# How can FileBeat access Kibana over SSL?

**URL:** <https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 23, 2020, 11:49pm UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420 "2020-11-23T23:49:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![houmie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houmie/32/78999_2.png) [@houmie](https://discuss.elastic.co/u/houmie)\
**Post date:** [November 23, 2020, 11:49pm UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/1 "2020-11-23T23:49:59Z")

</div>

Hello,

```auto
filebeat.inputs:
- type: log
  paths:
    - /var/log/app-uwsgi/app.json
  json.keys_under_root: true
  json.add_error_key: true
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: true
  reload.period: 10s
setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
  host: "api-s2.domain.net:5505"
  protocol: "https"
  ssl.enabled: true
  #ssl.verification_mode: none
output.elasticsearch:
  hosts: ["t1.domain.net:9102"]
  protocol: "https"
  username: "elastic"
  password: "xxxx"
  ssl.certificate_authorities:
    - /etc/filebeat/certs/ca.crt
processors:
  - drop_fields:
      fields: ["agent", "log", "input", "ecs"]
      ignore_missing: false

```

I have a certificate obtained from Let'sEncrypt for my Kibana setup. So it's fully CA certified.  
But when I run `filebeat setup` I get this:

> error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [https://api-s2.domain.net: ~~5505~~ /api/status](https://api-s2.domain.net:5505/api/status) fails: fail to execute the HTTP GET request: Get "[https://api-s2.domain.net: ~~5505~~ /api/status](https://api-s2.domain.net:5505/api/status)": x509: certificate signed by unknown authority. Response:

I could add `ssl.verification_mode: none` , but isn't that a security risk?

I prefer using the Let'sEncrypt SSL for Kibana instead of creating my own certificate through `elasticsearch-certutil cert --keep-ca-key --pem` .

The reason is that I would like to access my Kibana from anywhere from a browser. And for that to work I need CAs like lets encrypt, godaddy etc that are trusted by the browsers.

Certs created by `elasticsearch-certutil` are not recognised by browsers.

Any advise please? Thank you

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 24, 2020, 12:56am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/2 "2020-11-24T00:56:06Z")

</div>

Are you able to successfully `curl https://api-s2.domain.net:5505/api/status` from the Filebeat host? If so, can you share the exact `curl` command that worked?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![houmie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houmie/32/78999_2.png) [@houmie](https://discuss.elastic.co/u/houmie)\
**Post date:** [November 24, 2020, 7:32am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/3 "2020-11-24T07:32:47Z")

</div>

No, I'm not able to do this successfully. I get the error:

```auto
curl: (60) SSL certificate problem: unable to get local issuer certificate
More details here: https://curl.haxx.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

```

---

<div class="post-metadata">

**Author:** ![houmie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houmie/32/78999_2.png) [@houmie](https://discuss.elastic.co/u/houmie)\
**Post date:** [November 25, 2020, 7:17am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/4 "2020-11-25T07:17:44Z")

</div>

Hi Elastic Support Team,

Is there any logs I should provide or any other information you need?

Thank you

---

<div class="post-metadata">

**Author:** ![houmie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/houmie/32/78999_2.png) [@houmie](https://discuss.elastic.co/u/houmie)\
**Post date:** [November 26, 2020, 1:47pm UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/5 "2020-11-26T13:47:06Z")

</div>

Hi @shaunak,

I'm currently analysing the ELK stack (minus Logstash Plus FileBeat) to see if we could utilise this for our business. If FileBeats can't reach the central server over SSL as demonstrated, this is a security concern for us and we have to look for a different solution.

Before I move on too quickly, I would like know if this a bug that can be fixed by ticketing or not? A reply would be much appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 30, 2020, 3:00am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/6 "2020-11-30T03:00:27Z")

</div>

The fact that you aren't able to connect to Kibana with `curl` indicates that this isn't so much a Filebeat issue. I would suggest trying different options for the `curl` command until you can successfully connect to Kibana. Once you have a working `curl` command, please post it here and we can provide the corresponding Filebeat settings.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 30, 2020, 3:03am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/7 "2020-11-30T03:03:06Z")

</div>

> [@houmie](#):
>
> Hi Elastic Support Team,

Also, please note that these are **community** forums, not Elastic Support. We do our best to provide help here but there are no SLAs as such. If you are interested in Elastic Support (that comes with well-defined SLAs), you can find more information here: [https://www.elastic.co/services/](https://www.elastic.co/services/)

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2020, 5:03am UTC](https://discuss.elastic.co/t/how-can-filebeat-access-kibana-over-ssl/256420/8 "2020-12-28T05:03:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
