# Curl -k query works but Logstash cannot query

**URL:** <https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176>\
**Category:** Logstash\
**Created:** [January 11, 2018, 9:16pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176 "2018-01-11T21:16:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [January 11, 2018, 9:16pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/1 "2018-01-11T21:16:27Z")

</div>

When I issue a query via a curl -k command to an https elasticsearch end point, I get the query results, however, using the elasticsearch input plugin in logstash, I cannot retrieve the same data.

curl -k -u xxxx [https://server.com:9200/index-\*/\_search](https://server.com:9200/index-*/_search)

I get data from this command. From Logstash:

input {  
elasticsearch {  
hosts =\> ["[server.com:9200](http://server.com:9200)"]  
index =\> "index-\*"  
user =\> "xxxxx"  
password =\> "xxxxx"  
query =\> '{ "query": { "match\_all": {} } }'  
}  
}  
output {  
stdout {codec =\> rubydebug}  
}  
Logstash returns:

Error: [503]

Network Error  

> | Network Error (tcp\_error)  
>   
> |
> | A communication error occurred: "" |
> | The Web Server may be down, too busy, or experiencing other problems preventing it from responding to requests. You may wish to try again at a later time. |
> |   
> |

With ssl =\> true, I get:

[2018-01-11T16:11:19,049][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::Elasticsearch ssl=\>true, hosts=\>["[server.com:9200](http://server.com:9200)"], index=\>"index-\*", user=\>"xxxx", p  
assword=\>, query=\>"{ "query": { "match\_all": {} } }", id=\>"zzzzzz-1", enable\_metric=\>true, codec=\>\<LogStash::Codecs::JSON id=\>"json\_a80bfc29-c019-4c2b-b108-541132f0fee2", enable\_metric=\>true, charset=\>"UTF-8"\>, size=\>1000, scroll=\>"1m", docinfo=\>false, docinfo\_target=\>"@metadata", docinfo\_fields=\>["\_index", "\_type", "\_id"]\>  
Error: certificate verify failed

Any help? Thanks

---

<div class="post-metadata">

**Author:** ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Post date:** [January 11, 2018, 9:36pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/2 "2018-01-11T21:36:32Z")

</div>

> [@chapmantrain](#):
>
> `Error: certificate verify failed`

The certificate is failing verification. You should use a certificate on the server that properly verifies. That's also why only `curl -k` works - it's disabling verification.

You can [disable it](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl_certificate_verification) but that will compromise security.

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [January 11, 2018, 11:26pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/3 "2018-01-11T23:26:42Z")

</div>

Does it make a difference that I am just stdout the retrieval? This a proof  
of concept we just want to make sure we can hit and retrieve from the  
target end point.

---

<div class="post-metadata">

**Author:** ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Post date:** [January 11, 2018, 11:37pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/4 "2018-01-11T23:37:17Z")

</div>

Only you can make security decisions for your own environment.

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [January 12, 2018, 2:01am UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/5 "2018-01-12T02:01:38Z")

</div>

The question is since I am doing a stdout and not an output to elastic, why  
am I getting a cert problem. Can i tell logstash, as with the curl -k to  
ignore the insecure connection while we prove concept.

---

<div class="post-metadata">

**Author:** ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Post date:** [January 12, 2018, 3:14am UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/6 "2018-01-12T03:14:04Z")

</div>

> [@chapmantrain](#):
>
> ```auto
> Plugin: <LogStash::Inputs::Elasticsearch ssl=>true, hosts=>["server.com:9200"], …
> Error: certificate verify failed
> 
> ```

You've told logstash to connect to ES for _input_ - that's where the verification is failing. It isn't getting anywhere near the output yet.

> [@chapmantrain](#):
>
> This a proof of concept we just want to make sure we can hit and retrieve from the target end point.

Perfect! That's the security analysis: "this is a proof of concept only, disabling verification is OK." You can follow the link I posted above to see what to change to disable cert verification: [Elasticsearch output plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl_certificate_verification)

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [January 12, 2018, 4:55pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/7 "2018-01-12T16:55:59Z")

</div>

To sum up here and please correct me if I have come to the wrong conclusion. The Logstash Ellasticsearch INPUT plugin has an option of turning off SSL on the input request, however, it does not have the ability to ignore an insecure connection (like the curl -k option). So our solution is that we will have to request and install ssl certs on the development machines in order to complete the proof of concept project of extracting parts of a larder index from the divisional cluster to be re-indexed into our department cluster.

---

<div class="post-metadata">

**Author:** ![Supermathie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supermathie/32/44936_2.png) [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Post date:** [January 12, 2018, 5:09pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/8 "2018-01-12T17:09:17Z")

</div>

Ah, I see - I thought I linked to the [logstash-input-elastic plugin docs](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl_certificate_verification), I was linking to the logstash-output-elasticsearch docs.

As the input plugin doesn't have the ability to disable ssl cert verification, you can set the `ca_cert` option to a file with the self-signed certificate and it should verify. Or you can add the ability to disable verification to the plugin.

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [January 12, 2018, 5:27pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/9 "2018-01-12T17:27:21Z")

</div>

Yes. I think we have an accord now. I'll need to get me a cert because I am NOT going to write that code to disable the verification. Thanks for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2018, 5:27pm UTC](https://discuss.elastic.co/t/curl-k-query-works-but-logstash-cannot-query/115176/10 "2018-02-09T17:27:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
