# Enable TLS for filebeat.input \[Newbie\]

**URL:** <https://discuss.elastic.co/t/enable-tls-for-filebeat-input-newbie/319180>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 17, 2022, 11:30am UTC](https://discuss.elastic.co/t/enable-tls-for-filebeat-input-newbie/319180 "2022-11-17T11:30:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dant0005](https://avatars.discourse-cdn.com/v4/letter/d/e79b87/32.png) [@dant0005](https://discuss.elastic.co/u/dant0005)\
**Post date:** [November 17, 2022, 11:30am UTC](https://discuss.elastic.co/t/enable-tls-for-filebeat-input-newbie/319180/1 "2022-11-17T11:30:12Z")

</div>

Hallo community,

Quite new to the elastic stack but lurking for a while in this community.

I got the task to set up log management based on the elastic stack.  
Use case: External system (SAAS) sends logs (a variety of logs from a Linux machine, e.g. tomcat) via tcp to elastic. Our devs should be able to leverage elastic for analysis, alerts, etc.

My setup is using filebeat (with System module enabled) as syslog receiver, Elastic, Kibana  
(After reading a lot of discussions, I believe Logstash is not necessary for the moment)

filebeat.yml

```auto
filebeat.inputs:
- type: syslog
  format: auto
  enabled: true
  protocol.tcp:
    host: "localhost:514"

filebeat.config.modules:
  path: /etc/filebeat/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1

setup.kibana:
  host: "localhost:5601"

output.elasticsearch:
  hosts: ["localhost:9200"]

  protocol: "https"
  ssl.verification_mode: none

# Authentication credentials - either API key or username/password.
  api_key: "someapikey"

```

The vendor only communicates via TLS, so I assume to configure SSL in filebeat.input to the following:

```auto
filebeat.inputs:
- type: syslog
  format: auto
  enabled: true
  protocol.tcp:
    host: "localhost:514"
  ssl.enabled: true
  ssl.certificate: "/home/user/server.pem"
  ssl.key: "/home/user/server.key"
  ssl.verification_mode: "none"
  ssl.certificate_authority: "/home/user/ca.pem"

```

My questions:

- Is this change enough, so traffic between SAAS and our syslog receiver is using TLS?
- Is the input type "syslog" the right choice? (I am not sure I understand the difference between input type "Systlog" and "TYP" correctly.

Thank you for your help, highly appreciated!  
Dan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2022, 1:30pm UTC](https://discuss.elastic.co/t/enable-tls-for-filebeat-input-newbie/319180/2 "2022-12-15T13:30:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
