# How to setup Logstash agent secure SSL communication with RabbitMQ and eventually to ELK server

**URL:** <https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248>\
**Category:** Logstash\
**Created:** [May 10, 2017, 1:10pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248 "2017-05-10T13:10:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![satishkori](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@satishkori](https://discuss.elastic.co/u/satishkori)\
**Post date:** [May 10, 2017, 1:10pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/1 "2017-05-10T13:10:26Z")

</div>

Hi all,

Firstly does Logstash agent supports SSL with RabbitMQ?

if so ,could you list the steps to ships logs using logstash agent on one server to RabbitMQ server and finally the ELK server on another machine should be able to read it from the RabbitMQ queue.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 10, 2017, 1:47pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/2 "2017-05-10T13:47:41Z")

</div>

> Firstly does Logstash agent supports SSL with RabbitMQ?

The rabbitmq output plugin has an `ssl` option, so yes.

> if so ,could you list the steps to ships logs using logstash agent on one server to RabbitMQ server and finally the ELK server on another machine should be able to read it from the RabbitMQ queue.

I suspect nobody will take the time to describe this in any great detail. If you ask more specific questions you may have better luck getting response.

---

<div class="post-metadata">

**Author:** ![satishkori](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@satishkori](https://discuss.elastic.co/u/satishkori)\
**Post date:** [May 10, 2017, 3:14pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/3 "2017-05-10T15:14:30Z")

</div>

Thnx for the reply.However I have already setup using the below configuration but I am getting SSL communication error in logstash logs and logstash agent is unable to connect to RabbitMQ server.

vi /etc/rabbitmq/rabbitmq.config  
%% -_- mode: erlang -_-  
[{rabbit, [{ssl, true},  
{ssl\_listeners, ["127.0.0.1", 15671]},  
{auth\_mechanisms, ['EXTERNAL', 'PLAIN']},  
{ssl\_options, [{cacertfile,"/etc/pki/tls/testca/cacert.pem"},  
{certfile,"/etc/pki/tls/server/cert.pem"},  
{keyfile,"/etc/pki/tls/server/key.pem"},  
{password, "client1234passwd"},  
{verify,verify\_peer},  
{fail\_if\_no\_peer\_cert,true}]}  
]},  
{rabbitmq\_management,  
[{listener, [{port, 15671},  
{ssl, true},  
{auth\_mechanisms, ['EXTERNAL', 'PLAIN']},  
{ssl\_opts, [{cacertfile, "/etc/pki/tls/testca/cacert.pem"},  
{certfile, "/etc/pki/tls/server/cert.pem"},  
{keyfile, "/etc/pki/tls/server/key.pem"}  
{password, "client1234passwd"},  
{verify,verify\_peer},  
{fail\_if\_no\_peer\_cert, true}]}  
]}  
]}  
].  
For SSL : Ensure to create a CA and sign certificates with the CA.  
For creation of user,vhost,exchange,exchange-bindings,queue etc:  
./rabbitmqadmin declare exchange name=logstash-exchange type=direct -u sat -p sat

python [rabbitmqadmin.py](http://rabbitmqadmin.py) declare exchange name=logger type=topic -u username -p password

./rabbitmqadmin declare queue name=indexer-queue auto\_delete=false durable=true -u sat -p sat

./rabbitmqadmin declare binding source=logstash-exchange destination=indexer-queue routing\_key=logstash-routing\_key -u sat -p sat

./rabbitmqadmin publish exchange=logstash-exchange routing\_key=logstash-routing\_key payload="hello, world"

Logstash Server configuration:vi /etc/logstash/conf.d/elastic-rabbit.conf

input {  
rabbitmq {  
host =\> "[hidpuppet.example.com](http://hidpuppet.example.com)"  
queue =\> "indexer-queue"  
durable =\> true  
key =\> "logstash-routing\_key"  
exchange =\> "logstash-exchange"  
threads =\> 3  
prefetch\_count =\> 50  
port =\> 5672  
user =\> ""  
password =\> "sat"  
ssl =\> true  
ssl\_certificate\_path =\> "/etc/pki/tls/server/cert.pem"  
ssl\_certificate\_password =\> "client1234passwd"  
}  
}  
filter {  
if [type] == "syslog" {  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
if !("\_grokparsefailure" in [tags]) {  
mutate {  
replace =\> ["@source\_host", "%{syslog\_hostname}"]  
replace =\> ["@message", "%{syslog\_message}"]  
}  
}  
mutate {  
remove\_field =\> ["syslog\_hostname", "syslog\_message", "syslog\_timestamp"]  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
index =\> "syslog"  
document\_type =\> "log"  
}  
stdout { codec =\> rubydebug }  
}

