# Encryption between filebeat and Elastic Service?

**URL:** https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060
**Category:** Elasticsearch
**Created:** [September 13, 2021, 11:09am UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060 "2021-09-13T11:09:15Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![Chinnu](https://avatars.discourse-cdn.com/v4/letter/c/6f9a4e/32.png) [@Chinnu](https://discuss.elastic.co/u/Chinnu)
#### Post date: [September 13, 2021, 11:09am UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/1 "2021-09-13T11:09:15Z")

</div>

Hello,

When filebeat uses cloud.id and api\_key fields, is the connection between filebeat and ElasticCloud encrypted ? Has anyone already checked this before ?  
It would be helpful if you can point me to related documentation.

Thanks in advance for your reponse.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 13, 2021, 11:47am UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/2 "2021-09-13T11:47:18Z")

</div>

As far as I know Elastic Cloud only supports encrypted connections.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 13, 2021, 2:06pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/3 "2021-09-13T14:06:56Z")

</div>

Hi @Chinnu welcome to the community and considering Elastic Cloud

First , yes ALL communications to and from all Elastic Cloud components is via HTTPS.

There are also many other security features see here.

> **[Securing your deployment | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-security.html)**

You can also setup SAML

> **[Secure your clusters with SAML | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-securing-clusters-SAML.html)**

There are further security features such as IP Filters and Private Link connections as well.

> **[Traffic Filtering | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-traffic-filtering-deployment-configuration.html)**

---

<div class="post-metadata">

### Author: ![Chinnu](https://avatars.discourse-cdn.com/v4/letter/c/6f9a4e/32.png) [@Chinnu](https://discuss.elastic.co/u/Chinnu)
#### Post date: [September 14, 2021, 7:45am UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/4 "2021-09-14T07:45:37Z")

</div>

Thank you @Christian_Dahlqvist

---

<div class="post-metadata">

### Author: ![Chinnu](https://avatars.discourse-cdn.com/v4/letter/c/6f9a4e/32.png) [@Chinnu](https://discuss.elastic.co/u/Chinnu)
#### Post date: [September 14, 2021, 7:52am UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/5 "2021-09-14T07:52:06Z")

</div>

Thanks @stephenb for the documentation.  
I have gone through it: [Securing your deployment | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-security.html)  
For a user provisioned instance, I understand that we can have encrypted connections via Public Key Infrastructure ( Java key store, trust store, keys etc).

But, in Elastic Cloud Service, we use cloud.id and api\_key. In this case, is the communication between filebeat and Cloud encrypted first and then, secrets ( api key ) are then sent to Clould Cluster ?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 14, 2021, 1:52pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/6 "2021-09-14T13:52:40Z")

</div>

Hi @Chinnu

Yes. The connection itself is HTTPS so any credential passed are via HTTPS / Encrypted.

`cloud.id` under the covers is just and encoded version of the https endpoints

There is no way to communicate with Elastic Cloud Resources (Elasticsearch, Kibana, APM, FLeet) in and unencrypted way.

---

<div class="post-metadata">

### Author: ![Echaves](https://avatars.discourse-cdn.com/v4/letter/e/71c47a/32.png) [@Echaves](https://discuss.elastic.co/u/Echaves)
#### Post date: [September 15, 2021, 11:14pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/7 "2021-09-15T23:14:32Z")

</div>

Hi @stephenb  
I take advantage of the space, to ask the following and suddenly not open another unnecessary thread.  
I will handle PII data in the information that I will store in the elastic indexes, therefore I must implement **encryption at rest of the indexes**.  
Would you have any information or documentation about it?  
What options can I have?

Thanks in advance

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 15, 2021, 11:25pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/8 "2021-09-15T23:25:38Z")

</div>

Elastic Cloud has a very strong Security Posture

You should read this closely.  
[https://www.elastic.co/cloud/security](https://www.elastic.co/cloud/security)

You should also read this closely  
[https://www.elastic.co/security-and-compliance](https://www.elastic.co/security-and-compliance)

And about all the Security Features Here

> **[Securing your deployment | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-security.html)**

To Directly to you question from the first link.

