# Logstash unable to connect ssl enabled elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-unable-to-connect-ssl-enabled-elasticsearch/269570>\
**Category:** Logstash\
**Created:** [April 8, 2021, 9:37am UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-ssl-enabled-elasticsearch/269570 "2021-04-08T09:37:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhishek\_s1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhishek_s1/32/85080_2.png) [@abhishek\_s1](https://discuss.elastic.co/u/abhishek_s1)\
**Post date:** [April 8, 2021, 9:37am UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-ssl-enabled-elasticsearch/269570/1 "2021-04-08T09:37:23Z")

</div>

I was using logstash to ingest data into elasticearch. But now after enabling ssl to elasticsearch (using [this](https://www.elastic.co/guide/en/kibana/7.11/configuring-tls.html#configuring-tls-kib-es)) for using alerts & detections, Logstash is unable to connect elasticsearch.

Browser or curl command works alright for url, [https://localhost:9200](https://localhost:9200).

The logstash error I'm getting is:

```auto
[2021-04-08T11:00:03,536][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"https://elastic:xxxxxx@localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [https://elastic:xxxxxx@localhost:9200/][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}

```

elasticsearch log says:

```auto
[2021-04-08T12:22:42,176][WARN][o.e.x.s.t.n.SecurityNetty4HttpServerTransport] [ZBLR-ENGG-ABHIS] http client did not trust this server's certificate, closing connection Netty4HttpChannel{localAddress=/[0:0:0:0:0:0:0:1]:9200, remoteAddress=/[0:0:0:0:0:0:0:1]:56792}

```

My logstash conf file:

```auto
input {

    file {

        path => "C:/Users/Abhishek S/Desktop/Data/httpd-access.log"
        start_position => "beginning"
        type => "apache-access"
        sincedb_path => "NUL"
    }
}

filter {

    if [type] == "apache-access" {

        grok {
            match => { "message" => ["%{IPORHOST:client_ip} %{HTTPDUSER:ident} %{USER:username} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:http_method} %{NOTSPACE:svn_path}(?: HTTP/%{NUMBER:http_version})?|%{DATA:svn_path})\" %{NUMBER:http_response} (?:%{NUMBER:content_length}|-)" ,

                                      "%{IPORHOST:client_ip} %{HTTPDUSER:ident} %{EMAILADDRESS:username} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:http_method} %{NOTSPACE:svn_path}(?: HTTP/%{NUMBER:http_version})?|%{DATA:svn_path})\" %{NUMBER:http_response} (?:%{NUMBER:content_length}|-)"
 
                                    ]    
                    }  
        }

        date {
            match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
        }

        mutate { 
            remove_field => ["http_version", "host", "path", "ident", "@version"] 
            }
    }

}

output {

    elasticsearch {

        hosts => "https://localhost:9200"
        index => "httpd_analyis"
        user => "elastic"
        password => "elastic"
        
    }
    stdout { }
}   

```

Please help me out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 9:37am UTC](https://discuss.elastic.co/t/logstash-unable-to-connect-ssl-enabled-elasticsearch/269570/2 "2021-05-06T09:37:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
