# Filebeat Error

**URL:** <https://discuss.elastic.co/t/filebeat-error/346093>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2023, 7:15am UTC](https://discuss.elastic.co/t/filebeat-error/346093 "2023-10-31T07:15:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Phyo\_WaThone\_Win](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phyo_wathone_win/32/125590_2.png) [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Post date:** [October 31, 2023, 7:15am UTC](https://discuss.elastic.co/t/filebeat-error/346093/1 "2023-10-31T07:15:35Z")

</div>

Hello team,

When I setup the auditbeat, I face some issues in my elk server.

Here is error information:

> x509: certificate signed by unknown authority.

Could you please help for this issues?

Thanks,

---

<div class="post-metadata">

**Author:** ![suman.kumar](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@suman.kumar](https://discuss.elastic.co/u/suman.kumar)\
**Post date:** [November 1, 2023, 1:46pm UTC](https://discuss.elastic.co/t/filebeat-error/346093/2 "2023-11-01T13:46:30Z")

</div>

Hi @Phyo_WaThone_Win

could you please share the output of below cmd for further comment:

.\auditbeat.exe test output

Also could you please share the content of "Elasticsearch Output" part from auditbeat.yml.

---

<div class="post-metadata">

**Author:** ![Phyo\_WaThone\_Win](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phyo_wathone_win/32/125590_2.png) [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Post date:** [November 2, 2023, 5:05am UTC](https://discuss.elastic.co/t/filebeat-error/346093/3 "2023-11-02T05:05:25Z")

</div>

Thanks for your reply.

Here is my auditbeat output when I run the auditbeat.

`Get \"https://10.10.10.2:9200\": x509: certificate signed by unknown authority]","service.name":"auditbeat","ecs.version":"1.6.0"} Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at https://10.10.10.2:9200: Get "https://10.10.10.2:9200": x509: certificate signed by unknown authority]`

And, here is my elasticsearch output from my auditbeat.yml:

> output.elasticsearch:
> 
> # Array of hosts to connect to.
> 
> hosts: ["10.10.10.2:9200"]

> # Protocol - either `http` (default) or `https`.
> 
> protocol: "https"

> # Authentication credentials - either API key or username/password.
> 
> #api\_key: "id:api\_key"  
> username: "user"  
> password: "mypassword"  
> `

---

<div class="post-metadata">

**Author:** ![suman.kumar](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@suman.kumar](https://discuss.elastic.co/u/suman.kumar)\
**Post date:** [November 2, 2023, 9:54am UTC](https://discuss.elastic.co/t/filebeat-error/346093/4 "2023-11-02T09:54:22Z")

</div>

Hi @Phyo_WaThone_Win

As I can see you have configured output as elasticsearch is https.

So you have to provide elasticsearch's SSL certificate for handshake between the auditbeat and elasticsearch.

Could you please copy the SSL certificate to the machine where auditbeat is running and add a below configuration in output.elasticsearch stanza.

ssl.certificate\_authorities: "C:\tmp\elasticsearch-ca.pem"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2023, 11:54am UTC](https://discuss.elastic.co/t/filebeat-error/346093/5 "2023-11-30T11:54:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
