# No Data streams

**URL:** <https://discuss.elastic.co/t/no-data-streams/344985>\
**Category:** Kibana\
**Tags:** datastreams\
**Created:** [October 13, 2023, 10:26am UTC](https://discuss.elastic.co/t/no-data-streams/344985 "2023-10-13T10:26:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 13, 2023, 5:29pm UTC](https://discuss.elastic.co/t/no-data-streams/344985/2 "2023-10-13T17:29:44Z")

</div>

Hi @Jean-Claude Hope This Helps

> [@Jean-Claude](#):
>
> Elastic has self-signed certificate

Did you carefully read through this...

> **[Configure SSL/TLS for self-managed Fleet Servers | Fleet and Elastic Agent...](https://www.elastic.co/guide/en/fleet/current/secure-connections.html)**

If Elasticsearch is using a self-signed cert , then the Elastic Agents need that CA or [trusted fingerprint](https://www.elastic.co/guide/en/elasticsearch/reference/8.10/configuring-stack-security.html#_use_the_ca_fingerprint_5) because Agents send Data directly to Elasticsearch

See [Here](https://www.elastic.co/guide/en/fleet/current/secure-connections.html#_encrypt_traffic_between_elastic_agents_fleet_server_and_elasticsearch)

> To encrypt traffic between Elastic Agents, Fleet Server, and Elasticsearch:
> 
> 1. Configure Fleet settings. These settings are applied to all Fleet-managed Elastic Agents.
> 
> 2. In Kibana, open the main menu, then click **Management \> Fleet \> Settings**.
> 
> 3. Under **Fleet Server hosts** , specify the URLs Elastic Agents will use to connect to Fleet Server. For example, [https://192.0.2.1:8220](https://192.0.2.1:8220/), where 192.0.2.1 is the host IP where you will install Fleet Server.
> 
> For host settings, use the `https` protocol. DNS-based names are also allowed.
> 
> 1. Under **Outputs** , search for the default output, then click the **Edit** icon in the **Action** column.
> 2. In the **Hosts** field, specify the Elasticsearch URLs where Elastic Agents will send data. For example, [https://192.0.2.0:9200](https://192.0.2.0:9200/).
> 3. Specify either a CA certificate or CA fingerprint to connect securely Elasticsearch:  
> File path example:
> 
> - If you have a valid HEX encoded SHA-256 CA trusted fingerprint from root CA, specify it in the **Elasticsearch CA trusted fingerprint** field. To learn more, refer to the [Elasticsearch security documentation](https://www.elastic.co/guide/en/elasticsearch/reference/8.10/configuring-stack-security.html).
> - Otherwise, under **Advanced YAML configuration** , set `ssl.certificate_authorities` and specify the CA certificate to use to connect to Elasticsearch. You can specify a list of file paths (if the files are available), or embed a certificate directly in the YAML configuration. If you specify file paths, the certificates must be available on the hosts running the Elastic Agents.File path example:
> 
> `ssl.certificate_authorities: ["/path/to/your/elasticsearch-ca.crt"]`

Look at the diagram on [this](https://www.elastic.co/guide/en/fleet/current/fleet-server.html) page

 ![Screenshot 2023-10-13 at 10.22.46 AM](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5cba20e98ddef11ceb68ce741f1d9dca2a55ba0d.png)

 ![Screenshot 2023-10-13 at 10.20.10 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4fad083b7270717ebeafd6328669d500c8786a2a.png)

Note: if you use the Advanced YAML configuration

`ssl.certificate_authorities: ["/path/to/your/elasticsearch-ca.crt"]`

That path / CA will need to be available and readable on all hosts you deploy the agent to.

---

_[View the full topic](https://discuss.elastic.co/t/no-data-streams/344985)._
