# Logstash stopped processing logs after enabling minimal security

**URL:** <https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232>\
**Category:** Logstash\
**Created:** [March 7, 2023, 10:41pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232 "2023-03-07T22:41:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![A.Hani](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Post date:** [March 7, 2023, 10:41pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/1 "2023-03-07T22:41:13Z")

</div>

I was wondering what should be configured on logstash side after enabling basic on Elasticsearch node?  
I set x.pack.security.enabled to true on elasticsearch.yml, generated passwords for the cluster users, added the kibana user and password to the kibana file, and added the logstash\_system user and password to logstash.yml. I'm able to authenticate to kibana with the elastic superuser, but i can see logstash stopped processing logs

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 7, 2023, 10:48pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/2 "2023-03-07T22:48:28Z")

</div>

Did you add the user and password in your logstash output configuration?

Please share your configuration and also the logs from logstash.

---

<div class="post-metadata">

**Author:** ![A.Hani](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Post date:** [March 8, 2023, 5:49am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/3 "2023-03-08T05:49:36Z")

</div>

Logstash.yml config

```auto
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.username: "logstash_system"
xpack.monitoring.elasticsearch.password: "some password"
#xpack.monitoring.elasticsearch.proxy: ["http://proxy:port"]
xpack.monitoring.elasticsearch.hosts: ["http://x.x.x.x:9200"]

logstash output configuration
}
output {

if [type] == " ****"{
        elasticsearch { hosts => ["localhost:9200"]
        index => "......"
        }
    }

```

Dots and Asteriks are just placeholders for what is in there.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 8, 2023, 2:59pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/4 "2023-03-08T14:59:34Z")

</div>

> [@A.Hani](#):
>
> ```auto
> xpack.monitoring.elasticsearch.username: "logstash_system"
> xpack.monitoring.elasticsearch.password: "some password"
> 
> ```

This is only used for monitoring Logstash and this kind of monitoring is deprecated, you should not use it, but use metricbeat if you want to monitor logstash.

> [@A.Hani](#):
>
> ```auto
> if [type] == " ****"{
> elasticsearch { hosts => ["localhost:9200"]
> index => "......"
> }
> }
> 
> ```

You didn't set he `user` and `password` in your output, you need to set it, something like this:

```auto
elasticsearch {
    hosts => ["hosts"]
    index => "your-index"
    user => "user"
    password => "password"
}

```

Did you check this [documentation](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic) about configuring logstash to use basic authentication?

You will probably need to create a new user to use in logstash with permissions to the index patterns you want to write.

---

<div class="post-metadata">

**Author:** ![A.Hani](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Post date:** [March 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/5 "2023-03-09T11:02:25Z")

</div>

That was it. Thank s for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232/6 "2023-04-06T11:03:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
