# Logstash http output user password

**URL:** <https://discuss.elastic.co/t/logstash-http-output-user-password/231525>\
**Category:** Logstash\
**Created:** [May 7, 2020, 11:43am UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525 "2020-05-07T11:43:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 7, 2020, 11:43am UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/1 "2020-05-07T11:43:41Z")

</div>

I am receiving log data from TCP and sending it to a https url as json using logstash.

Here is my configuration

> input {  
> tcp {  
> port =\> 8443  
> codec =\> json\_lines { charset =\> CP1252 }  
> }  
> }  
> output {  
> http  
> {  
> format=\>"json"  
> http\_method=\>"post"  
> url=\>"[Domain Available | MicroStrategy](https://alert.com/ts/dmd/evcon)"  
> headers =\>{  
> user=\> "username"  
> password =\> "password"  
> }  
> }  
> }

and im receiving the below error:

> [HTTP Output Failure] Could not fetch URL {:url=\>"[Domain Available | MicroStrategy](https://alert.com/ts/dmd/evcon)", :headers=\>{"username","password", "Content-Type"=\>"application/json"}, :message=\>"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target", :class=\>"Manticore::ClientProtocolException", :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:37:in `block in initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:79:in `call'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-http-5.2.4/lib/logstash/outputs/http.rb:239:in `send_event'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-http-5.2.4/lib/logstash/outputs/http.rb:175:in `send\_events'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-http-5.2.4/lib/logstash/outputs/http.rb:124:in `multi_receive'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:118:in `multi\_receive'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:101:in `multi_receive'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:239:in `block in start\_workers'"], :will\_retry=\>true}

Im not sure if headers is the place to give the username and password of the url. Also, added the below for avoiding the cert error:

> ```
> ssl_certificate_validation => false
> verify_ssl => false
> 
> ```

which gave me

> [2020-05-07T04:48:03,430][ERROR][logstash.outputs.http] Unknown setting 'verify\_ssl' for http  
> [2020-05-07T04:48:03,435][ERROR][logstash.outputs.http] Unknown setting 'ssl\_certificate\_validation' for http

How do i use http output here?  
Is this the right way of giving user password to reach the url?  
How can i avoind the certificate error.

Note: Running logstash in 7.2 in Linux

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 7, 2020, 3:59pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/2 "2020-05-07T15:59:22Z")

</div>

> [@katara](#):
>
> :message=\>"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"

I believe this is saying that the certificate for [alert.com](http://alert.com), or the ca thereof, is not in your truststore. It has nothing to do with the username and password.

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 7, 2020, 4:13pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/3 "2020-05-07T16:13:56Z")

</div>

@Badger,  
Thank you for your time,  
How can I ignore the certificate of the url?  
While doing a curl I use a -k at the end as

> Curl -u user:password [https://url.com](https://url.com) -k

To get a response. If I do not use a -k, I get a certificate error.

Also, just to clarify, the header and user password method is right? Is that how I should be including my credentials ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 7, 2020, 4:35pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/4 "2020-05-07T16:35:20Z")

</div>

The elasticsearch output does not support insecure connections. Just use HTTP instead of TLS if you do not care about security.

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 7, 2020, 5:17pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/5 "2020-05-07T17:17:02Z")

</div>

there’s cacert option for http output plugin. since your cert is not trusted, you need to get the cacert locally and point the cacert option to the path where you store the cert.

also you need to pass the username and password in the way that it’s accepted by your webserver. probably need Authorization in header. you can pass the header in the header option of the http output as well

you can read the options available in the [docs](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-http.html#plugins-outputs-http-headers)

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 7, 2020, 5:22pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/6 "2020-05-07T17:22:35Z")

</div>

@badger, I'm not sending this data to elasticsearch. I'm sending it to a monitoring tool which is a https connection, which I cannot avoid.

I have to have a https, can I bypass the security with  
**Ssl =\> false**?

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 7, 2020, 5:26pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/7 "2020-05-07T17:26:20Z")

</div>

@ptamba thank you for your help,  
I'm so sorry, I'm not sure of how to use a Authorization in a header. Could you please guide me on what I can do?

What I have is a destination url and a username password. Should I make some conversion to the credentials to create this?

Please help me out with understanding this.

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 7, 2020, 5:29pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/8 "2020-05-07T17:29:55Z")

</div>

i’m sorry, but it really depends on http endpoint you sent the output to. there should be documentation in your http server on how to authenticate

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 7, 2020, 5:38pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/9 "2020-05-07T17:38:16Z")

</div>

The url when accessed normally will have an authentication page for username and password.  
This will not come as a pop up but as a page. (Tried in a browser. )  
@Badger @ptamba, which there after I can post with.

I'm not sure what kind of information this will require for me to decide this Authorization.

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [May 8, 2020, 7:11pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/10 "2020-05-08T19:11:53Z")

</div>

@Badger @ptambam  
I managed to create an authorization with @badger's different answer  
[here](https://discuss.elastic.co/t/how-to-pass-basic-authentication-details-in-http-filter-plugin/201246/6)

My config is now

> output  
> {  
> http  
> {  
> format=\>"json"  
> http\_method=\>"post"  
> url=\>"[https://zenossprod.lsk12.com/zport/dmd/evconsole\_router](https://zenossprod.lsk12.com/zport/dmd/evconsole_router)"  
> cacert =\> "/opt/cert/cert.crt"  
> headers =\> {  
> "Authorization" =\> "Basic RUxLOldlbGNvbWUxMjMgaHR0cHMbWQvZXZjb25zb2xlX3JvdXRlcg=="  
> }  
> }  
> stdout { codec =\> rubydebug }  
> }

But I'm still getting the certificate error,  
message=\>"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target",

I also tried with pem and cer type certificates. None of it works,

Please help me resolve it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 7:11pm UTC](https://discuss.elastic.co/t/logstash-http-output-user-password/231525/11 "2020-06-05T19:11:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
