# Issue with logstash (1:7.17.1-1) service on Ubuntu 18.04.3 LTS

**URL:** <https://discuss.elastic.co/t/issue-with-logstash-1-7-17-1-1-service-on-ubuntu-18-04-3-lts/299460>\
**Category:** Logstash\
**Tags:** elastic-stack-security, elastic-stack-alerting\
**Created:** [March 11, 2022, 2:02pm UTC](https://discuss.elastic.co/t/issue-with-logstash-1-7-17-1-1-service-on-ubuntu-18-04-3-lts/299460 "2022-03-11T14:02:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulgupta18](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rahulgupta18](https://discuss.elastic.co/u/rahulgupta18)\
**Post date:** [March 11, 2022, 2:02pm UTC](https://discuss.elastic.co/t/issue-with-logstash-1-7-17-1-1-service-on-ubuntu-18-04-3-lts/299460/1 "2022-03-11T14:02:25Z")

</div>

Hi Team,

I have deployed a 2-node ELK stack cluster where I can successfully login to kibana instance with my superuser credentials.

All of the ELK components (running on same Ubuntu VM) including metricbeats is running version 7.17.1.

I have xpath security enabled on both the nodes which can be seen as follows -

xpack.security.enabled: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: cert/elastic-stack-ca.p12  
xpack.security.transport.ssl.truststore.path: cert/elastic-stack-ca.p12

The problem is while I am trying to stop/start/restart logstash service, it just hangs in there with no output at all.

Verified the logstash-test.conf file under /etc/logstash/conf.d/ with command "bin/logstash -f logstash-test.conf --config.test\_and\_exit" and it looked fine.

```auto
[WARN] 2022-03-11 05:32:53.291 [LogStash::Runner] elasticsearch - Relying on default value of `pipeline.ecs_compatibility`, which may change in a future major release of Logstash. To avoid unexpected changes when upgrading Logstash, please explicitly declare your desired ECS Compatibility mode.
Configuration OK
[INFO] 2022-03-11 05:32:53.386 [LogStash::Runner] runner - Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash

```

Looking at the /var/log/logstash/logstash-plain.log as well as running command "bin/logstash -f logstash-test.conf --config.reload.automatic" results in same log events which are as follows -

```auto

[2022-03-11T04:09:40,940][DEBUG][logstash.outputs.elasticsearch][syslog-test] Running health check to see if an ES connection is working {:url=>"http://<ip_masked>:9200/", :path=>"/"}
[2022-03-11T04:09:40,948][WARN][logstash.outputs.elasticsearch][syslog-test] Failed to perform request {:message=>"Unsupported or unrecognized SSL message", 
:exception=>Manticore::UnknownException, :cause=>javax.net.ssl.SSLException: Unsupported or unrecognized SSL message, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.8.0-java/lib/manticore/response.rb:36:in `block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.8.0-java/lib/manticore/response.rb:79:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/manticore_adapter.rb:73:in `perform_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:324:in `perform_request_to_url'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:233:in `health_check_request'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:240:in `block in healthcheck!'", "org/jruby/RubyHash.java:1415:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:238:in `healthcheck!'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:215:in `block in start_resurrectionist'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:136:in `until_stopped'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-11.4.1-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:214:in `block in start_resurrectionist'"]}
[2022-03-11T04:09:40,949][DEBUG][logstash.outputs.elasticsearch.httpclient.manticoreadapter][syslog-test]

```

Surprisingly, I am able to curl to http://\<elasticsearch\_ip\_masked\>:9200 without user credentials on the browser, however, the same is getting failed with/without user credentials via CLI (w/ -u username:password).

```auto
{"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}}],"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}},"status":401}

```

I have already spent a lot of time on troubleshooting and reviewing [Configuring Security in Logstash | Logstash Reference [7.17] | Elastic](https://www.elastic.co/guide/en/logstash/7.17/ls-security.html#ls-http-auth-basic), however, couldn't really make any progress.

Any inputs from your side in order to debug or isolate the issue would be highly appreciated.

Thanks,  
Rahul

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2022, 6:30pm UTC](https://discuss.elastic.co/t/issue-with-logstash-1-7-17-1-1-service-on-ubuntu-18-04-3-lts/299460/2 "2022-04-04T18:30:06Z")

</div>

> [@rahulgupta18](#):
>
> I am able to curl to http://\<elasticsearch\_ip\_masked\>:9200 without user credentials on the browser

http? So you do not have SSL configured?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2022, 6:30pm UTC](https://discuss.elastic.co/t/issue-with-logstash-1-7-17-1-1-service-on-ubuntu-18-04-3-lts/299460/3 "2022-05-02T18:30:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
