instance) If you have any recommendations on how to use the `$CLUSTERNAME-es-http-certs-public` with that, I'd appreciate the guidance. What are the negatives to using the `$CLUSTERNAME-es-http-certs-internal`? Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:25am UTC](https://discuss.elastic.co/t/cant-connect-from-fluentd-notsslrecordexception-error/199221/9 "2022-11-04T07:25:07Z")

</div>


