# Multiple Logstash output with different SSL signing authorities, certificates and keys

**URL:** <https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 30, 2017, 9:48am UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398 "2017-06-30T09:48:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Platypus](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@Platypus](https://discuss.elastic.co/u/Platypus)\
**Post date:** [June 30, 2017, 9:48am UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398/1 "2017-06-30T09:48:56Z")

</div>

Hello,

I need Filebeat to send the same logs to two different logstash endpoints with differents signing authorities, certificates and keys. I have test them separetly and the connexion with both endpoints works fine. But, once I try them at the same time filebeat only sends the logs to one of the endpoints.

First I tried the load balancing option:

```
output.logstash:
   hosts: ["end_point1:5044", "end_point2:5044"]
   loadbalance : true
   ssl.certificate_authorities: ["/etc/ssl/certs/end_point1.cer", /etc/ssl/certs/end_point2.cer"]
   ssl.certificate: "/etc/ssl/certs/end_point1.cer"
   ssl.key: "/etc/ssl/certs/end_point1.key"
   ssl.certificate: "/etc/ssl/certs/end_point2.cer"
   ssl.key: "/etc/ssl/certs/end_point2.key"

```

I tried also to put both keys and certificates in a list as for certificate\_authorities but I got a invalid type error. And then I tried to define two ouputs:

```
output.logstash:
  hosts: ["end_point1:5044"]
  ssl.certificate_authorities: ["/etc/ssl/certs/end_point1.cer"]
  ssl.certificate: "/etc/ssl/certs/end_point1.cer"
  ssl.key: "/etc/ssl/certs/end_point1.key"

output.logstash:
  hosts: ["end_point2:5044"]
  ssl.certificate_authorities: ["/etc/ssl/certs/end_point2.cer"]
  ssl.certificate: "/etc/ssl/certs/end_point2.cer"
  ssl.key: "/etc/ssl/certs/end_point2.key"

```

But none of this worked...

Any ideas?

note: I have tried loadbalancing without using ssl and it also worked

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 30, 2017, 10:53am UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398/2 "2017-06-30T10:53:28Z")

</div>

This kind of use-case has been discussed here: [https://github.com/elastic/beats/issues/1035](https://github.com/elastic/beats/issues/1035)

filebeats purpose is to ship logs off, of one server. Implicit coupling between to LS instances via filebeat can lead to troubles in doing so. It's recommended to use an intermedia queuing service (LS with persistent queues, redis, kafka), to ship logs and decouple the downstream systems.

---

<div class="post-metadata">

**Author:** ![Platypus](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@Platypus](https://discuss.elastic.co/u/Platypus)\
**Post date:** [July 3, 2017, 11:23am UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398/3 "2017-07-03T11:23:19Z")

</div>

Thank you for your reply but isn't there any other way of doing this without adding a queuing system? This is only a temporary solution while we migrate from one platform to another and I will prefer not adding more complexity.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 3, 2017, 1:45pm UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398/4 "2017-07-03T13:45:14Z")

</div>

You can have two filebeat instances run (each with it's own registry file). As every filebeat instance is processing the same file, there will be (almost) no coupling between the systems you push to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2017, 1:45pm UTC](https://discuss.elastic.co/t/multiple-logstash-output-with-different-ssl-signing-authorities-certificates-and-keys/91398/5 "2017-07-31T13:45:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
