# Filebeat 6.1.1 not connecting to logstash over ssl

**URL:** <https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 19, 2018, 6:56pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291 "2018-01-19T18:56:59Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 19, 2018, 6:56pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/1 "2018-01-19T18:56:59Z")

</div>

I am having an issue with my ssl connection to logstash, Filebeat says everything is ok,

```auto
  C:\filebeat>filebeat test output
logstash: logstash:5044...
  connection...
    parse host... OK
    dns lookup... OK
    addresses: xx.xx.xx.xx
    dial up... OK
  TLS...
    security: server's certificate chain verification is enabled
    handshake... OK
    TLS version: TLSv1.2
    dial up... OK
  talk to server... OK

```

ran `>filebeat -c filebeat.yml -e -d "*"`  
didn't show any issues.

But on Logstash I see the connection was closed,

```auto
**[2018-01-19T18:21:47,080][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.**
**0:5044, remote: undefined] Exception: An existing connection was forcibly closed**
 **by the remote host,**

```

filebeat.yml

```auto
filebeat.prospectors:

- type: log

   enabled: true
 
  paths:
    #- /var/log/*.log
    - c:\fileuploads\*
name: Filebeat1
output.logstash:
  # The Logstash hosts
  hosts: ["logstash:5044"]
  protocol: "https"
  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  ssl.certificate_authorities: ["c:\\certs\\ca\\ca.crt"]

  # Certificate for SSL client authentication
  ssl.certificate: "c:\\certs\\filebeat1\\filebeat1.crt"

  # Client Certificate Key
  ssl.key: "c:\\certs\\filebeat1\\filebeat1.key"

```

* * *

logstash beats config,

```auto
input { 
	beats {
	port => 5044
	codec => "json"
	ssl => true
	ssl_certificate_authorities =>	["D:\logstash-6.1.1\config\ca\ca.crt"]
	ssl_certificate => "D:\logstash-6.1.1\config\logstash\logstash.crt"
	ssl_key => "D:\logstash-6.1.1\config\logstash\logstash.key"	
	} 
 }

```

any ideas?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 19, 2018, 8:11pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/2 "2018-01-19T20:11:13Z")

</div>

@GSCully Can you start logstash in with debug turn on? `bin/logstash --log.level debug` This should give us a bit more idea what is happening.

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 19, 2018, 9:32pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/3 "2018-01-19T21:32:04Z")

</div>

thankjs, it appears a cert is bad?

[2018-01-19T21:26:42,822][DEBUG][org.logstash.netty.SslSimpleBuilder] Certificate Authorities: [D:\logstash-6.1.1\config\ca\ca.crt]  
[2018-01-19T21:26:42,822][DEBUG][org.logstash.netty.SslSimpleBuilder] Load certificates collection  
[2018-01-19T21:26:42,822][DEBUG][org.logstash.netty.SslSimpleBuilder] Loading certificates from file D:\logstash-6.1.1\config\ca\ca.crt  
[2018-01-19T21:26:42,838][DEBUG][org.logstash.netty.SslSimpleBuilder] Available ciphers:...  
[2018-01-19T21:26:42,854][DEBUG][org.logstash.netty.SslSimpleBuilder] Certificate Authorities: [D:\logstash-6.1.1\config\ca\ca.crt]  
[2018-01-19T21:26:42,854][DEBUG][org.logstash.netty.SslSimpleBuilder] Load certificates collection  
[2018-01-19T21:26:42,854][DEBUG][org.logstash.netty.SslSimpleBuilder] Loading certificates from file D:\logstash-6.1.1\config\ca\ca.crt  
[2018-01-19T21:26:42,869][DEBUG][org.logstash.netty.SslSimpleBuilder] TLS: [TLSv1, TLSv1.1, TLSv1.2]  
[2018-01-19T21:26:42,869][DEBUG][org.logstash.netty.SslSimpleBuilder] TLS: [TLSv1, TLSv1.1, TLSv1.2]  
[2018-01-19T21:26:42,885][DEBUG][io.netty.util.internal.JavassistTypeParameterMatcherGenerator] Generated: io.netty.util.internal. **matchers**.org.logstash.beats.AckMatcher  
[2018-01-19T21:26:42,885][DEBUG][io.netty.util.internal.JavassistTypeParameterMatcherGenerator] Generated: io.netty.util.internal. **matchers**.org.logstash.beats.BatchMatcher  
[2018-01-19T21:26:42,947][DEBUG][io.netty.handler.ssl.OpenSslEngine] SSL\_read failed: OpenSSL error: error:10000412:SSL routines:OPENSSL\_internal:SSLV3\_ALERT\_BAD\_CERTIFICATE  
[2018-01-19T21:26:42,979][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5044, remote: undefined] Exception: javax.net.ssl.SSLHandshakeException: error:10000412:SSL routines:OPENSSL\_internal:SSLV3\_ALERT\_BAD\_CERTIFICATE  
[2018-01-19T21:26:42,979][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5044, remote: undefined] Exception: An existing connection was forcibly closed by the remote host

