Fleet Settings - Elasticsearch output configuration (YAML)

Hello everyone,

Do I need to create separate agent policies for Linux and Windows hosts?

The reason is the ca certs are in different location depending on the OS

ssl.certificate_authorities: ["/etc/elasticsearch/certs/cert.crt"]
ssl.certificate_authorities: ["C:/Program Files/Elastic/Agent/certs/cert.crt"]

Currently, the agent doesn't support keystores? so username and password can be specified in this YAML too? or each individual (fileabeat.yaml, metricbeat.yaml, etc)

Thank you for your help

We recommend inlining the cert instead of using paths in this case, For example

ssl.certificate_authorities:
  - |
   -----BEGIN CERTIFICATE-----
   MIIDSTCCAjGgAwIBAgIUSG64XLc34rcXzT6jbmo13itoZuYwDQYJKoZIhvcNAQEL
   BQAwNDEygDAGA1UEAxMpRWxhc3RpYyBDZXJ0aWZpY2F0ZSBUb29sIEF1dG9nZW5l
   cmF0ZWQgQ0EwHhcNMjAxMjIyMTg1NTA0WhcNMjMxMjIyMTg1NTA0WjA0MTIwMAYD
   VQQDEylFbGFzdGljIENlcnRpZmljYXRlIFRvb2wgAXV0b2dlbmVyYXRlZCBDQTCC
   ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAManUXssX6WI5iObj/EfOOOt
   XJn2t7EfSVylY9v79VgtQ7iZHoLfLxPH4DqHutno0w6pqqnLD0kv9e9GFeobI3d9
   dvJtb2ChRiJsX9AyU4jrioafUhNHibvD0r8xECeWILqSG34vkjHwX4/YHrS5GG9i
   zj0ZkeLm3L7//dTLeZRQ0h0SahUo0YR58BvndTl+bedEJNuQICTA8zuYMG+ohOjv
   jltqjDx2/PqFrtsQCeY2HYZnbGza++vMcyeOUcX6I2HkJOURNuh0I+nQpZvt+nVF
   cAjeZY8kBZCIJ0iZ0SHenrSvM7G2KnnduGYqIxAHGTzWkJwM/K7sM34ltYOm0oUC
   AwEAAaNTMFEwHQYDVR0OBBYEFNAA3vwPOD00bV1MDQEnA/i3XutWMB8GA1UdIwQY
   MBaAFNAA3vwPOD00bV1MDQEnA/i3XutWMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZI
   hvcNAQELBQADggEBAKHegTIvphV+y7/XZ5dv5BEH1Nf9rSBd1qs0F2Bz8A7pnyxM
   XFQtlkx386EDGQZeYXB63mgXLoayzxSnAzqo+TFZlbxg8Lfm245H7hqjyGqVXynt
   iexAFkevXN4QcxT/G4deF2hIgTrlU/PsW6xgA0tckpLpnp+GJd5dBnhsyf1NmqDB
   CJKNrPsOM3gGPwM52720tOhwHRyTHdu5oLmWGg1xBXXNM0OB8ETr19xcLcelcOnF
   o55ozZknr0pBccEdWDbHRSaTdzJwTThFkaxSAry8KlNmjuh9qmb9+jlgVI8eiVgA
   ya/QYmC2OsPAQxZTBp10IqKiWFOz6OchQISle1k=
   -----END CERTIFICATE-----

@MichelLaterman

Thank you, that makes perfect sense

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.