# Filebeat SSL to logstash

**URL:** <https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 3, 2017, 10:31am UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398 "2017-05-03T10:31:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mango](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Mango](https://discuss.elastic.co/u/Mango)\
**Post date:** [May 3, 2017, 10:31am UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398/1 "2017-05-03T10:31:08Z")

</div>

hi,  
I have a problem with filebeat sending logs to logstash when I use SSL(filebeat 5.3.0 logstash 5.2.2).

That is my config  
filebeat :

**output.logstash:**  
**hosts: ["127.0.0.1:5044"]**  
**ssl.enabled: true**  
**ssl.supported\_protocols: [TLSv1.2]**  
**ssl.certificate\_authorities: ["/usr/ELK/ca/test/ca.crt"]**

logstash:

**beats {**  
**port =\> 5044**  
**ssl =\> true**  
**ssl\_certificate =\> "/usr/ELK/ca/test/server.crt"**  
**ssl\_key =\> "/usr/ELK/ca/test/pserver.key"**  
**}**

It always show the error  
2017/05/03 10:13:04.389987 sync.go:85: ERR Failed to publish events caused by:  
read tcp 127.0.0.1:50527-\>127.0.0.1:5044: read: connection reset by peer  
2017/05/03 10:13:04.390041 single.go:91: INFO Error publishing events (retrying):  
read tcp 127.0.0.1:50527-\>127.0.0.1:5044: read: connection reset by peer

But when I "curl -v --tlsv1.2 --cacert /usr/ELK/ca/test/ca.crt [https://127.0.0.1:5044](https://127.0.0.1:5044)"  
it worked well. I have no idea what problems is.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 3, 2017, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398/2 "2017-05-03T13:54:30Z")

</div>

Please check your indentation in the Beat config. I couldn't tell due to the formatting of your post, but it should look like this.

```auto
output.logstash:
  hosts: ["127.0.0.1:5044"]
  ssl.enabled: true
  ssl.supported_protocols: [TLSv1.2]
  ssl.certificate_authorities: ["/usr/ELK/ca/test/ca.crt"]

```

---

<div class="post-metadata">

**Author:** ![Mango](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@Mango](https://discuss.elastic.co/u/Mango)\
**Post date:** [May 3, 2017, 11:43pm UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398/3 "2017-05-03T23:43:21Z")

</div>

Thank you for your reply, I edited it wrongly on the web.But the filebeat config is the same as what you posted.  
Is any other thing wrong which cause the SSL fault?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [May 9, 2017, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398/4 "2017-05-09T12:56:11Z")

</div>

The error message notes the connection being closed by Logstash. This can happen during TLS handshake or much later due to logstash timing out inactive connections. Try to ramp up the connectivity timeout in the beats input in Logstash. Also, have you checked the logstash-input-beats plugin version installed with your Logstash? Updating the plugin or moving to Logstash 5.4 might help here as well, as a few older versions of the plugin are prone to close perfectly valid connections.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2017, 1:00pm UTC](https://discuss.elastic.co/t/filebeat-ssl-to-logstash/84398/5 "2017-06-06T13:00:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
