# Connecting Filebeat to Logstash

**URL:** <https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2018, 12:18am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725 "2018-10-10T00:18:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samuel\_Dare](https://avatars.discourse-cdn.com/v4/letter/s/7ab992/32.png) [@Samuel\_Dare](https://discuss.elastic.co/u/Samuel_Dare)\
**Post date:** [October 10, 2018, 12:18am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725/1 "2018-10-10T00:18:11Z")

</div>

I am new to elasticsearch and following the tutorial here:

> **[How To Install Elasticsearch, Logstash, and Kibana (ELK Stack) on CentOS 7 |...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-centos-7)**
>
> In this tutorial, we will go over the installation of the Elasticsearch ELK Stack on CentOS 7—that is, Elasticsearch 2.1.x, Logstash 2.1.x, and Kibana 4.3.x. We will also show you how to configure it to gather and visualize the syslogs of your...

I have hit a stumbling block as I can connect the servers with the ELK stack configured with the the server that is logging activity to file beat.

I have narrowed it down to an issue with the SSL certificates copied from the ELK server as when i check /var/log/messages I get the following error:

`usr/bin/filebeat[13730]: transport.go:125: SSL client failed to connect with: x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "serial:16193853809450343771")`

How ever, the keys have been copied over and these files are the same on both servers :

`cat /etc/pki/tls/certs/logstash-forwarder.crt`

When I try to read the syslogs, I get this:

`sudo tail /var/log/syslog | grep filebeat:`

`tail: cannot open ‘/var/log/syslog’ for reading: No such file or directory`.

I will appreciate any pointers on this

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [October 11, 2018, 10:57am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725/2 "2018-10-11T10:57:06Z")

</div>

Hi @Samuel_Dare 🙂

I don't have an answer for you right now but I'd suggest you to paste you configuration and check the versions you're using in your machine. I mean logstash and filebeat version but also the version of the module you're using.

We have seen many issues regarding "old" versions that are shipped by default in Centos so it could be some issue that it's already solved or using a newer version of filebeat or of the service you're fetching (say apache or whatever)

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 11:04am UTC](https://discuss.elastic.co/t/connecting-filebeat-to-logstash/151725/3 "2018-11-08T11:04:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
