# Logstash crashing, user error with pipeline and SSL certs configuration

**URL:** <https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612>\
**Category:** Logstash\
**Created:** [January 9, 2021, 3:58pm UTC](https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612 "2021-01-09T15:58:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eden\_Corbin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eden_corbin/32/81657_2.png) [@Eden\_Corbin](https://discuss.elastic.co/u/Eden_Corbin)\
**Post date:** [January 9, 2021, 3:58pm UTC](https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612/1 "2021-01-09T15:58:38Z")

</div>

I'm struggling a bit getting certs in place for just logstash and filebeat. My goal is to secure log trasnport between VPS instances and my logstash server. Although I'm testing with everything on the same server at the moment. Things were working fine before attempting to configure SSL, now I get this error message from Logstash:

```auto
Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: PipelineAction::Create<main>, action_result: false", :backtrace=>nil}

```

My Logstash pipeline configuration is as follows:

```auto
input {
        beats {
                port => 5044
                ssl => true
                ssl_certificate_authorities => ["/certs/ca/ca.crt"]
                ssl_verify_mode => "force_peer"
        }
}

```

this cert is copied in via docker and I can confirm they are in the correct location in the container prior to it crashing. I doubt its related but I do map another docker container readonly to the same cert.  
My filebeat configuration is as follows:

```auto
output.logstash:
  enabled: true
  hosts: ["logstash:5044"]
  ssl.certificate_authorities: ["/certs/ca/ca.crt"]
  ssl.certificate: "/certs/instance/instance.crt"
  ssl.key: "/certs/instance/instance.key"

```

I'm not entirely sure I setup my keys correctly, what I did for that was:

```auto
bin/elasticsearch-certutil cert --keep-ca-key --pem --out /temp/certs.zip

```

This generates the above refrenced certs in the same naming and folder structure. Any idea what Im' doing wrong here or why logstash crashes?

---

<div class="post-metadata">

**Author:** ![Eden\_Corbin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eden_corbin/32/81657_2.png) [@Eden\_Corbin](https://discuss.elastic.co/u/Eden_Corbin)\
**Post date:** [January 10, 2021, 12:56pm UTC](https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612/2 "2021-01-10T12:56:13Z")

</div>

Missed an important earlier error. Looks like I get this:

```auto
Pipeline error {:pipeline_id=>"main", :exception=>#<LogStash::ConfigurationError: Certificate or Certificate Key not configured>

```

---

<div class="post-metadata">

**Author:** ![Eden\_Corbin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eden_corbin/32/81657_2.png) [@Eden\_Corbin](https://discuss.elastic.co/u/Eden_Corbin)\
**Post date:** [January 11, 2021, 12:03pm UTC](https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612/3 "2021-01-11T12:03:55Z")

</div>

I'm trying some more / different settings with multiple VPS intsances now. I can't delete this so I will call this answered here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2021, 12:04pm UTC](https://discuss.elastic.co/t/logstash-crashing-user-error-with-pipeline-and-ssl-certs-configuration/260612/4 "2021-02-08T12:04:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