> ## We’ve built In logical security controls
> 
> We've taken significant measures to ensure that Elastic Cloud customer data cannot be read, copied, modified, or deleted during electronic transmission, transport, or storage through unauthorized means. To reduce the likelihood of vulnerability-related incidents, the Elastic Cloud team deploys Elasticsearch instances based on the latest operating system kernels, and patches the computing “fleet” whenever a critical CVE (i.e., "Common Vulnerability and Exposure," in security-speak) is discovered in any component software. Similarly, Elastic software, including Elastic Stack components and Elastic Cloud Enterprise, used in the provisioning of Elastic Cloud SaaS offerings, is updated as soon as it is released to ensure the latest versions are deployed.
> 
> To protect customer data, Elastic Cloud clusters are equipped with Elastic security features that randomly assign individual passwords. Clusters are deployed behind redundant proxies and are not visible to internet scanning. Transport Layer Security (TLS) encrypted communication from the Internet is provided in the default configuration. Elasticsearch nodes run in isolated containers, configured according to the principle of least privilege, and with restrictions on system calls and allowed root operations. Elasticsearch nodes communicate using TLS (requires customer to select 6.0 or later versions of the Elastic Stack). **Cluster data is encrypted at rest.** We support IP address-based access controls so users may restrict access to their hosted deployments by filtering specific IP ranges. Additional network layer security is available on Amazon with AWS PrivateLink integration. Our support for AWS PrivateLink helps eliminate the exposure of your data to the public internet. This is accomplished by securing the network connection between your Amazon VPCs, applications, and your Elastic Cloud deployments on AWS. API access is limited to Elasticsearch APIs, and no remote access to the instance or container at the Linux level is allowed. Containers have no means of setting up communication with containers from another cluster.

And Finally Depending on your Company's Needs you should reach out to [sales@elastic.co](mailto:sales@elastic.co) and engage with a Solution Architect Like Me.

Typically a company will go through a joint cloud review etc. when it involves PII.

---

<div class="post-metadata">

### Author: ![Echaves](https://avatars.discourse-cdn.com/v4/letter/e/71c47a/32.png) [@Echaves](https://discuss.elastic.co/u/Echaves)
#### Post date: [September 16, 2021, 1:51pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/9 "2021-09-16T13:51:24Z")

</div>

Good Morning @stephenb

Thanks for your answer, I saw in this information, that talk about Elastic Cloud. Do you have any information, about Elastic **OnPremise**?

Thanks again.

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [September 16, 2021, 2:13pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/10 "2021-09-16T14:13:52Z")

</div>

I think that this post is still accurate: [How should I encrypt data at rest with Elasticsearch?](https://discuss.elastic.co/t/how-should-i-encrypt-data-at-rest-with-elasticsearch/96)

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [September 16, 2021, 2:33pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/11 "2021-09-16T14:33:32Z")

</div>

For "Self Managed"

Well of course then all the host, network, disk, organization etc. Security is up to You.

The CVE Program still applies.

And if you engage in a commercial relationship you will have support and can get Professional Services to help with your Architecture, Design and Implementation

Some of the Security features of Elasticsearch are Commercial Licensed only  
A couple examples are : SSO / SAML, Field Level Security etc

You can look at all the features vs license here

> **[Subscriptions | Elastic Stack Products & Support | Elastic](https://www.elastic.co/subscriptions)**
>
> See subscription levels, pricing, and tiered features for on-prem deployments of the Elastic Stack (Elasticsearch Kibana, Beats, and Logstash), Elastic Cloud, and Elastic Cloud Enterprise.

Then, the actual Elasticsearch product / technical features (which are quite extensive) you will need to take a look at out docs about Securing Your Cluster.

> **[Secure the Elastic Stack | Elasticsearch Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-cluster.html)**

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 14, 2021, 2:33pm UTC](https://discuss.elastic.co/t/encryption-between-filebeat-and-elastic-service/284060/12 "2021-10-14T14:33:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