Would that be the ca cert? or the logstash cert or beats? I suspect beats.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 19, 2018, 9:39pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/4 "2018-01-19T21:39:59Z")

</div>

I suspect beats too, let's check if you can do server auth only without doing client auth.

Remove the following lines:

```auto
 # Certificate for SSL client authentication
  ssl.certificate: "c:\\certs\\filebeat1\\filebeat1.crt"

  # Client Certificate Key
  ssl.key: "c:\\certs\\filebeat1\\filebeat1.key"

```

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 19, 2018, 10:17pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/5 "2018-01-19T22:17:46Z")

</div>

I don't seethe same errors but I also don't see a connection,  
[io.netty.util.internal.JavassistTypeParameterMatcherGenerator] Generated: io.netty.util.internal. **matchers**.org.logstash.beats.AckMatcher  
[2018-01-19T22:15:00,879][DEBUG][io.netty.util.internal.JavassistTypeParameterMatcherGenerator] Generated: io.netty.util.internal. **matchers**.org.logstash.beats.BatchMatcher  
[2018-01-19T22:15:02,847][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2a9aab53 sleep\>"}  
[2018-01-19T22:15:07,425][INFO][org.logstash.beats.BeatsHandler] [local: 0.0.0.0:5044, remote: undefined] Exception: not an SSL/TLS record: 3f0d0a650d0a  
[2018-01-19T22:15:07,832][DEBUG][logstash.config.source.local.configpathloader] Skipping the following files while reading config since they don't match the specified glob pattern {:files=\>["D:/logstash-6.1.1/CONTRIBUTORS", "D:/logstash-6.1.1/Gemfile", "D:/logstash-6.1.1/Gemfile.lock", "D:/logstash-6.1.1/LICENSE", "D:/logstash-6.1.1/NOTICE.TXT", "D:/logstash-6.1.1/bin", "D:/logstash-6.1.1/config", "D:/logstash-6.1.1/data", "D:/logstash-6.1.1/lib", "D:/logstash-6.1.1/logs", "D:/logstash-6.1.1/logstash-core", "D:/logstash-6.1.1/logstash-core-plugin-api", "D:/logstash-6.1.1/modules", "D:/logstash-6.1.1/tools", "D:/logstash-6.1.1/vendor"]}  
[2018-01-19T22:15:07,832][DEBUG][logstash.config.source.local.configpathloader] Reading config file {:config\_file=\>"D:/logstash-6.1.1/logstash.conf"}  
[2018-01-19T22:15:07,832][DEBUG][logstash.agent] Converging pipelines  
[2018-01-19T22:15:07,847][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2a9aab53 sleep\>"}  
[2018-01-19T22:15:12,847][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2a9aab53 sleep\>"}  
[2018-01-19T22:15:17,831][DEBUG][logstash.config.source.local.configpathloader] Skipping the following files while reading config since they don't match the specified glob pattern {:files=\>["D:/logstash-6.1.1/CONTRIBUTORS", "D:/logstash-6.1.1/Gemfile", "D:/logstash-6.1.1/Gemfile.lock", "D:/logstash-6.1.1/LICENSE", "D:/logstash-6.1.1/NOTICE.TXT", "D:/logstash-6.1.1/bin", "D:/logstash-6.1.1/config", "D:/logstash-6.1.1/data", "D:/logstash-6.1.1/lib", "D:/logstash-6.1.1/logs", "D:/logstash-6.1.1/logstash-core", "D:/logstash-6.1.1/logstash-core-plugin-api", "D:/logstash-6.1.1/modules", "D:/logstash-6.1.1/tools", "D:/logstash-6.1.1/vendor"]}  
[2018-01-19T22:15:17,831][DEBUG][logstash.config.source.local.configpathloader] Reading config file {:config\_file=\>"D:/logstash-6.1.1/logstash.conf"}  
[2018-01-19T22:15:17,831][DEBUG][logstash.agent] Converging pipelines  
[2018-01-19T22:15:17,847][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2a9aab53 sleep\>"}  
[2018-01-19T22:15:22,862][DEBUG][logstash.pipeline] Pushing flush onto pipeline {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x2a9aab53 sleep\>"}  
I telnet in and that is the undefined ssl error came from, the filebeat server is where i ran telnet.

