# How to enable authentication with logstash email output

**URL:** <https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473>\
**Category:** Logstash\
**Created:** [November 8, 2022, 8:28pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473 "2022-11-08T20:28:40Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 8, 2022, 8:28pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/1 "2022-11-08T20:28:40Z")

</div>

I want to learn how to use logstash with mailtrap smtp for development purposes. I installed logstash then ran this command:

```auto
/usr/share/logstash/bin/logstash -e 'input { stdin { } } output { email {
		to => "user@example.com"
		from => "user@example.com"
		subject => "Alert - %{title}"
		body => "content here"
		authentication => "plain"
		domain => "smtp.mailtrap.io:2525"
		username => "20ff3475e0c350"
		password => "594980b5a1be46"
    }
}'

```

Once logstash is up and running, I type something and press enter. This causes the error below:

```auto
[ERROR] 2022-11-08 19:34:59.861 [[main]>worker1] email - Something happen while delivering an email {:exception=>#<Net::SMTPAuthenticationError: 503 5.5.1 Error: authentication not enabled

```

How do I enable authentication? Or what am I doing wrong? I also can't find any documentation on what are acceptable values for the `authentication` property.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [November 9, 2022, 5:59am UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/2 "2022-11-09T05:59:17Z")

</div>

You have the incorrect configuration:

```auto
 {
		to => "user@example.com"
		from => "user@example.com"
		subject => "Alert - %{title}"
		body => "content here"
		authentication => "plain"
		domain => "smtp.mailtrap.io" #Pplease enter domain only, not include port
        port =>2525 # port used to communicate with the mail server
		username => "20ff3475e0c350"
		password => "594980b5a1be46"
    }

```

You can view more detail about email configuration in here  
[Email output plugin | Logstash Reference [8.5] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-email.html#plugins-outputs-email-domain)

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 9, 2022, 6:17am UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/3 "2022-11-09T06:17:18Z")

</div>

> [@tatdat](#):
>
> ```auto
> {
> to => "user@example.com"
> from => "user@example.com"
> subject => "Alert - %{title}"
> body => "content here"
> authentication => "plain"
> domain => "smtp.mailtrap.io" #Pplease enter domain only, not include port
> port =>2525 # port used to communicate with the mail server
> username => "20ff3475e0c350"
> password => "594980b5a1be46"
> }
> 
> ```

Thanks for suggestion. I just tried your configuration. Now the error I get is:

```auto
[ERROR] 2022-11-09 06:16:40.507 [[main]>worker0] email - Something happen while delivering an email {:exception=>#<Errno::ECONNREFUSED: Connection refused - connect(2) for "localhost" port 2525>}

```

The credentials i shared in my original post are real and you can test with the same details to confirm the same errors.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [November 9, 2022, 6:21am UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/4 "2022-11-09T06:21:24Z")

</div>

Which is the logstash version you are using?

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 9, 2022, 2:04pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/5 "2022-11-09T14:04:04Z")

</div>

I tried on logstash 8.4.1 and logstash 8.5.0 and they both gave the same errors.

Did you actually get a success response on your end when you ran the logstash command? If so, can you post the response? And let me know which logstash version you used?

Thanks

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [November 9, 2022, 2:12pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/6 "2022-11-09T14:12:28Z")

</div>

From your logstash server, try to test connect to mail server with command

```auto
telnet smtp.mailtrap.io 2525

```

Is that working?

btw, try to add this args in the output email config

```auto
{
		.......
		domain => "smtp.mailtrap.io"
        address=> "smtp.mailtrap.io"
        .......
    }

```

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 9, 2022, 2:17pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/7 "2022-11-09T14:17:59Z")

</div>

> [@tatdat](#):
>
> `telnet smtp.mailtrap.io 2525`

Yes, I got this response:

```auto
telnet smtp.mailtrap.io 2525
Trying 3.219.2.182...
Connected to mailsend-smtp-classic-f3a4534c019a3e96.elb.us-east-1.amazonaws.com.
Escape character is '^]'.
220 smtp.mailtrap.io ESMTP ready

```

I also have a web application that has no trouble connecting and submitting emails to `smtp.mailtrap.io` on port 2525.

I also tried many combinations of `address, domain, port` and they all gave the `ECONNREFUSED` error. The only combination that gave a different error was the configuration i posted in my original question -- with the error being authentication not enabled.

