# Logstash ssl-tcp configuration syslog output

**URL:** <https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349>\
**Category:** Logstash\
**Created:** [June 23, 2020, 11:07pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349 "2020-06-23T23:07:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bambam](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@bambam](https://discuss.elastic.co/u/bambam)\
**Post date:** [June 23, 2020, 11:07pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/1 "2020-06-23T23:07:45Z")

</div>

Hello,

I'm trying to forward messages from Logstash to an external syslog server (Qradar). I need to use ssl-tcp, for the external connection only not the connection to Elasticsearch. I can't find any documentation on how to properly configure the output file and what needs to be included in the file. Below is the current logstash output config file. The "syslog.cert" is a certificate generated from the external syslog server. The current output to Elasticsearch works without any issues but the syslog output is not working correctly.

output {  
Elasticsearch { hosts =\> localhost }  
}

output {  
Syslog {  
Host =\> “10.10.10.10”  
Severity =\> “debug”  
protocol =\> “ssl-tcp”  
port =\> “6514”  
ssl\_cert =\> “/tmp/syslog.cert.”  
ssl\_verify =\> ‘false’  
codec =\> line { format =\> “%{message}” }  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 23, 2020, 11:38pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/2 "2020-06-23T23:38:33Z")

</div>

> [@bambam](#):
>
> the syslog output is not working correctly

What does not work? Are there error messages in either the logstash or syslog logs?

---

<div class="post-metadata">

**Author:** ![bambam](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@bambam](https://discuss.elastic.co/u/bambam)\
**Post date:** [June 24, 2020, 12:02pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/4 "2020-06-24T12:02:09Z")

</div>

I was told communication is getting to the Qradar machine but the logs show something messages like they're looking for a handshake to complete before it will accept the logs. This is why I entered the ssl\_cert into the config. The reason I believe it's related to the certificate is because I have tested forwarding the logs without ssl and have verified connectivity.

---

<div class="post-metadata">

**Author:** ![bambam](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@bambam](https://discuss.elastic.co/u/bambam)\
**Post date:** [June 24, 2020, 2:33pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/5 "2020-06-24T14:33:06Z")

</div>

Below are the error messages I see after making changes to the configuration file and restart the logstash service.

[2020-06-24T10:30:24,753][ERROR][logstash.agent] Pipeline aborted due to error {:exception=\>#\<TypeError: can't convert nil into String\>, :backtrace=\>["org/jruby/RubyIO.java:3804:in `read'", "org/jruby/RubyIO.java:3987:in `read'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:229:in `setup_ssl'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:132:in `register'", "org/jruby/RubyArray.java:1613:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/output_delegator_strategies/legacy.rb:17:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/output\_delegator.rb:43:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:290:in `register\_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:301:in `register_plugins'", "org/jruby/RubyArray.java:1613:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:301:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:310:in `start\_workers'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:235:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:408:in `start\_pipeline'"]}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 24, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/6 "2020-06-24T14:39:42Z")

</div>

> [@bambam](#):
>
> error {:exception=\>#\<TypeError: can't convert nil into String\>, :backtrace=\>["org/jruby/RubyIO.java:3804:in `read'", "org/jruby/RubyIO.java:3987:in ` read'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.rb:229:in `setup_ssl'"`

line 229 is [this](https://github.com/logstash-plugins/logstash-output-syslog/blob/9a6130586b130da01db54368a523840b6bb904df/lib/logstash/outputs/syslog.rb#L229).

```
ssl_cert => “/tmp/syslog.cert.”

```

Are you sure that should have a trailing period?

---

<div class="post-metadata">

**Author:** ![bambam](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@bambam](https://discuss.elastic.co/u/bambam)\
**Post date:** [June 24, 2020, 2:43pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/7 "2020-06-24T14:43:33Z")

</div>

that is a typo there is no . in the actual config. Do you need to trust the syslog.cert or add it to anything? The only thing I've done is copy it to my machine from the destination machine.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 24, 2020, 2:44pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/8 "2020-06-24T14:44:56Z")

</div>

I suspect it is failing to read the file at all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2020, 2:45pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-configuration-syslog-output/238349/9 "2020-07-22T14:45:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
