# Encrypting and authenticating communication between Winlogbeat and Logstash

**URL:** <https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 26, 2018, 1:07am UTC](https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108 "2018-11-26T01:07:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [November 26, 2018, 1:07am UTC](https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108/1 "2018-11-26T01:07:46Z")

</div>

I've working on a proof of concept where I'm using Elasticsearch, Logstash, Kibana and Winlogbeat.

The Winlogbeat service is running on a remote system and then sending events directly to Logstash. I've setup my configurations as follows:

**Logstash config:**

```auto
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate => "logstash-remote.crt"
    ssl_key => "logstash-remote.key"
  }
}

```

**Winlogbeat config:**

```auto
output.logstash:
  hosts: ["X.X.X.X:5044"]
  
  ssl.certificate_authorities: ['logstash-remote.crt']

  compression_level: 3

  bulk_max_size: 2048

```

This is far from optimal as far as security goes (no central CA, no additional configurations, etc)., however for a proof of concept I'm just trying to make sure none can install their own Winlogbeat service and send bogus data to my Logstash node and any traffic sent between the Winlogbeat service and Logstash can be decrypted unless they have the two certificates residing on the Logstash node.

Do my configurations look correct so far for basic encryption and authentication?

Thanks in advance! 🙂

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 26, 2018, 1:49am UTC](https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108/2 "2018-11-26T01:49:27Z")

</div>

> [@popa](#):
>
> I'm just trying to make sure none can install their own Winlogbeat service and send bogus data to my Logstash node

I don't see anything in your configuration that would provide that protection.  
Your TLS setup is:

1. encrypting the communication
2. ensuring that beats it talking to the real Logstash server

But it does not prevent additional (rogue) beats clients from connecting to that logstash port.

For that you want to enable (and enforce) client certifcates.  
See

- Logstash [`ssl_verify_mode`](https://www.elastic.co/guide/en/logstash/6.4/plugins-inputs-beats.html#plugins-inputs-beats-ssl_verify_mode) (you want `force_peer`)
- Logstash [`ssl_certificate_authorities`](https://www.elastic.co/guide/en/logstash/6.4/plugins-inputs-beats.html#plugins-inputs-beats-ssl_certificate_authorities)
- Winlogbeat [`ssl.certificate`](https://www.elastic.co/guide/en/beats/winlogbeat/6.4/configuration-ssl.html#certificate)
- Winlogbeat [`ssl.key`](https://www.elastic.co/guide/en/beats/winlogbeat/6.4/configuration-ssl.html#key)

---

<div class="post-metadata">

**Author:** ![popa](https://avatars.discourse-cdn.com/v4/letter/p/dec6dc/32.png) [@popa](https://discuss.elastic.co/u/popa)\
**Post date:** [November 26, 2018, 4:18am UTC](https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108/3 "2018-11-26T04:18:56Z")

</div>

Thank you Tim!

Also, the guide I followed for the steps mentioned above is here: [https://docs.bitnami.com/aws/apps/elk/administration/connect-remotely-logstash/](https://docs.bitnami.com/aws/apps/elk/administration/connect-remotely-logstash/)

Additionally, to prevent rogue beat clients from communicating with Logstash I've implement ed firewall rules to only accept connections from trusted sources.

At the very least with my setup communication is encrypted end-to-end, which is the most important thing for this proof of concept.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 4:19am UTC](https://discuss.elastic.co/t/encrypting-and-authenticating-communication-between-winlogbeat-and-logstash/158108/4 "2018-12-24T04:19:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
