# How to configure filebeat to use a particular cipher suite

**URL:** <https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 3, 2016, 11:04am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790 "2016-06-03T11:04:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sai\_Birada](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_birada/32/142367_2.png) [@Sai\_Birada](https://discuss.elastic.co/u/Sai_Birada)\
**Post date:** [June 3, 2016, 11:04am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790/1 "2016-06-03T11:04:39Z")

</div>

I want filebeat to send logs over tls using AES256-SHA cipher, I found cipher\_suites option in tls options page of filebeat configuration. But when i used it, I am getting the following error  
Exiting: error loading config file: YAML config parsing failed on logstash.yml: yaml: line 15: found character that cannot start any token  
Following is my configuration file  
filebeat:  
prospectors:  
-  
paths:  
- "/root/filebeat/data.log"

```
  input_type: log
  document_type: log
  registry_file: /var/lib/filebeat/registry

```

output:  
logstash:  
hosts: ["10.10.35.66:5044"]  
tls:  
certificate\_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]  
cipher\_suites: ["AES128/256"]

logging:  
to\_syslog: false  
to\_files: true

files:  
path: /var/log/filebeat  
name: filebeat.log  
rotateeverybytes: 10485760  
keepfiles: 7  
level: debug

---

<div class="post-metadata">

**Author:** ![adioss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adioss/32/10174_2.png) [@adioss](https://discuss.elastic.co/u/adioss)\
**Post date:** [June 3, 2016, 5:42pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790/2 "2016-06-03T17:42:57Z")

</div>

Maybe check [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-output-tls.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-output-tls.html)  
but i think that there are typo on doc. eg: RSA-AES256-CBC-SHA is in fact RSA-AES-256-CBC-SHA  
so something like: cipher\_suites: [RSA-AES-256-CBC-SHA] should work?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 6, 2016, 2:26pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790/3 "2016-06-06T14:26:35Z")

</div>

here is a list of ciphers currently available: [https://github.com/elastic/beats/blob/master/libbeat/outputs/tls.go#L173](https://github.com/elastic/beats/blob/master/libbeat/outputs/tls.go#L173)

File is yaml, either use:

```auto
    cipher_suites: 
      - RSA-AES-256-CBC-SHA

```

or

```auto
    cipher_suites: ["RSA-AES-256-CBC-SHA"]

```

GIthub issue for typos here: [https://github.com/elastic/beats/issues/1801](https://github.com/elastic/beats/issues/1801)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2016, 11:04am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-use-a-particular-cipher-suite/51790/4 "2016-06-24T11:04:49Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
