# How to connect Logstash with Elastic Cloud Elasticsearch via https

**URL:** <https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071>\
**Category:** Logstash\
**Created:** [May 16, 2018, 8:57am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071 "2018-05-16T08:57:00Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 16, 2018, 8:57am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/1 "2018-05-16T08:57:00Z")

</div>

I am having problems to connect my local Logstash with an Elastic Cloud Elasticsearch.

The following lines are placed within the output plugin in the config file:

> elasticsearch {  
> codec =\> json  
> manage\_template =\> false  
> hosts =\> ["[https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243](https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243)" ]  
> ssl =\> true  
> user =\> "cardoso\_fep\_user"  
> password =\> ""  
> index =\> "%{[@metadata][endpoint]}"  
> document\_type =\> "ObjectEvent"  
> document\_id =\> "%{epc}"   
> }

Inside of the logstash.yml I have:

> node.name: Logstash6  
> cloud.id: ":"  
> cloud.auth: "elastic:"  
> http.host: "localhost"  
> xpack.monitoring.enabled: true  
> xpack.monitoring.elasticsearch.url: ["[https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243](https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243)"]  
> xpack.monitoring.elasticsearch.username: cardoso\_fep\_user  
> xpack.monitoring.elasticsearch.password:

Inside of the Elastic Cloud Enterprise I've created an Elasticsearch and a Kibana node and haven't changed the elasticsearch.yml and kibana.yml files. Both nodes are working. I am able to log in.  
This is what I get:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27bfc0ed7180e698744805c42789ed7e2fc5acef.png)  
I don't know what I have to do to be able to connect my local Logstash with the Elastic Cloud Elasticsearch...

Does anyone have an idea?

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [May 16, 2018, 9:26am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/2 "2018-05-16T09:26:31Z")

</div>

Can you provide the configuration of logstash.

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 16, 2018, 11:03am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/3 "2018-05-16T11:03:28Z")

</div>

What do you mean? logstash.yml or the .config file?  
In the logstash.yml file I've done the changes as I've written above. In the configuration file I've described the elasticsearch output plugin also as above.

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [May 16, 2018, 1:37pm UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/4 "2018-05-16T13:37:23Z")

</div>

where u have mentioned the certificate or truststore certificate in logstash.conf file.without that u will get  
"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"  
It means that the certificates are not trusted and does not contain the root certificate for the generated node and client certificates)

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 17, 2018, 7:13am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/5 "2018-05-17T07:13:42Z")

</div>

That is a bit complicated. I am using my local laptop just to do some tests with the logstash configuration file. But I don't have access to the certificate, because it is not at my machine.

On the other hand, we have a virtual machine where we've installed docker. Then we've initialized a logstash instance inside of a docker container. In the virtual machine I've placed both files: logstash.yml and the config file. The same files that I have mentioned part of them above. I've mounted both files to the container where I've started logstash.

Do I have to mount the _certificate_ to the logstash container and give the path for the certificate to the field _cacert_ inside of the elasticsearch output plugin? How do I configure the fields inside of elasticsearch output plugin within the logstash config file?

I hope you could understand....

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [May 17, 2018, 9:29am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/6 "2018-05-17T09:29:20Z")

</div>

output {  
elasticsearch {  
hosts =\> ............  
user =\> provide the user  
password =\> provide the pwd  
ssl =\> true  
ssl\_certificate\_verification =\> true  
truststore =\> "/path/to/truststore.jks"  
truststore\_password =\> changeit  
}  
}  
I just provided the sample.Please check and configure that whether is truststore or root\_ca .

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 17, 2018, 10:38am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/7 "2018-05-17T10:38:25Z")

</div>

Thanks a lot for the sample!

I actually have gotten a .crt file. Then I've done like that:  
elasticsearch {  
codec =\> json  
manage\_template =\> false  
hosts =\> ["[https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243](https://e95444bf74974e44b8c8011d48c96f25.rb-elasticsearch.de.bosch.com:9243)" ]  
user =\> "cardoso\_fep\_user"  
password =\> "mypassword"  
index =\> "%{[@metadata][endpoint]}"  
document\_type =\> "ObjectEvent"  
document\_id =\> "%{epc}"  
ssl =\> true  
ssl\_certificate\_verification =\> true  
cacert =\> "pathtoctrfile/crtfile.crt"  
}

But it continues with the same problem...  
Do you know if there is a way to do that with a crt file?

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 17, 2018, 11:04am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/8 "2018-05-17T11:04:09Z")

</div>

I've added the following line in the logstash.yml file:

`xpack.monitoring.elasticsearch.ssl.ca: /path/to/ca.crt`

and the pipeline doesn't start anymore.

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf073e8e1aa3a621268e1a7e561437f0727b558a.png)

---

<div class="post-metadata">

**Author:** ![Dvikas](https://avatars.discourse-cdn.com/v4/letter/d/a9adbd/32.png) [@Dvikas](https://discuss.elastic.co/u/Dvikas)\
**Post date:** [May 17, 2018, 11:07am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/9 "2018-05-17T11:07:19Z")

</div>

error is related to certificate.did u copy the ca.crt file in your logstash folder.I am talking about same ca.crt file which is used in elasticsearch.

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 17, 2018, 11:25am UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/10 "2018-05-17T11:25:03Z")

</div>

Yes, I've done that.

When I start a docker I do like that:

docker run -d -v /path/logstash/pipeline/:/path/logstash/pipeline/ -v /path/logstash/config/:/path/logstash/config/ **-v /pathtoctrlfile/:/pathtoctrlfile/** --name cardoso -p 9600:9600 --net host hostname/elastic.co/logstash:5.6.8

I mount the crt file of my virtual machine to my logtash container. In the config file I give the path of the crt file inside of the container:  
`cacert => "pathtoctrfile/crtfile.crt"`  
and in the logstash.yml I've added that:  
`xpack.monitoring.elasticsearch.ssl.ca: pathtoctrfile/crtfile.crt`

---

<div class="post-metadata">

**Author:** ![EloaCardoso](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@EloaCardoso](https://discuss.elastic.co/u/EloaCardoso)\
**Post date:** [May 17, 2018, 1:52pm UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/11 "2018-05-17T13:52:49Z")

</div>

I really don't understand that... I've done exactly like here:  
[https://www.elastic.co/guide/en/x-pack/5.6/logstash.html#ls-http-ssl](https://www.elastic.co/guide/en/x-pack/5.6/logstash.html#ls-http-ssl)  
and it doesn't help...  
[ERROR][logstash.pipeline] Error registering plugin?  
I don't get it 😥

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2018, 1:52pm UTC](https://discuss.elastic.co/t/how-to-connect-logstash-with-elastic-cloud-elasticsearch-via-https/132071/12 "2018-06-14T13:52:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
