# Enabling SSL with Elasticsearch cause logstash pipeline error

**URL:** <https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131>\
**Category:** Logstash\
**Created:** [November 16, 2022, 11:43pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131 "2022-11-16T23:43:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [November 16, 2022, 11:43pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/1 "2022-11-16T23:43:16Z")

</div>

hi,

I am using 8.4.3, for both elastic and logstash.

We have enabled ssl with Elasticsearch. with the ssl our logstash fails to output data there, without ssl it works fine.

the output settings:

```auto
output{
elasticsearch {
		hosts => "elstichost:443"
		index => "%{[log-type]}-%{[a-type]}--%{+YYYY.MM}"
		ssl => "true"
		user => " ****"
		password => " ******"
		#ilm_enabled => false
        #manage_template => false
		cacert => "\logstash_cert.crt"
        keystore => "\logstash_key.key"
        ssl_certificate_verification => true
    }
}

```

The Error i am getting is:

```auto
[2022-11-16T14:10:43,383][ERROR][logstash.javapipeline][main] Pipeline error {:pipeline_id=>"main", :exception=>#<Java::JavaIo::IOException: toDerInputStream rejects tag type 45>, :backtrace=>["sun.security.util.DerValue.toDerInputStream(sun/security/util/DerValue.java:1155)", "sun.security.pkcs12.PKCS12KeySt
ore.engineLoad(sun/security/pkcs12/PKCS12KeyStore.java:2013)", "sun.security.util.KeyStoreDelegator.engineLoad(sun/security/util/KeyStoreDelegator.java:221)", "java.security.KeyStore.load(java/security/KeyStore.java:1473)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)", "jdk.internal.refl
ect.NativeMethodAccessorImpl.invoke(jdk/internal/reflect/NativeMethodAccessorImpl.java:77)", "jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:568)", "org.jruby.javasupport.JavaMetho
d.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:427)", "org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:294)", 
......

[2022-11-16T14:10:43,406][INFO][logstash.javapipeline][main] Pipeline terminated {"pipeline.id"=>"main"}
[2022-11-16T14:10:43,415][ERROR][logstash.agent] Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: PipelineAction::Create<main>, action_result: false", :backtrace=>nil}
[2022-11-16T14:10:43,506][INFO][logstash.runner] Logstash shut down.

```

Any help would be really appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 17, 2022, 2:22am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/2 "2022-11-17T02:22:40Z")

</div>

> [@Indigo\_Star](#):
>
> ```auto
> cacert => "\logstash_cert.crt"
> keystore => "\logstash_key.key"
> 
> ```

This does not looks like a valid path, have you tried to use the **full path** to both of those files?

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [November 17, 2022, 2:47am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/3 "2022-11-17T02:47:32Z")

</div>

Thanks Leandro for your respinse actually in my config i used the full and the valid path here i just cropped it. I should have mentioned that. There was nothing invalid in this config.

Can you please see if there is anything else missing for the ssl configuration

I didn't find a full example of output with ssl enabled anywhere i picked these keys from different forums so i am.not sure if this is all we need to specify.

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 17, 2022, 4:18am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/4 "2022-11-17T04:18:37Z")

</div>

Did you check the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch) ?

It explains what is every option in the output.

Normally in logstash you just need to configure de `cacert` option and point it to the self-signed CA used to sign the Elasticsearch certificates, this is also explained in [the documentation](https://www.elastic.co/guide/en/logstash/current/ls-security.html#es-security-onprem).

Try to remove the `keystore` option and use the `cacert` option only.

Try this:

```auto
elasticsearch {
	hosts => "elstichost:443"
	index => "%{[log-type]}-%{[a-type]}--%{+YYYY.MM}"
	ssl => "true"
	user => " ****"
	password => " ******"
	#ilm_enabled => false
    #manage_template => false
	cacert => "path-to-the-ca-cert.crt"
    ssl_certificate_verification => true
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 17, 2022, 5:07pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/5 "2022-11-17T17:07:12Z")

</div>

> [@Indigo\_Star](#):
>
> in my config i used the full and the valid path here i just cropped it.

If you are using backslash in the file paths try changing them to forward slash. I know in the file input that when javafication was done (V5.x?) the input started treating them as escapes.

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [November 17, 2022, 6:11pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/6 "2022-11-17T18:11:07Z")

</div>

Hi Thanks for your responses.

@Leandrojmp  
I've already tried without the kaystore option that was giving me this error:

```auto
[2022-11-16T13:31:49,923][DEBUG][logstash.instrument.periodicpoller.jvm] collector name {:name=>"G1 Old Generation"}
[2022-11-16T13:31:49,938][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash-agent:xxxxxx@elastichost:443/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=
>"Got response code '403' contacting Elasticsearch at URL 'https://elastichost:443/'"}

```

I am not sure why it indicates  
"[https://logstash-agent:xxxxxx@elastichost:443/](https://logstash-agent:xxxxxx@elastichost:443/)"  
in the error.  
Is this an expected thing?

@Badger when i tried with the forward slash and without keystore option i get the same error

