# Logstash Key store

**URL:** <https://discuss.elastic.co/t/logstash-key-store/275633>\
**Category:** Logstash\
**Created:** [June 11, 2021, 12:52am UTC](https://discuss.elastic.co/t/logstash-key-store/275633 "2021-06-11T00:52:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![farciarz121](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Post date:** [June 11, 2021, 12:52am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/1 "2021-06-11T00:52:50Z")

</div>

I am trying to improve my ELK security with logstash keystore.

I am following instruction from this article:  
`https://www.elastic.co/guide/en/logstash/current/keystore.html`

All instructions seems to be straight forward until there is actually time to type variables ....

I want to create 2 variables: ${var1} , ${var1}. I have created password protected keystore and I have moved it to config folder (this is where my .conf file is located)

Now, when I create variables that supposed to hold cloud\_id and cloud\_auth do I need to type it character by character or can I simple copy - paste? Especially cloud\_id is a super long String. To make it more complicated when I type I can not see what is getting type. This makes it super easy to make a mistake.

As always, thank you for support in the advance.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 11, 2021, 1:12am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/2 "2021-06-11T01:12:10Z")

</div>

Hmm don't think you should move the keystore it belongs [here](https://www.elastic.co/guide/en/logstash/current/keystore.html#keystore-location)

> The keystore must be located in Logstash’s path.settings directory. This is the same directory that contains the logstash.yml file.

And yes you can paste in the strings at the command line

---

<div class="post-metadata">

**Author:** ![farciarz121](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Post date:** [June 11, 2021, 1:17am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/3 "2021-06-11T01:17:43Z")

</div>

By defult keysotre is located in bin folder. You are right instruction says ''same direectory that contain logstash.yml'' which is config folder

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea5be81ccc41b292afc41f6ce6a4d3964b79d32f.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 11, 2021, 1:41am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/4 "2021-06-11T01:41:40Z")

</div>

Directory layout.

> **[Logstash Directory Layout | Logstash Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/logstash/current/dir-layout.html#zip-targz-layout)**

Typically you run keystore from base directory not from inside the `.\bin` and then it should probably end up in the right place.

`.\bin\logstash-keystore create`

---

<div class="post-metadata">

**Author:** ![farciarz121](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Post date:** [June 11, 2021, 1:53am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/5 "2021-06-11T01:53:41Z")

</div>

> [@stephenb](#):
>
> he keystore must be located in Logstash’s path.settings directory. This is the same directory that contains the logstash.yml file.

That's correct, after creation keystore ends up in bin dicrectory. But also, as you cited above

```auto
The keystore must be located in Logstash’s path.settings directory. This is the same directory that contains the logstash.yml file.

```

This says that logstash.yml should be in the same direcotry that keystore. Does it mean that I should move .yml file to bin instead of moving keystore to config directory?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/0/20c6e604f5d286563b01fc0f55cf01212392170b.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 11, 2021, 1:57am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/6 "2021-06-11T01:57:18Z")

</div>

**Exactly** what command and from exactly where did you run it.

Or try it and see if it works.

I've always run the command exactly as it's defined in the documents, from the base directory not inside the bin and never had an issue.

In fact I've never really even thought about where it is until you asked I follow the documents and it's always worked.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 11, 2021, 2:24am UTC](https://discuss.elastic.co/t/logstash-key-store/275633/7 "2021-06-11T02:24:45Z")

</div>

```auto
ceres:logstash-7.13.0 sbrown$ pwd
/Users/sbrown/workspace/elastic-install/7.13.0/logstash-7.13.0

ceres:logstash-7.13.0 sbrown$ ./bin/logstash-keystore create
....

ceres:logstash-7.13.0 sbrown$ cd config
ceres:config sbrown$ pwd
/Users/sbrown/workspace/elastic-install/7.13.0/logstash-7.13.0/config
ceres:config sbrown$ ls -la
total 40
drwxr-xr-x 9 sbrown staff 288 Jun 10 19:22 ./
drwxr-xr-x 19 sbrown staff 608 Jun 8 08:48 ../
-rw-r--r-- 1 sbrown staff 2034 May 19 14:58 jvm.options
-rw-r--r-- 1 sbrown staff 7561 May 19 14:58 log4j2.properties
-rw-r--r-- 1 sbrown staff 342 May 19 14:58 logstash-sample.conf 
-rw-r--r-- 1 sbrown staff 472 Jun 10 19:22 logstash.keystore <-----
-rw-r--r-- 1 sbrown staff 11194 May 19 14:58 logstash.yml
-rw-r--r-- 1 sbrown staff 3693 May 19 14:58 pipelines.yml
-rw-r--r-- 1 sbrown staff 1696 May 19 14:58 startup.options
ceres:config sbrown$

```

---

<div class="post-metadata">

**Author:** ![farciarz121](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Post date:** [June 11, 2021, 12:42pm UTC](https://discuss.elastic.co/t/logstash-key-store/275633/8 "2021-06-11T12:42:24Z")

</div>

Nice, so it created keystore in config folder when you executed "logstash-keystore create" from the base directory. Cool, I have a few meetings in the morning but I will keep working on this today.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2021, 12:43pm UTC](https://discuss.elastic.co/t/logstash-key-store/275633/9 "2021-07-09T12:43:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
