# Config Help with SSL between Logstash and Elasticsearch

**URL:** <https://discuss.elastic.co/t/config-help-with-ssl-between-logstash-and-elasticsearch/49876>\
**Category:** Logstash\
**Created:** [May 12, 2016, 9:29am UTC](https://discuss.elastic.co/t/config-help-with-ssl-between-logstash-and-elasticsearch/49876 "2016-05-12T09:29:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aljaz\_Gantar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aljaz_gantar/32/9636_2.png) [@Aljaz\_Gantar](https://discuss.elastic.co/u/Aljaz_Gantar)\
**Post date:** [May 12, 2016, 9:29am UTC](https://discuss.elastic.co/t/config-help-with-ssl-between-logstash-and-elasticsearch/49876/1 "2016-05-12T09:29:54Z")

</div>

Okei so i have this case:  
I have tree server which are running the whole stack, and they are set up so:  
Filebeat =\> Logstash =\> Elasticsearch/Kibana

And I successfully configured that the Filebeat sends logs from his server all too the Elasticksearch/Kibana without any security. But now I would like to use SSL to secure the connection between those servers. What I did so far I could create a self signed certificate on the Logstash server and copied the Filebeat server so that he can verify that thats the correct server so Filebeat =\> Logstash works. What I could not get to working is Logstash =\> Elasticsearch/kibana It writes an error in the logs really late, like it waits filebeat to first send the logs and than it gets and error.

So my question is, how do I correctly configure that Logstash so it can communicate with the Elasticsearch/kibana sever with SSL correctly?

So here is my output config from Logstash:  
output {  
elasticsearch {  
hosts =\> "12.12.12:9200" #random IP  
ssl =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Elasticsearch.yml config:  
script.groovy.sandbox.enabled: true  
shield.ssl.keystore.path: /usr/lib/jvm/java-7-openjdk-amd64/jre/lib/security/cacerts  
shield.ssl.keystore.password: changeit  
shield.ssl.keystore.key\_password: changeit  
http.port: 9200  
shield.http.ssl: true  
shield.transport.ssl: true

but I always get this error:  
:message=\>"Failed to flush outgoing items", :outgoing\_count=\>1, :exception=\>"Manticore::ClientProtocolException"

---

<div class="post-metadata">

**Author:** ![bblank](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@bblank](https://discuss.elastic.co/u/bblank)\
**Post date:** [May 13, 2016, 1:29pm UTC](https://discuss.elastic.co/t/config-help-with-ssl-between-logstash-and-elasticsearch/49876/2 "2016-05-13T13:29:35Z")

</div>

Can you connect to your elasticsearch instance with a browser to prove ssl is working?  
[https://12.12.12:9200](https://12.12.12:9200)" ? If this doesn't work, then Logstash won't be able to connect either.

In your logstash.conf output section, you will need a line:  
cacert =\> "path to a PEM file with the certificate of the CA that signed your elasticsearch certificate"

I would also change the hosts line to:  
hosts =\> "[https://12.12.12:9200](https://12.12.12:9200)"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:57am UTC](https://discuss.elastic.co/t/config-help-with-ssl-between-logstash-and-elasticsearch/49876/3 "2017-07-06T04:57:40Z")

</div>