```auto
[2022-11-17T09:52:38,874][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash-agent:xxxxxx@elastichost:443/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError,
 :message=>"Got response code '403' contacting Elasticsearch at URL 'https://elastichost:443/'"}
 
when i try with keystore and forward slash i am back to the original error that i initially posted:

```

```auto
[2022-11-17T10:00:54,959][ERROR][logstash.javapipeline][main] Pipeline error {:pipeline_id=>"main", :exception=>#<Java::JavaIo::IOException: toDerInputStream rejects tag type 45>, :backtrace=>["sun.security.util.DerValue.toDerInputStream(sun/security/util/DerValue.java:1155)", "sun.security.pkcs12.P
KCS12KeyStore.engineLoad(sun/security/pkcs12/PKCS12KeyStore.java:2013)", "sun.security.util.KeyStoreDelegator.engineLoad(sun/security/util/KeyStoreDelegator.java:221)", "java.security.KeyStore.load(java/security/KeyStore.java:1473)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)"
, "jdk.internal.reflect.NativeMethodAccessorImpl.invoke(jdk/internal/reflect/NativeMethodAccessorImpl.java:77)", "jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:568)", "o

```

```auto
elasticsearch {
        hosts => "elastichost:443"
        index => "%{[log-type]}-%{[a-type]}-%{[customer]}-debug-%{[log-timestamp-year]}.%{[log-timestamp-month]}.%{[log-timestamp-day]}"
		user => " ****"
		password => " *****"
		ssl => "true"
        cacert => "C:/my/path/to/certificate/logstash_cert.crt"
        #keystore => "C:/my/path/to/logstash_key.key"
        ssl_certificate_verification => true		
      }

```

There is no difference in the error messages.

Is there anything else that i can have a look at?

Appreciate your help.

Thanks

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [November 28, 2022, 9:56pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/7 "2022-11-28T21:56:07Z")

</div>

Hi,

@Badger @leandrojmp  
I couldn't find any solution for this. I have tried all the possible combination with the output settings as mentioned earlier but i am still unable to get it work anything you guys can indicate to help?

Thanks

Following is the error i get

WARNING: Illegal reflective access by org.jruby.javasupport.binding.ConstantField (file:/C:/Program%20Files/Elastic/logstash-8.5.2/vendor/jruby/lib/jruby.jar) to field sun.security.x509.X509CertImpl.SIG  
WARNING: Please consider reporting this to the maintainers of org.jruby.javasupport.binding.ConstantField  
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations  
WARNING: All illegal access operations will be denied in a future release  
[2022-11-28T13:37:31,351][ERROR][logstash.javapipeline][main] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<Java::JavaIo::IOException: toDerInputStream rejects tag type 45\>, :backtrace=\>["sun.security.util.DerValue.toDerInputStream(sun/security/util/DerValue.java:873)", "sun.security.pkcs12.PKCS12KeyStore.engineLoad(sun/security/pkcs12/PKCS12KeyStore.java:1997)", "sun.security.util.KeyStoreDelegator.engineLoad(sun/security/util/KeyStoreDelegator.java:222)", "java.security.KeyStore.load(java/security/KeyStore.java:1479)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke(jdk/internal/reflect/NativeMethodAccessorImpl.java:62)", "jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:566)", "org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:427)", "org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:294)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.get\_store(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:762)", "org.jruby.RubyKernel.tap(org/jruby/RubyKernel.java:1940)", "org.jruby.RubyKernel$INVOKER$s$0$0$tap.call(org/jruby/RubyKernel$INVOKER$s$0$0$tap.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.get\_store(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:760)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.setup\_key\_store(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:718)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.ssl\_socket\_factory\_from\_options(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:693)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.pool\_builder(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:454)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.pool(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:462)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.manticore\_minus\_0\_dot\_9\_dot\_1\_minus\_java.lib.manticore.client.initialize(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/manticore-0.9.1-java/lib/manticore/client.rb:227)", "org.jruby.RubyClass.new(org/jruby/RubyClass.java:911)", "org.jruby.RubyClass$INVOKER$i$newInstance.call(org/jruby/RubyClass$INVOKER$i$newInstance.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client.manticore\_adapter.initialize(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:26)", "org.jruby.RubyClass.new(org/jruby/RubyClass.java:911)", "org.jruby.RubyClass$INVOKER$i$newInstance.call(org/jruby/RubyClass$INVOKER$i$newInstance.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client.build\_adapter(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client.rb:329)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client.build\_pool(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client.rb:345)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client.initialize(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client.rb:63)", "org.jruby.RubyClass.new(org/jruby/RubyClass.java:911)", "org.jruby.RubyClass$INVOKER$i$newInstance.call(org/jruby/RubyClass$INVOKER$i$newInstance.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client\_builder.create\_http\_client(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client\_builder.rb:106)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.http\_client\_builder.build(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch/http\_client\_builder.rb:102)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.plugin\_mixins.elasticsearch.common.build\_client(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/plugin\_mixins/elasticsearch/common.rb:39)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.vendor.bundle.jruby.