# Logstash without SSL?

**URL:** <https://discuss.elastic.co/t/logstash-without-ssl/732>\
**Category:** Logstash\
**Created:** [May 15, 2015, 6:56am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732 "2015-05-15T06:56:57Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [May 15, 2015, 6:56am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/1 "2015-05-15T06:56:58Z")

</div>

Hi,  
I want to know whether we can ship logs to logstash without SSL? is there any way to disable SSL and then configure logstash and forwarder without SSL certificates?

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![Joshua\_Rich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_rich/32/44953_2.png) [@Joshua\_Rich](https://discuss.elastic.co/u/Joshua_Rich)\
**Post date:** [May 15, 2015, 7:35am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/2 "2015-05-15T07:35:52Z")

</div>

Hi @sunilmchaudhari,

Just out of curiosity, why do you need to disable SSL? Logstash-forwarder will be your problem here, it requires encryption. Instead, you could replace the forwarder with another Logstash instance or use a syslog client to forward the logs via plain tcp or udp.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [May 15, 2015, 8:21am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/3 "2015-05-15T08:21:03Z")

</div>

Hi @Joshua_Rich,  
to answer your question, we have some process to create certificates on test environment.  
I don't want to wait till that time and want to test whether its working or not. Its just temporarily i want to disable SSL for testing purpose.  
what do you mean by syslog client?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 15, 2015, 11:45am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/4 "2015-05-15T11:45:38Z")

</div>

> to answer your question, we have some process to create certificates on test environment.  
> I don't want to wait till that time and want to test whether its working or not. Its just temporarily i want to disable SSL for testing purpose.

But if it's just for testing purposes, why not just create the certificate and key yourself?

> what do you mean by syslog client?

Any program that's capable of reading logs and sending them via the syslog protocol. Like Logstash.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 15, 2015, 10:06pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/5 "2015-05-15T22:06:44Z")

</div>

There are forks of the LSF out there that don't require SSL.

---

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [July 15, 2015, 1:46pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/6 "2015-07-15T13:46:18Z")

</div>

Could you please direct us to a link? Here is a case where SSL will not be required: we have a private network with applications running and to access this network/application you would have already been authenticated. So SSL would only be an additional overhead. Our current roadmap is that we do not require SSL but in the future for clients SSL may require.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [July 15, 2015, 2:28pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/7 "2015-07-15T14:28:26Z")

</div>

Hi,  
I am not expert. however, I think you can use logstash in shipper mode in your case, skipping LSF.

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [July 15, 2015, 2:57pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/8 "2015-07-15T14:57:04Z")

</div>

Shipper mode? I have multiple instances of different versions of the same application running on many servers. All within the same private network. How does shipper mode work?

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [July 16, 2015, 3:18am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/9 "2015-07-16T03:18:06Z")

</div>

Hi,  
shipper mode--\> instead of using logstash forwarder, you can use logstash as below.

input {  
file {  
type =\> "testType"  
path =\> "C:/MyDirectory/logging.log"

}

output {  
redis {  
host =\> ... # string, default: "127.0.0.1"  
key =\> ... # string  
port =\> ... # number, default: 6379

}  
}

So it will ship logs to the broker and then another instance of logstash (called indexer) will take data from broker and output to elasticsearch.

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [July 16, 2015, 5:58am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/10 "2015-07-16T05:58:18Z")

</div>

Yup sorry complete forgot about that option. I just kept in my mind that using a logstash instance will be very heavy on the cpu and memory. But is redis just a protocol? Or do you actually have to create shippers? I am trying to learn the best way to ship logs between servers on the same private network.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [July 16, 2015, 6:24am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/11 "2015-07-16T06:24:52Z")

</div>

Hi,  
Shipper is the concept only. It just ships logs from source to the destination (broker/filter/elasticsearch). In your case I am not sure if you are using any broker in between shipper and filter. So here in your case you can use logstash to take input form file and output to redis (if you are using). this forms basic shipper structure.

Redis is broker which holds data in memory. It basically solves purpose of asynchronous communication between client and server. You need to download and install it on server. Provide its host and default port:6379 in logstash (shipper) output as shown.

I am using below design in my project:

LSF (client side) ==\> LS (shipper : Input from lumberjack and output to redis) ==\> LS (Indexer: input from redis and output to Elasticsearch )

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![michaellizhou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michaellizhou/32/4143_2.png) [@michaellizhou](https://discuss.elastic.co/u/michaellizhou)\
**Post date:** [July 16, 2015, 3:58pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/12 "2015-07-16T15:58:58Z")

</div>

Interesting. Just familiarizing myself with some of these terms. I think I can further simplify this by not having a redis instance running.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 17, 2015, 2:21am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/13 "2015-07-17T02:21:21Z")

</div>

[https://github.com/driskell/log-courier](https://github.com/driskell/log-courier) is one example/

---

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [March 18, 2016, 10:42pm UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/14 "2016-03-18T22:42:21Z")

</div>

Hi,  
I am trying to use logstash shipper to ship some logs to redis queue in another server...can u help me?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 19, 2016, 2:01am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/15 "2016-03-19T02:01:40Z")

</div>

Please start your own thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732/16 "2017-07-06T05:06:22Z")

</div>


