# Checking if the output.logstash is going to valid host

**URL:** <https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 14, 2021, 3:36pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202 "2021-09-14T15:36:17Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 3:36pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/1 "2021-09-14T15:36:18Z")

</div>

My goal is to verify that the output.logstash is actually being sent to the proper host. My filebeat configuration is set up like so

```auto
filebeat.inputs:

- input_type: log
  paths:
    - /var/log/*.log
    - /var/log/*/*.log

tags: ["security", "bastion"]

processors:
 - add_cloud_metadata:

output.logstash:
  hosts: ["myhost:5000"]
  ssl.certificate_authorities: ["/etc/pki/beats/logstashCA.crt"]
  ssl.certificate: "/etc/pki/beats/beats.crt"
  ssl.key: "/etc/pki/beats/beats.key"

```

The logstash instance is up and running, but I'd like to know how to test whether or not the data is actually being sent from the machine running filebeat to the machine running logstash. Does anyone have a suggestion for how to test this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 3:45pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/2 "2021-09-14T15:45:13Z")

</div>

See [here](https://www.elastic.co/guide/en/beats/filebeat/current/command-line-options.html#test-command)

`filebeat test output`

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 3:48pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/3 "2021-09-14T15:48:39Z")

</div>

> [@stephenb](#):
>
> filebeat test output

Error initializing beat: could not initialize the keystore: open /var/lib/filebeat/filebeat.keystore: permission denied

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 4:02pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/4 "2021-09-14T16:02:37Z")

</div>

Thats is a different issue all together.

That is usually a directory / file permission issue...

Does the user you are running the test command have permission to access those files / directory?

Did you install with a package if so those files are probably owned by the filebeat

you may need to run the above command with sudo

`sudo filebeat test output`

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 4:51pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/5 "2021-09-14T16:51:03Z")

</div>

> [@stephenb](#):
>
> sudo filebeat test output

Thank you for the suggestion. Looks like things are up and running, but I'm getting security... WARN server's certificate chain verification is disabled

logstash: myinstance:5000...  
connection...  
parse host... OK  
dns lookup... OK  
addresses: x.xxx.xxx.xxx, xx.xx.xxx.xx, xx.xx.xx.xxx  
dial up... OK  
TLS...  
security... WARN server's certificate chain verification is disabled  
handshake... OK  
TLS version: TLSv1.2  
dial up... OK  
talk to server... OK

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 4:58pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/6 "2021-09-14T16:58:48Z")

</div>

Certs... not my area of expertise.

#### [Filebeat logstash outpput ssl](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html#_ssl_5)

Configuration options for SSL parameters like the root CA for Logstash connections. See [_SSL_](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html) for more information. To use SSL, you must also configure the [Beats input plugin for Logstash](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html) to use SSL/TLS.

Do you have the beats input plugin on logstash using SSL?

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 5:35pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/7 "2021-09-14T17:35:46Z")

</div>

ls /var/lib/logstash/plugins/inputs/

s3

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 6:07pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/8 "2021-09-14T18:07:55Z")

</div>

No it is a directory on your unix filesystem

> **[Directory layout | Filebeat Reference \[7.14\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/directory-layout.html)**

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 8:16pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/9 "2021-09-14T20:16:23Z")

</div>

What exactly do you mean by that?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 8:30pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/10 "2021-09-14T20:30:46Z")

</div>

You asked....

> [@EvanGertis](#):
>
> ls /var/lib/logstash/plugins/inputs/
> 
> s3

`/var/lib/logstash/plugins/inputs/` is a filesystem directory on a Unix OS.

Perhaps if you are not familiar with Unix Operating Systems and Filesystems you could reach out to a peer that is.

This is fundamental Unix OS Admin stuff: Filesystems, Directories, Permissions etc.. etc..

and I am not clear why you are asking about it that is directory in the first place?

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 8:40pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/11 "2021-09-14T20:40:18Z")

</div>

Thank you, I'm trying to understand how to validate whether or not this is an ssl issue. I was listing out the inputs. The filebeat test output shows that this instance is connected. How would you test if this is being processed on the logstash side of things?

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 9:00pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/12 "2021-09-14T21:00:59Z")

</div>

The ssl certificate for logstash is valid. I just checked.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 9:07pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/13 "2021-09-14T21:07:04Z")

</div>

> [@EvanGertis](#):
>
> Thank you, I'm trying to understand how to validate whether or not this is an ssl issue. I was listing out the inputs. The filebeat test output shows that this instance is connected. How would you test if this is being processed on the logstash side of things?

The filebeat output is common for the 2 different filebeat inputs.

You would test logstash by running beats -\> logstash -\> output (Elasticsearch or Console etc)

In your logstash pipeline config did you enable ssl in the beats input? Try that

> **[Beats input plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-ssl)**

```auto
input {
  beats {
    port => 5044
    ssl => true
  }
}

```

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 9:12pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/15 "2021-09-14T21:12:29Z")

</div>

That shows that it's running.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 14, 2021, 9:43pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/16 "2021-09-14T21:43:22Z")

</div>

Apologies @EvanGertis

I am not sure how to help, I am not sure how to respond to 1 line statements perhaps someone else will be able to help.

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 14, 2021, 10:01pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/17 "2021-09-14T22:01:37Z")

</div>

[INFO] 2021-09-14 21:27:06.698 [[main]-pipeline-manager] beats - Beats inputs: Starting input listener {:address=\>"0.0.0.0:5000"} the pipeline started and it's running.

---

<div class="post-metadata">

**Author:** ![EvanGertis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evangertis/32/85191_2.png) [@EvanGertis](https://discuss.elastic.co/u/EvanGertis)\
**Post date:** [September 15, 2021, 1:22pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/18 "2021-09-15T13:22:31Z")

</div>

solved: I was specifying an IP address for logstash instead of the DNS name

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2021, 1:22pm UTC](https://discuss.elastic.co/t/checking-if-the-output-logstash-is-going-to-valid-host/284202/19 "2021-10-13T13:22:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