$2\_dot\_6\_dot\_0.gems.logstash\_minus\_output\_minus\_elasticsearch\_minus\_11\_dot\_9\_dot\_3\_minus\_java.lib.logstash.outputs.elasticsearch.register(C:/Program Files/Elastic/logstash-8.5.2/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.9.3-java/lib/logstash/outputs/elasticsearch.rb:296)", "org.jruby.RubyClass.finvoke(org/jruby/RubyClass.java:572)", "org.jruby.RubyBasicObject.callMethod(org/jruby/RubyBasicObject.java:348)", "org.logstash.config.ir.compiler.OutputStrategyExt$SimpleAbstractOutputStrategyExt.reg(org/logstash/config/ir/compiler/OutputStrategyExt.java:275)", "org.logstash.config.ir.compiler.OutputStrategyExt$AbstractOutputStrategyExt.register(org/logstash/config/ir/compiler/OutputStrategyExt.java:131)", "org.logstash.config.ir.compiler.OutputDelegatorExt.doRegister(org/logstash/config/ir/compiler/OutputDelegatorExt.java:117)", "org.logstash.config.ir.compiler.AbstractOutputDelegatorExt.register(org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:68)", "org.logstash.config.ir.compiler.AbstractOutputDelegatorExt$INVOKER$i$0$0$register.call(org/logstash/config/ir/compiler/AbstractOutputDelegatorExt$INVOKER$i$0$0$register.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.register\_plugins(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:234)", "org.jruby.RubyArray.each(org/jruby/RubyArray.java:1865)", "org.jruby.RubyArray$INVOKER$i$0$0$each.call(org/jruby/RubyArray$INVOKER$i$0$0$each.gen)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.register\_plugins(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:233)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.maybe\_setup\_out\_plugins(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:600)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.start\_workers(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:246)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.run(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:191)", "C\_3a\_.Program\_20\_Files.Elastic.logstash\_minus\_8\_dot\_5\_dot\_2.logstash\_minus\_core.lib.logstash.java\_pipeline.start(C:/Program Files/Elastic/logstash-8.5.2/logstash-core/lib/logstash/java\_pipeline.rb:143)", "org.j

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 28, 2022, 10:06pm UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/8 "2022-11-28T22:06:30Z")

</div>

Have you simply tried to curl from logstash host to elasticsearch with the SSL?

Do you actually have elasticsearch running on 443 not 9200?

Start with

`curl -k -v -u username https://eshost:port`

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [November 29, 2022, 1:12am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/9 "2022-11-29T01:12:11Z")

</div>

> [@stephenb](#):
>
> curl -k -v -u username [https://eshost](https://eshost):port

@stephenb Thanks for your response.

Yes elastic is running on the host and i have tried following:

Yes i have tried the curl command i have curl installed on windows but i get the following error

Invoke-WebRequest : Parameter cannot be processed because the parameter name 'u' is ambiguous. Possible matches  
include: -UseBasicParsing -Uri -UseDefaultCredentials -UserAgent.  
At line:1 char:12

i tried without any parameter as well but nothing seems working

Although when i try via postman it does work for the same credentials.  
I just provide  
Method Put  
the user/pwd and  
the '[https://ealstichost/index-name1](https://ealstichost/index-name1)' and I was able to create an index

Also i can access the host via chrome, but when i try via logstash it get this error while providing only the user/pwd and no port

[2022-11-28T16:59:03,745][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"[http://logstash-agent:xxxxxx@elastichost:9200/](http://logstash-agent:xxxxxx@elastichost:9200/)", :exception=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError, :message=\>"Elasticsearch Unreachable: [[http://elastichost:9200/](http://elastichost:9200/)][Manticore::ConnectTimeout] Connect to elastichost:9200 [ealstichost/] failed: connect timed out"}

I don't know what else should be tried here?

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 29, 2022, 2:05am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/10 "2022-11-29T02:05:32Z")

</div>

> [@Indigo\_Star](#):
>
> [2022-11-28T16:59:03,745][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"[http://logstash-agent:xxxxxx@elastichost:9200/](http://logstash-agent:xxxxxx@elastichost:9200/)", :exception=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError, :message=\>"Elasticsearch Unreachable: [[http://elastichost:9200/](http://elastichost:9200/)][Manticore::ConnectTimeout] Connect to elastichost:9200 [ealstichost/] failed: connect timed out"}

`http` or `https`?

Can you share your actual logstash output again... it seems to be changing?

Also do you have more than 1 conf file in the conf.d directory? If so it will be concatenated together.

On `curl` not sure which curl you installed ... -u for user is a common option.

The just try

`curl -k -v https://eshost:port`

Nothing that you have showed shows that there is network connectivity between the logstash server and the elasticsearch server.

Also to test you could turn ssl verification off to test

```auto
   elasticsearch {
     hosts => "https://elastichost:9200"
     index => "%{[log-type]}-%{[a-type]}-%{[customer]}-debug-%{[log-timestamp-year]}.%{[log-timestamp-month]}.%{[log-timestamp-day]}"
     user => " ****"
     password => " *****"
     ssl_certificate_verification => false		
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2022, 2:05am UTC](https://discuss.elastic.co/t/enabling-ssl-with-elasticsearch-cause-logstash-pipeline-error/319131/11 "2022-12-27T02:05:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
