# Logstash - Unknown setting 'ssl\_certificate' & 'ssl\_key' for elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 27, 2020, 2:02pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887 "2020-11-27T14:02:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![atharvak](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Post date:** [November 27, 2020, 2:02pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/1 "2020-11-27T14:02:51Z")

</div>

Hi guys,  
I am trying to connect logstash with elasticsearch that has security enabled. While elasticsearch is running well with the SSL Certificates/keys, the same certificates/keys are not working for the Logstash. Following is my configuration and error.

1. My `output.conf` file.

```auto
output {
        file {
                create_if_deleted => true
                path => "/var/log/logstash/logstash_log"
                codec => "rubydebug"
        }
        elasticsearch {
                hosts => ["https://localhost:9200"]
                user => "admin"
                password => "admin"
                manage_template => false
                ssl => true
                cacert => "/etc/elasticseach/root-ca.pem"
                ssl_certificate => "/etc/elasticsearch/esnode.pem"
                ssl_key => "/etc/elasticsearch/esnode-key.pem"
                index => "%{[index_name]}-%{+YYYY.MM.dd}"
                document_id => "%{[@metadata][fingerprint]}"
                http_compression => true
        }
}

```

1. Error in logs

```auto
Nov 27 19:29:31 [localhost] logstash: [2020-11-27T19:29:31,573][ERROR][logstash.outputs.elasticsearch] Unknown setting 'ssl_certificate' for elasticsearch
Nov 27 19:29:31 [localhost] logstash: [2020-11-27T19:29:31,578][ERROR][logstash.outputs.elasticsearch] Unknown setting 'ssl_key' for elasticsearch

```

1. My `Elasticsearch` version is `7.9.1` and `Logstash` version is `7.9.1`

Any help is appreciated. Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2020, 2:20pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/2 "2020-11-27T14:20:42Z")

</div>

> [@atharvak](#):
>
> ```auto
> ssl_certificate => "/etc/elasticsearch/esnode.pem"
> ssl_key => "/etc/elasticsearch/esnode-key.pem"
> 
> ```

Delete these lines, the elasticsearch output does not support them.

---

<div class="post-metadata">

**Author:** ![atharvak](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Post date:** [November 27, 2020, 2:22pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/3 "2020-11-27T14:22:26Z")

</div>

Oh! Okay.  
But how should I add SSL certificates to the output conf?  
Because I have already added this, `cacert` is working but not rest...

```auto
               cacert => "/etc/elasticseach/root-ca.pem"
               ssl_certificate => "/etc/elasticsearch/kirk.pem"
               ssl_key => "/etc/elasticsearch/kirk-key.pem"

```

Because without SSL `ssl => true`, following error is showing.

```auto
Nov 27 19:56:25 [localhost] logstash: [2020-11-27T19:56:25,356][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"https://admin:xxxxxx@localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [https://admin:xxxxxx@localhost:9200/][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target"}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2020, 2:44pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/4 "2020-11-27T14:44:39Z")

</div>

> [@atharvak](#):
>
> `unable to find valid certification path to requested target`

That would suggest the cacert is not correct.

---

<div class="post-metadata">

**Author:** ![atharvak](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Post date:** [November 27, 2020, 2:59pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/5 "2020-11-27T14:59:05Z")

</div>

After removing the two lines mentioned, now it is taking `cacert` in account but Logstash service failing due to following reasons.

```auto
Nov 27 20:26:10 [localhost] logstash: LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError: Got response code '500' contacting Elasticsearch at URL 'https://localhost:9200/_xpack'

Nov 27 20:26:11 [localhost] logstash: [2020-11-27T20:26:11,009][FATAL][logstash.runner] An unexpected error occurred! {:error=>#<LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError: LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError>,...

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2020, 3:18pm UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/6 "2020-11-27T15:18:52Z")

</div>

Do the elasticsearch logs contain anything that explains the 500 response?

---

<div class="post-metadata">

**Author:** ![atharvak](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@atharvak](https://discuss.elastic.co/u/atharvak)\
**Post date:** [November 28, 2020, 10:38am UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/7 "2020-11-28T10:38:12Z")

</div>

Yes. It was another issue. Actually I am using Open distro for Elasticsearch, so it does not `x-pack` in it and Logstash was attempting to connect to its `/_xpack` endpoint. That is why it was failing with `500` error code. So I resolved that issue using [this method](https://github.com/elastic/logstash/issues/10783#issuecomment-505755371).  
Thank you for your assistance @Badger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2020, 10:38am UTC](https://discuss.elastic.co/t/logstash-unknown-setting-ssl-certificate-ssl-key-for-elasticsearch/256887/8 "2020-12-26T10:38:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
