# How to connect eck elasticsearch with eck logstash

**URL:** <https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [June 24, 2023, 7:31am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804 "2023-06-24T07:31:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Piyumitha\_Nirman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyumitha_nirman/32/122480_2.png) [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Post date:** [June 24, 2023, 7:31am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804/1 "2023-06-24T07:31:00Z")

</div>

eck logtash 8 version needs ca.crt of eck Elasticsearch. But i dont know how to access this ca.crt file using logstash. my log stash file has cacert location. but I don't know how to access ca.crt file.

```
        hosts => "quickstart-es-http:9200"
        user => "elastic"
        password => ""
        cacert => " ***********************"

```

Can someone give me a guide to accessing the Elasticsearch ca. crt file from Logstash?

---

<div class="post-metadata">

**Author:** ![Hemanth\_Gowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hemanth_gowda/32/23886_2.png) [@Hemanth\_Gowda](https://discuss.elastic.co/u/Hemanth_Gowda)\
**Post date:** [June 24, 2023, 2:52pm UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804/2 "2023-06-24T14:52:28Z")

</div>

You can get ca.cer in Elasticsearch pod. You might have to get the file from Elasticsearch pod and mount the same in logstash pod under some path and refer the same in logstash output plugin.

You also have option to skip SSL. However this is not recommended.

> **[Elasticsearch output plugin | Logstash Reference \[8.8\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl_verification_mode)**

---

<div class="post-metadata">

**Author:** ![Piyumitha\_Nirman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyumitha_nirman/32/122480_2.png) [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Post date:** [June 24, 2023, 4:27pm UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804/3 "2023-06-24T16:27:39Z")

</div>

I tried your solution previously. but it didn't work. It comes indentation issue. can you share an example logtash yaml for this?

---

<div class="post-metadata">

**Author:** ![Hemanth\_Gowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hemanth_gowda/32/23886_2.png) [@Hemanth\_Gowda](https://discuss.elastic.co/u/Hemanth_Gowda)\
**Post date:** [June 25, 2023, 6:40am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804/4 "2023-06-25T06:40:33Z")

</div>

May I know what you have tried. The skip SSL one? Can you please post your output plugin here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2023, 6:40am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804/5 "2023-07-23T06:40:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
