# Encrypting Logstash pipeline output

**URL:** <https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613>\
**Category:** Logstash\
**Created:** [November 15, 2024, 4:08pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613 "2024-11-15T16:08:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richard\_LaRoche](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richard_laroche/32/138643_2.png) [@Richard\_LaRoche](https://discuss.elastic.co/u/Richard_LaRoche)\
**Post date:** [November 15, 2024, 4:08pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/1 "2024-11-15T16:08:38Z")

</div>

I am doing something new with my logstash collectors that I recently built and are working quite well. I need to start encrypting the data I am sending to another part of my organization. I have been looking at pretty much all the documentation in the elastic/logstash area and I am struggling a bit to know how to set this up. Like for example do I need to download something extra on my logstash server. Do I need openssl. I have the cert from the the destination organization. Just need a nudge in the right direction.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 15, 2024, 4:36pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/2 "2024-11-15T16:36:14Z")

</div>

What is the output you are using?

How you will configure it depends on the output.

---

<div class="post-metadata">

**Author:** ![Richard\_LaRoche](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richard_laroche/32/138643_2.png) [@Richard\_LaRoche](https://discuss.elastic.co/u/Richard_LaRoche)\
**Post date:** [November 15, 2024, 5:55pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/4 "2024-11-15T17:55:35Z")

</div>

Would look something like this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5b750e25aa6dc5b4bade77eadf0f282be8a3791b.png)

---

<div class="post-metadata">

**Author:** ![Richard\_LaRoche](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richard_laroche/32/138643_2.png) [@Richard\_LaRoche](https://discuss.elastic.co/u/Richard_LaRoche)\
**Post date:** [November 15, 2024, 8:13pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/5 "2024-11-15T20:13:29Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5b750e25aa6dc5b4bade77eadf0f282be8a3791b.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 15, 2024, 9:06pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/6 "2024-11-15T21:06:39Z")

</div>

You should try with something like this:

```auto
output {
  syslog {
    host => "192.168.0.1"
    protocol => "ssl-tcp"
    port => "8888"
    ssl_cacert => "/etc/logstash/cert.pem"
    #ssl_cert => "/etc/logstash/server.crt"
    #ssl_key => "/etc/logstash/private.key"
    ssl_verify => "true"
  }
}

```

Avoid the /tmp directory since the "logstash" user must have access rights.

---

<div class="post-metadata">

**Author:** ![Richard\_LaRoche](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richard_laroche/32/138643_2.png) [@Richard\_LaRoche](https://discuss.elastic.co/u/Richard_LaRoche)\
**Post date:** [November 18, 2024, 4:10pm UTC](https://discuss.elastic.co/t/encrypting-logstash-pipeline-output/370613/7 "2024-11-18T16:10:02Z")

</div>

thanks - will give that a try
