# Logstash-forwarder working

**URL:** <https://discuss.elastic.co/t/logstash-forwarder-working/31707>\
**Category:** Logstash\
**Created:** [October 6, 2015, 3:02pm UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707 "2015-10-06T15:02:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [October 6, 2015, 3:02pm UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707/1 "2015-10-06T15:02:38Z")

</div>

Hi,

I have just started using Logstash-forwarder , I have created key and crt and then want to check whether is is fine or not,

```
input {

lumberjack {
port => 9300
ssl_certificate => "/elkt/software/bkup/logstash-1.5.4/bin/server.crt"
ssl_key => "/elkt/software/bkup/logstash-1.5.4/bin/server.key"
type => "lumberjack"
}
}

filter{}

output {
stdout { codec => rubydebug }
}

```

When I am trying to get the info from es port , it is showing that port is already in use , and if I am specifying random port it is just showing logstash started .  
Is there any way how to check whether it is working or not ?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2015, 5:53pm UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707/2 "2015-10-06T17:53:53Z")

</div>

How about connecting logstash-forwarder (or Logstash with a lumberjack _output_) to the Logstash instance above and see if messages are being received? That's your end goal anyway, right?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [October 7, 2015, 10:20am UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707/3 "2015-10-07T10:20:40Z")

</div>

yes.

so I tried getting logs from logstash-forwarder ,  
So I have created key, certificate (following this doc [link](http://www.logstashbook.com/TheLogstashBook_sample.pdf) )

But I am getting an error that -

```
2015/10/07 06:06:52.054195 Failed to tls handshake with 127.0.0.1 x509: cannot validate certificate for 127.0.0.1 because it doesn't contain any IP SANs

```

I was searched for the error and got the solution that I will have to change the openssl.cnf but I am not able to get the location of file in my system (perhaps do not have privilege ).  
Is there other way possible ?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [October 7, 2015, 10:52am UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707/4 "2015-10-07T10:52:48Z")

</div>

Got the solution here : [link](http://serverfault.com/questions/633681/logstash-forwarder-is-throwing-ssl-errors)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-forwarder-working/31707/5 "2017-07-06T05:27:13Z")

</div>