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 9, 2022, 2:26pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/8 "2022-11-09T14:26:56Z")

</div>

I just tried this

```auto
/usr/share/logstash/bin/logstash -e 'input { stdin { } } output { email {
    to => "user@example.com"
    from => "user@example.com"
    subject => "Alert - %{title}"
    body => "content here"
    authentication => "plain"
    address => "smtp.mailtrap.io"
    domain => "smtp.mailtrap.io"
    port =>2525
    username => "20ff3475e0c350"
    password => "594980b5a1be46"
    }
}'

```

The system just hangs like this:

```auto
Using bundled JDK: /usr/share/logstash/jdk
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console
[WARN] 2022-11-09 14:25:02.474 [main] runner - NOTICE: Running Logstash as superuser is not recommended and won't be allowed in the future. Set 'allow_superuser' to 'false' to avoid startup errors in future releases.
[INFO] 2022-11-09 14:25:02.491 [main] runner - Starting Logstash {"logstash.version"=>"8.5.0", "jruby.version"=>"jruby 9.3.8.0 (2.6.8) 2022-09-13 98d69c9461 OpenJDK 64-Bit Server VM 17.0.4+8 on 17.0.4+8 +indy +jit [x86_64-linux]"}
[INFO] 2022-11-09 14:25:02.495 [main] runner - JVM bootstrap flags: [-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -Djruby.jit.threshold=0, -XX:+HeapDumpOnOutOfMemoryError, -Djava.security.egd=file:/dev/urandom, -Dlog4j2.isThreadContextMapInheritable=true, -Djruby.regexp.interruptible=true, -Djdk.io.File.enableADS=true, --add-exports=jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED, --add-opens=java.base/java.security=ALL-UNNAMED, --add-opens=java.base/java.io=ALL-UNNAMED, --add-opens=java.base/java.nio.channels=ALL-UNNAMED, --add-opens=java.base/sun.nio.ch=ALL-UNNAMED, --add-opens=java.management/sun.management=ALL-UNNAMED]
[WARN] 2022-11-09 14:25:02.868 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified
[INFO] 2022-11-09 14:25:04.561 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=>9600, :ssl_enabled=>false}
[INFO] 2022-11-09 14:25:05.240 [Converge PipelineAction::Create<main>] Reflections - Reflections took 178 ms to scan 1 urls, producing 125 keys and 438 values
[INFO] 2022-11-09 14:25:05.874 [Converge PipelineAction::Create<main>] javapipeline - Pipeline `main` is configured with `pipeline.ecs_compatibility: v8` setting. All plugins in this pipeline will default to `ecs_compatibility => v8` unless explicitly configured otherwise.
[INFO] 2022-11-09 14:25:06.863 [[main]-pipeline-manager] javapipeline - Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>2, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>250, "pipeline.sources"=>["config string"], :thread=>"#<Thread:0x27564684 run>"}
[INFO] 2022-11-09 14:25:07.513 [[main]-pipeline-manager] javapipeline - Pipeline Java execution initialization time {"seconds"=>0.65}
[INFO] 2022-11-09 14:25:07.587 [[main]-pipeline-manager] javapipeline - Pipeline started {"pipeline.id"=>"main"}
The stdin plugin is now waiting for input:
[INFO] 2022-11-09 14:25:07.658 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
Typing another test then press enter

```

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [November 9, 2022, 2:36pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/9 "2022-11-09T14:36:06Z")

</div>

It seems like the error disappeared.  
Add `--debug` on the Logstash run command , After logstash run success, enter sometext send see output.

```auto
/usr/share/logstash/bin/logstash --debug -e 'input { stdin { } } output { email {
    to => "user@example.com"
    from => "user@example.com"
    subject => "Alert - %{title}"
    body => "content here"
    authentication => "plain"
    address => "smtp.mailtrap.io"
    domain => "smtp.mailtrap.io"
    port =>2525
    username => "20ff3475e0c350"
    password => "594980b5a1be46"
    }
}'

```

When you see the log

```auto
[INFO] 2022-11-09 14:25:07.587 [[main]-pipeline-manager] javapipeline - Pipeline started {"pipeline.id"=>"main"}
The stdin plugin is now waiting for input:
[INFO] 2022-11-09 14:25:07.658 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
Typing another test then press enter

```

Enter some text to test

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 9, 2022, 2:40pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/10 "2022-11-09T14:40:43Z")

</div>

Oh wait!! it actually worked! The system wasn't actually hanging. It's just natural behaviour to not report anything when success. So to confirm, your suggesion with this command yielded success:

```auto
/usr/share/logstash/bin/logstash -e 'input { stdin { } } output { email {
    to => "user@example.com"
    from => "user@example.com"
    subject => "Alert - %{title}"
    body => "content here"
    authentication => "plain"
    address => "smtp.mailtrap.io"
    domain => "smtp.mailtrap.io"
    port =>2525
    username => "20ff3475e0c350"
    password => "594980b5a1be46"
    }
}'

```

Thank you so much !!! I will create a youtube video and share with the internet

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [November 9, 2022, 2:50pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/11 "2022-11-09T14:50:24Z")

</div>

Glad to help you. I'm looking forward to your video, hehe 😆  
One more thing, if user/pass is **TRUE** , please **remove** it or change to ` ******* `

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 10, 2022, 5:28pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/12 "2022-11-10T17:28:44Z")

</div>

Thanks, here's the video I made thanks to your assistance!

[![](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9eae4f83a07100d4a2ace9ea3104944ca281bede.jpeg "APM with Elasticsearch 8.x - Part 3: Email Alerts via Server Log Connector") ](https://www.youtube.com/watch?v=P6eq8vOlO9k)

I used your mailtrap solution at 14:50 of the video.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2022, 5:29pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473/13 "2022-12-08T17:29:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
