# Logstash https plugin not working

**URL:** <https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386>\
**Category:** Logstash\
**Created:** [July 23, 2020, 6:28pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386 "2020-07-23T18:28:18Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajkumar.m](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Post date:** [July 23, 2020, 6:28pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/1 "2020-07-23T18:28:19Z")

</div>

Hi Team,

I am unable to send data with logstash plugin https, someone please help me.  
I can send data with http without security successfully, but when try to enable ssl, it is failing,

please find the below command syntax and configuration and advise

curl -v -H 'content-type: application/json' --cacert /path/to/cert.pem -XPUT '[https://logstashnode](https://logstashnode):XXXX/\_bulk' -d @/path/to/test.json

- About to connect() to logstashnode port XXXX (#0)
- Trying XX.XX.XX.XX ... connected
- Connected to logstashnode (XX.XX.XX.XX) port XXXX (#0)
- Initializing NSS with certpath: sql:/etc/pki/nssdb
- CAfile: /path/to/cert/abc.pem  
CApath: none
- NSS error -5961
- Closing connection #0
- SSL connect error  
curl: (35) SSL connect error

Below is my plugin configuration:

``````````````````````auto
input {
       http {
             port => XXXX
             user => XXXXX
             password => "XXXXXX"
             codec => json
             ssl => true
             keystore => "/path/XXXXXXXX.jks" 
             keystore_password => "XXXXX"
       }
}
`````````````````````
``````````````````````

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2020, 6:46pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/2 "2020-07-23T18:46:25Z")

</div>

-5961L is "TCP connection reset by peer". It is unclear why the http input would do that.

---

<div class="post-metadata">

**Author:** ![rajkumar.m](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Post date:** [July 23, 2020, 7:00pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/3 "2020-07-23T19:00:44Z")

</div>

If I use http without ssl, it is working fine.  
but it is failing only if i use https with ssl. Please advise

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2020, 7:09pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/4 "2020-07-23T19:09:15Z")

</div>

Does logstash log anything when it drops the connection?

---

<div class="post-metadata">

**Author:** ![rajkumar.m](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Post date:** [July 23, 2020, 7:20pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/5 "2020-07-23T19:20:07Z")

</div>

No messages found in logstash log file.

I have removed user section and updated like below, but still it is not working.  
working only when i disable ssl.

input {  
http {  
port =\> XXXX  
codec =\> json  
ssl =\> true  
keystore =\> "/path/XXXXXXXX.jks"  
keystore\_password =\> "XXXXX"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2020, 7:34pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/6 "2020-07-23T19:34:41Z")

</div>

Can you try replacing keystore/keystore\_password with ssl\_certificate (.crt format) and ssl\_key (PKCS8 format)?

---

<div class="post-metadata">

**Author:** ![rajkumar.m](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Post date:** [July 23, 2020, 7:42pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/7 "2020-07-23T19:42:32Z")

</div>

I found the below error in logstash and not able to start it.

[ERROR][logstash.inputs.http] Unknown setting 'ssl\_certificate' for http  
[ERROR][logstash.inputs.http] Unknown setting 'ssl\_key' for http

But the below configuration is working for filebeat.

```auto
input {
        beats {
                port=> XXXX
                ssl => true
                ssl_certificate => "/path/to/xxx.crt"
                ssl_key => "/path/to.xxx.pkcs8"
        }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 23, 2020, 8:05pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/8 "2020-07-23T20:05:29Z")

</div>

Which version of logstash are you using?

Can you confirm the keystore includes the private key and not just the certificate?

---

<div class="post-metadata">

**Author:** ![Sreekanth\_Ragi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sreekanth_ragi/32/58498_2.png) [@Sreekanth\_Ragi](https://discuss.elastic.co/u/Sreekanth_Ragi)\
**Post date:** [July 24, 2020, 3:35pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/9 "2020-07-24T15:35:54Z")

</div>

Yes please confirm the logstash version and looking at the documentation here  
[https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html)

You should be replacing beats with http.

---

<div class="post-metadata">

**Author:** ![rajkumar.m](https://avatars.discourse-cdn.com/v4/letter/r/e9bcb4/32.png) [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Post date:** [July 24, 2020, 5:45pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/10 "2020-07-24T17:45:29Z")

</div>

Issue got resolved after fixing the jks file passwd,  
I am using logstash 5.6 Version and below is the config that worked,

Thanks Badger & Sreekanth for your help !!

```auto
input {
http {
port => XXXX
codec => json
ssl => true
keystore => "/path/XXXXXXXX.jks"
keystore_password => "XXXXX"
}
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2020, 5:48pm UTC](https://discuss.elastic.co/t/logstash-https-plugin-not-working/242386/11 "2020-08-21T17:48:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
