# Connecting metricbeat to elasticsearch using ssl connection

**URL:** <https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121>\
**Category:** Elasticsearch\
**Created:** [September 29, 2023, 9:37am UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121 "2023-09-29T09:37:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![website](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/website/32/141503_2.png) [@website](https://discuss.elastic.co/u/website)\
**Post date:** [September 29, 2023, 9:37am UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/1 "2023-09-29T09:37:10Z")

</div>

Good afternoon, can you help with connecting metricbeat to elasticsearch wazuh  
The file /etc/elasticsearch/elasticsearch.yml looks like this:

```auto
network.host: 0.0.0.0
node.name: elasticsearch
cluster.initial_master_nodes: elasticsearch

# Transport layer
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.key: /etc/elasticsearch/certs/elasticsearch.key
xpack.security.transport.ssl.certificate: /etc/elasticsearch/certs/elasticsearch.crt
xpack.security.transport.ssl.certificate_authorities: /etc/elasticsearch/certs/ca/ca.crt

# HTTP layer
xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.verification_mode: certificate
xpack.security.http.ssl.key: /etc/elasticsearch/certs/elasticsearch.key
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/elasticsearch.crt
xpack.security.http.ssl.certificate_authorities: /etc/elasticsearch/certs/ca/ca.crt

# Elasticsearch authentication
xpack.security.enabled: true

path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch

```

The file /etc/metricbeat/metricbeat/metricbeat.yml looks like this to me:

```auto
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["localhost:9200"]
  # Protocol - either `http` (default) or `https`.
  protocol: "https"
  # Authentication credentials - either API key or username/password.
  #api_key: "${ES_API_KEY}"
  #api_key: "xxxx"
  #username: "elastic"
  #password: "xxxxx"
  ssl.certificate_authorities: ["/etc/elasticsearch/certs/ca/ca.crt"]
  ssl.certificate: "/etc/elasticsearch/certs/elasticsearch.crt"
  ssl.key: "/etc/elasticsearch/certs/elasticsearch.key"
  ssl.key_passphrase: "xxxxx"

```

But when checked with the command :

```auto
./metricbeat test output -c /etc/metricbeat/metricbeat.yml --path.home /usr/share/metricbeat/ --path.data /var/lib/metricbeat

```

```auto
elasticsearch: https://localhost:9200...
  parse url... OK
  connection...
    parse host... OK
    dns lookup... OK
    addresses: ::1, 127.0.0.1
    dial up... OK
  TLS...
    security: server's certificate chain verification is enabled
    handshake... ERROR x509: certificate is not valid for any names, but wanted to match localhost

```

I get an authorization error, can you tell me what I'm doing wrong?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 30, 2023, 6:47pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/2 "2023-09-30T18:47:49Z")

</div>

> [@website](#):
>
> `ERROR x509: certificate is not valid for any names, but wanted to match localhost`

How did you generate cert? hostname, localhost or IP?  
The `hosts: ["localhost:9200"`] value must match cert name in the subject or the alt name.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 1, 2023, 6:25pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/3 "2023-10-01T18:25:30Z")

</div>

Hi @website Welcome to the community

What version?, you should always include that.

How what version did you install of elasticsearch?

You should not need these

> [@website](#):
>
> ```auto
> ssl.certificate: "/etc/elasticsearch/certs/elasticsearch.crt"
> ssl.key: "/etc/elasticsearch/certs/elasticsearch.key"
> ssl.key_passphrase: "xxxxx"
> 
> ```

This should suffice:

` ssl.certificate_authorities: ["/etc/elasticsearch/certs/ca/ca.crt"]`

And then @Rios is asking the right question how did you create the elasticsearch certificate

---

<div class="post-metadata">

**Author:** ![website](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/website/32/141503_2.png) [@website](https://discuss.elastic.co/u/website)\
**Post date:** [October 2, 2023, 5:52am UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/4 "2023-10-02T05:52:31Z")

</div>

Good afternoon I solved the problem, but there was an error with the address, I have version 7.17 installed, but after installing metricbeat, the data is not displayed in Kibana, what could be the reason?

 ![2](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d7e9d9b7814ec31f3eb5577135de0ab46cf71247.jpeg)

---

<div class="post-metadata">

**Author:** ![website](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/website/32/141503_2.png) [@website](https://discuss.elastic.co/u/website)\
**Post date:** [October 2, 2023, 5:53am UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/5 "2023-10-02T05:53:01Z")

</div>

![11](https://us1.discourse-cdn.com/elastic/original/3X/3/8/385398bbe60dbb69bf8af40f53de61f6690b71f4.jpeg)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/6 "2023-10-02T14:42:36Z")

</div>

Hi @website

Did you run `setup` command before starting metricbeat?

That is a crucial step...

`metricbeat setup -e`

if you did not you will need to delete the metricbeat index then run `setup` and try again.

Also did you check in discover to see if you are actually getting data?

I see you are trying the prometheus module ... are you sure it is configured correctly?

Following the quick start help[https://www.elastic.co/guide/en/beats/metricbeat/7.17/metricbeat-installation-configuration.html?](https://www.elastic.co/guide/en/beats/metricbeat/7.17/metricbeat-installation-configuration.html?) your would just be with the prometheus module

Did you look at the metricbeat logs and see if there any other issues?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2023, 2:42pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121/7 "2023-10-30T14:42:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
