# Logstash authentication to ES

**URL:** <https://discuss.elastic.co/t/logstash-authentication-to-es/156746>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 14, 2018, 9:56pm UTC](https://discuss.elastic.co/t/logstash-authentication-to-es/156746 "2018-11-14T21:56:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Andre](https://avatars.discourse-cdn.com/v4/letter/m/c6cbf5/32.png) [@Mark\_Andre](https://discuss.elastic.co/u/Mark_Andre)\
**Post date:** [November 14, 2018, 9:56pm UTC](https://discuss.elastic.co/t/logstash-authentication-to-es/156746/1 "2018-11-14T21:56:47Z")

</div>

Hi all,  
I'm trying to determine if there's a way to send log data via logstash pipelines into Elastic without having to use saved passwords in the pipeline config.  
Is this possible?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 15, 2018, 5:34am UTC](https://discuss.elastic.co/t/logstash-authentication-to-es/156746/2 "2018-11-15T05:34:42Z")

</div>

Hi there,

You have a couple of otpions:

1. Use the [Secrets keystore](https://www.elastic.co/guide/en/logstash/current/keystore.html) to set the password and then reference it by key in your Elasticsearch output plugin config

2. If your ES node is (or can be) configured for PKI authentication, you can use a key and certificate stored in a [JKS or PKCS#12 keystore](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-keystore) to authenticate to Elasticsearch. Note that this option carries the side effect that if your `JKS`, or `PKCS#12` keystores are password protected then you'd need to include [this password](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-keystore_password) in your config, which depending on your threat model can be as bad as having the Elasticsearch user password there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2018, 5:34am UTC](https://discuss.elastic.co/t/logstash-authentication-to-es/156746/3 "2018-12-13T05:34:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
