# Logstash not working with https elastic search output

**URL:** <https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [July 15, 2019, 10:14am UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494 "2019-07-15T10:14:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharma3007](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharma3007/32/43414_2.png) [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Post date:** [July 15, 2019, 10:14am UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/1 "2019-07-15T10:14:51Z")

</div>

Hi Team,

I am getting below error while run log stash with https elastic search output:

Here are the error details:

[2019-07-15T12:08:17,978][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=\>"Elasticsearch Unreachable: [[https://elastic:xxxxxx@X.X.X.X:9200/](https://elastic:xxxxxx@X.X.X.X:9200/)][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}  
[2019-07-15T12:08:18,228][ERROR][logstash.monitoring.internalpipelinesource] Failed to fetch X-Pack information from Elasticsearch. This is likely due to failure to reach a live Elasticsearch cluster.  
[2019-07-15T12:08:20,963][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[https://logstash\_system:xxxxxx@X.X.X.X:9200/](https://logstash_system:xxxxxx@X.X.X.X:9200/)]}}  
[2019-07-15T12:08:21,119][ERROR][logstash.javapipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Manticore::UnknownException: Host name 'x.x.x.x' does not match the certificate subject provided by the peer (CN=instance)\>, :backtrace=\>["D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:37:in `block in initialize'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/manticore-0.6.4-java/lib/manticore/response.rb:79:in`call'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:74:in `perform_request'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:291:in`perform\_request\_to\_url'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:245:in `block in healthcheck!'", "org/jruby/RubyHash.java:1419:in`each'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:241:in `healthcheck!'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:341:in`update\_urls'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:71:in `start'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client.rb:302:in`build\_pool'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client.rb:64:in `initialize'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http_client_builder.rb:103:in`create\_http\_client'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/http\_client\_builder.rb:99:in `build'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch.rb:238:in`build\_client'", "D:/ElasticStack/Logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.1.0-java/lib/logstash/outputs/elasticsearch/common.rb:25:in `register'", "org/logstash/config/ir/compiler/OutputStrategyExt.java:106:in`register'", "org/logstash/config/ir/compiler/AbstractOutputDelegatorExt.java:48:in `register'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java_pipeline.rb:191:in`block in register\_plugins'", "org/jruby/RubyArray.java:1792:in `each'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java_pipeline.rb:190:in`register\_plugins'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java\_pipeline.rb:445:in `maybe_setup_out_plugins'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java_pipeline.rb:203:in`start\_workers'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java\_pipeline.rb:145:in `run'", "D:/ElasticStack/Logstash/logstash-core/lib/logstash/java_pipeline.rb:104:in`block in start'"], :thread=\>"#\<Thread:0xe6d1f9a run\>"}  
[2019-07-15T12:08:21,171][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2019-07-15T12:08:21,569][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-07-15T12:08:26,525][INFO][logstash.runner] Logstash shut down.

Below are the OUTPUT details of my logstash.config file:

```
output {
 
	elasticsearch {

	ssl => true
	ssl_certificate_verification => true
	cacert => "D:\ElasticStack\Logstash\config\elastic-ca.pem"
    hosts => ["https://X.X.X.X:9200"]	
    user => "logstash_system"
	password => "TEST@123"
    
	manage_template => false
   index => "%{[@metadata][index]}-%{+YYYY.MM.dd}"
   
    }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 15, 2019, 2:24pm UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/2 "2019-07-15T14:24:21Z")

</div>

> [@Sharma3007](#):
>
> PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

I believe that is telling you that it cannot validate the certificate presented by the server based on the CA cert that it has. Did you include the intermediate in the elastic-ca.pem?

---

<div class="post-metadata">

**Author:** ![Sharma3007](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharma3007/32/43414_2.png) [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Post date:** [July 15, 2019, 5:20pm UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/3 "2019-07-15T17:20:59Z")

</div>

Thanks for the reply @Badger ,  
No, I didn't use intermediate.  
Dont know how to use that.  
Can you please provide the steps?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 15, 2019, 6:56pm UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/4 "2019-07-15T18:56:59Z")

</div>

Try [this](https://unix.stackexchange.com/questions/368123/how-to-extract-the-root-ca-and-subordinate-ca-from-a-certificate-chain-in-linux).

---

<div class="post-metadata">

**Author:** ![barcomasile](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/barcomasile/32/50243_2.png) [@barcomasile](https://discuss.elastic.co/u/barcomasile)\
**Post date:** [July 16, 2019, 11:54am UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/5 "2019-07-16T11:54:47Z")

</div>

Allow me to suggest a simple thing: on windows, if you use backslashes, you need to escape them. I don't know if it's actually going to solve the problem, but it' something.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2019, 11:54am UTC](https://discuss.elastic.co/t/logstash-not-working-with-https-elastic-search-output/190494/6 "2019-08-13T11:54:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