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 19, 2018, 10:34pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/6 "2018-01-19T22:34:13Z")

</div>

from filebeat I got this,  
ERR Failed to connect: remote error: tls: handshake failure

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 19, 2018, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/7 "2018-01-19T22:35:59Z")

</div>

Seems to be ok now, I added back the client certs and data started flowing.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [January 22, 2018, 3:12pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/8 "2018-01-22T15:12:25Z")

</div>

You did not regenerate the certs?

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 22, 2018, 11:37pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/9 "2018-01-22T23:37:03Z")

</div>

No I used the existing certs, I had a wrong path in filebeat for the drop folder. But after a restart logstash throwing different errors. I installed x-pack for monitoring.

Should I open another thread for the below?  
I did not use IP's in the SSL, so don't know why it is trying to resolve them?

[2018-01-22T23:02:26,686][WARN][logstash.outputs.elasticsearch] UNEXPECTED POOL ERROR {:e=\>#\<Manticore::UnknownException: Host name '10.210.0.129' does not match the certificate subject provided by the peer (CN=elastic1)\>}  
[2018-01-22T23:02:26,686][WARN][logstash.outputs.elasticsearch] Error while performing sniffing {:error\_message=\>"Host name '10.210.0.129' does not match the certificate subject provided by the peer (CN=elastic1)", :class=\>"Manticore::UnknownException", :backtrace=\>["D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.1-java/lib/manticore/response.rb:37:in `block in initialize'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.1-java/lib/manticore/response.rb:79:in`call'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:74:in `perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:287:in`perform\_request\_to\_url'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:274:in `block in perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:369:in`with\_connection'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:273:in `perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:163:in`check\_sniff'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:156:in `sniff!'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:145:in`block in start\_sniffer'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:127:in `until_stopped'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:143:in`block in start\_sniffer'"]}  
[2018-01-22T23:02:26,733][WARN][logstash.licensechecker.licensereader] UNEXPECTED POOL ERROR {:e=\>#\<Manticore::UnknownException: Host name '10.210.0.129' does not match the certificate subject provided by the peer (CN=elastic1)\>}  
[2018-01-22T23:02:26,733][WARN][logstash.licensechecker.licensereader] Error while performing sniffing {:error\_message=\>"Host name '10.210.0.129' does not match the certificate subject provided by the peer (CN=elastic1)", :class=\>"Manticore::UnknownException", :backtrace=\>["D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.1-java/lib/manticore/response.rb:37:in `block in initialize'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/manticore-0.6.1-java/lib/manticore/response.rb:79:in`call'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:74:in `perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:287:in`perform\_request\_to\_url'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:274:in `block in perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:369:in`with\_connection'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:273:in `perform_request'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:163:in`check\_sniff'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:156:in `sniff!'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:145:in`block in start\_sniffer'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:127:in `until_stopped'", "D:/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/logstash-output-elasticsearch-9.0.2-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:143:in`block in start\_sniffer'"]}

---

<div class="post-metadata">

**Author:** ![GSCully](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gscully/32/26104_2.png) [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Post date:** [January 23, 2018, 7:24pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/10 "2018-01-23T19:24:25Z")

</div>

I figured the vm logstash is on needed replacement so I start over, did not install x-pack as that seems too cause to many issues.  
After adding the CA cert to the Java keystore it seems to be working so I'm going to go without Logstash monitoring for now.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2018, 7:24pm UTC](https://discuss.elastic.co/t/filebeat-6-1-1-not-connecting-to-logstash-over-ssl/116291/11 "2018-02-20T19:24:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
