# Certificate Error in File Beat connecting to Logstash

**URL:** <https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 6, 2016, 11:44am UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503 "2016-01-06T11:44:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![RickH](https://avatars.discourse-cdn.com/v4/letter/r/b4bc9f/32.png) [@RickH](https://discuss.elastic.co/u/RickH)\
**Post date:** [January 6, 2016, 11:44am UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503/1 "2016-01-06T11:44:38Z")

</div>

We are running a proof of concept on our network to establish whether we can configure filebeat (installed on Windows 2012) to connect to Logstash (on RHEL). unfortunately we are getting a certificate error when we attempt to start beats:

_ERR SSL client failed to connect with: x509: certificate is valid for 10.123.52.154, not 10.123.52.154_

Where 10.123.52.154 is the IP of our server. The certificate has been set-up using this IP - the Linux server is not discoverable using the FQDN as it is part of a lab deployment (which does not add DNS records).

This same configuration worked with the logstash-forwarder from Windows to RHEL. Any suggestions what could cause this?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 6, 2016, 1:57pm UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503/2 "2016-01-06T13:57:13Z")

</div>

Uhm, that's weird. I assume it is the same certificate you've used with logstash-forwarder?

Which command have you used to generate the certificate?

Can you show filebeat and logstash-forwarder config? Also the logstash input sections.

---

<div class="post-metadata">

**Author:** ![RickH](https://avatars.discourse-cdn.com/v4/letter/r/b4bc9f/32.png) [@RickH](https://discuss.elastic.co/u/RickH)\
**Post date:** [January 6, 2016, 2:42pm UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503/3 "2016-01-06T14:42:04Z")

</div>

We used the following command to create the cert (on the linux node):

_sudo openssl req -config /etc/pki/tls/openssl.cnf -x509 -days 3650 -batch -nodes -newkey rsa:2048 -keyout private/filebeat.key -out certs/filebeat.crt_

It is a new certificate for filebeat, but we can use the old cert and get the same issue. Below are the files as provided to me by my team.

Logstash-forwarder.json:

> {  
> "network": {  
> "servers": ["10.123.52.154:1514"],  
> "timeout": 30,  
> "ssl ca": "C:/Logstash/logstash-forwarder.crt"  
> },  
> "files": [  
> {  
> "paths": ["C:\Windows\System32\LogFiles"],  
> "fields": { "type": "syslog" }  
> }  
> ]  
> }

Filebeat config (on Windows):

```
filebeat:
  # List of prospectors to fetch data.
  prospectors:
    # Each - is a prospector. Below are the prospector specific configurations
    -
      paths:
         - c:\programdata\filebeat\Logs\*
      fields:
        type: syslog

      input_type: log
  registry_file: "C:/ProgramData/filebeat/registry"

############################# Output ##########################################

output:
  logstash:
    # The Logstash hosts
    hosts: ["10.123.52.154:1514"]
    tls:
      certificate: "C:/Abee/filebeat.crt"
      certificate_key: "C:/Abee/filebeat.key"

############################# Logging #########################################

# There are three options for the log ouput: syslog, file, stderr.
# Under Windos systems, the log files are per default sent to the file output,
# under all other system per default to syslog.
logging:=
  to_files: true
  files:
    name: mybeat
    rotateeverybytes: 10485760 # = 10MB

```

Logstash input section:

> input {  
> lumberjack {  
> port =\> 1514  
> ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
> ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
> type =\> "lumberjack"  
> }

> file {  
> path =\> "/tmp/test.log"  
> type =\> "test"  
> }

> heartbeat {  
> interval =\> 10  
> type =\> "heartbeat"  
> }  
> }

Update....  
Logstash config input section now:

> input {  
> beats {  
> port =\> "1514"  
> ssl =\> true  
> ssl\_certificate =\> "/etc/pki/tls/certs/filebeat.crt"  
> ssl\_key =\> "/etc/pki/tls/private/filebeat.key"

> }  
> file {  
> path =\> "/tmp/test.log"  
> type =\> "test"  
> }  
> heartbeat {  
> interval =\> 10  
> type =\> "heartbeat"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 7, 2016, 7:50am UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503/4 "2016-01-07T07:50:17Z")

</div>

looks like a misconfigured logstash output. The `certificate` and `certificate_key` options are required for client authentication (which is not yet supported by logstash plugin).

try:

```
output:
  logstash:
    hosts: ["19.123.52.154:1514"]
    tls:
      certificate_authorities:
        - C:/Abee/filebeat.crt

```

In filebeat you can add multiple certificates for validation, that's why the list.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:57pm UTC](https://discuss.elastic.co/t/certificate-error-in-file-beat-connecting-to-logstash/38503/5 "2017-07-05T21:57:01Z")

</div>


