# Logstash monitoring security setup

**URL:** <https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [March 8, 2019, 4:41pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533 "2019-03-08T16:41:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 8, 2019, 4:41pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/1 "2019-03-08T16:41:42Z")

</div>

We're trying to learn how to setup TLS on elastic. We have a 1 node stack with version 6.6.1, working on getting logstash setup. All output is in pipelines. Getting this error at startup:

> [WARN][logstash.outputs.elasticsearch] \*\* WARNING \*\* Detected UNSAFE options in elasticsearch output configuration!  
> \*\* WARNING \*\* You have enabled encryption but DISABLED certificate verification.  
> \*\* WARNING \*\* To make sure your data is secure change :ssl\_certificate\_verification to true

That seems to be the default and I don't have ssl\_certificate\_verification anywhere in the config (verified by grep -ri) . I think it may be from something in the xpack.monitoring config, but I have nothing there for verification either.

Any ideas?

---

<div class="post-metadata">

**Author:** ![kharvey](https://avatars.discourse-cdn.com/v4/letter/k/d07c76/32.png) [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Post date:** [March 8, 2019, 5:10pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/2 "2019-03-08T17:10:33Z")

</div>

Not sure what side is causing your error, so I will answer for both the input and the output.

For your input:

```auto
input { 
  tcp { 
    id => "blah"
    codec => "json"
    port => 5044
    type => "log-file"
    ssl_verify => true
    ssl_enable => true
    ssl_key => "/etc/logstash/logstash.key"
    ssl_cert => "/etc/logstash/logstash.crt"
  }
}
```

For the output:

```auto
output {
	elasticsearch {
		ssl => true
		cacert => "/etc/logstash/cert.crt"
		hosts => ["https://elasticsearch.com/URL:9200"]
		ssl_certificate_verification => true
		codec => "json"
		action => "index"
		index => "%{indexname}"
		id => "log-file"
	}
}
```

Hmm, now that I look at it, I think that you only need to add the ssl\_certificate\_verification =\> true to your output. But you would have to be using a verified cert.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 8, 2019, 5:33pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/3 "2019-03-08T17:33:18Z")

</div>

Well, I had read the doc :-).... if you are using an "httpS" url, then ssl =\> becomes true based on the url and ssl\_certificate\_validation defaults to true, so I left them out.

Adding these to all my pipelines didn't eliminate the error.

---

<div class="post-metadata">

**Author:** ![kharvey](https://avatars.discourse-cdn.com/v4/letter/k/d07c76/32.png) [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Post date:** [March 8, 2019, 5:46pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/4 "2019-03-08T17:46:38Z")

</div>

Are your logs not making it to Elasticsearch?

You can try setting the ssl\_certificate\_verification =\> false  
If you read the last message on this git issue it says that the traffic should still be going through:

> <https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/433>

I don't have SSL setup in my test environment right now, so I am not able to test this, but I do have it running in prod.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 8, 2019, 5:52pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/5 "2019-03-08T17:52:27Z")

</div>

I honestly hadn't expected any traffic yet since I hadn't updated the beats for tls, but yes, there is traffic getting thru from winlogbeat test systems and monitoring data, so it's just a nag warning message and it appears to only happen at startup. If the pipelines are unhealthy, they can produce continuous messages.

At this point, I'm OK for my dev environment, when we get our contracts in place, I can open a support case 🙂

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 5:52pm UTC](https://discuss.elastic.co/t/logstash-monitoring-security-setup/171533/6 "2019-04-05T17:52:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