Logstash agent server configuration: vi /etc/logstash/conf.d/logstash-forward.conf

input {  
file {  
type =\> "syslog"  
path =\> ["/var/log/syslog"]  
}  
heartbeat {  
interval =\> 10  
type =\> "heartbeat"  
}  
}  
output {  
rabbitmq {  
exchange =\> "logstash-exchange"  
exchange\_type =\> "direct"  
key =\> "logstash-routing\_key"  
host =\> "[hidpuppet.example.com](http://hidpuppet.example.com)"  
vhost =\> Some\_Virtual\_Host  
durable =\> true  
persistent =\> true  
port =\> 5672  
user =\> ""  
password =\> "sat"  
ssl =\> true  
ssl\_certificate\_path =\> "/etc/pki/tls/client/cert.pem"  
ssl\_certificate\_password =\> "client1234passwd"  
}  
stdout {  
codec =\> rubydebug  
}  
}  
logstash-forward.conf (END)

Error in logstash agents logs:

[2017-05-08T02:13:37,159][ERROR][logstash.agent] Pipeline aborted due to error {:exception=\>#\<MarchHare::Session::SSLContextException: toDerInputStream rejects tag type 45

---

<div class="post-metadata">

**Author:** ![satishkori](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@satishkori](https://discuss.elastic.co/u/satishkori)\
**Post date:** [May 10, 2017, 3:15pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/4 "2017-05-10T15:15:02Z")

</div>

Error in logstash agents logs:

[2017-05-08T02:13:37,159][ERROR][logstash.agent] Pipeline aborted due to error {:exception=\>#\<MarchHare::Session::SSLContextException: toDerInputStream rejects tag type 45

[2017-05-08T02:13:37,124][ERROR][logstash.pipeline] Error registering plugin {:plugin=\>"#\<LogStash::OutputDelegator:0xcf4f6d9 @namespaced\_metric=#\<LogStash::Instrument::NamespacedMetric:0x2ef5c31f @metric=#\<LogStash::Instrument::Metric:0x5d97b6d3 @collector=#\<LogStash::Instrument::Collector:0x28b1126b @agent=nil, @metric\_store=#\<LogStash::Instrument::MetricStore:0x3d87b9a @store=#\<Concurrent:🗺0x3b5bdc5 @default\_proc=nil\>, @structured\_lookup\_mutex=#Mutex:0x63f4b24e, @fast\_lookup=#\<Concurrent:🗺0x43f6d611 @default\_proc=nil\>\>\>\>, @namespace\_name=[:stats, :pipelines, :main, :plugins, :outputs, :"8060fc8ed7fdb640b58e0561cd033303b3cfc16a-3"]\>, @metric=#\<LogStash::Instrument::NamespacedMetric:0x2d47bf78 @metric=#\<LogStash::Instrument::Metric:0x5d97b6d3 @collector=#\<LogStash::Instrument::Collector:0x28b1126b @agent=nil, @metric\_store=#

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 10, 2017, 8:04pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/5 "2017-05-10T20:04:08Z")

</div>

> [{rabbit, [{ssl, true},  
> {ssl\_listeners, ["127.0.0.1", 15671]},

Surely you want the SSL-wrapped AMQP listener to run on port 5671, not 15671?

> {rabbitmq\_management,  
> [{listener, [{port, 15671},

Especially since you're running the management interface listener on port 15671.

> port =\> 5672

And yet you're telling Logstash to connect to port 5672?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2017, 8:08pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-agent-secure-ssl-communication-with-rabbitmq-and-eventually-to-elk-server/85248/6 "2017-06-07T20:08:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
