# No More Logs After Enabling SSL and X-Pack

**URL:** <https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161>\
**Category:** Elasticsearch\
**Created:** [September 19, 2018, 5:12pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161 "2018-09-19T17:12:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tvoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tvoll/32/33651_2.png) [@tvoll](https://discuss.elastic.co/u/tvoll)\
**Post date:** [September 19, 2018, 5:12pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/1 "2018-09-19T17:12:54Z")

</div>

Running the Elastic Stack on v6.3.2, recently got X-Pack, but am now having issues with authenticating logstash/filebeat with SSL. I've created a username and password for each of the services, but nothing is appearing in kibana. I'm not seeing any errors with Filebeat either whenever I run it in debug mode.

**Elasticsearch.yml**

> path.data: /var/lib/elasticsearch  
> path.logs: /var/log/elasticsearch  
> network.host: 0.0.0.0  
> http.port: 9200  
> xpack.security.enabled: true  
> xpack.security.transport.ssl.enabled: true  
> xpack.security.transport.ssl.verification\_mode: certificate  
> xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12  
> xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12

**Kibana.yml**

> #server.port: 5601  
> server.host: "0.0.0.0"  
> elasticsearch.username: "kibana"  
> elasticsearch.password: "test"  
> xpack.security.enabled: true

**logstash.conf**

> input {  
> elasticsearch {  
> user =\> logstash\_internal  
> password =\> test  
> }  
> beats {  
> port =\> 5044  
> host =\> ["vkd01.scw.local:5044"]  
> }  
> }  
> filter {  
> elasticsearch {  
> user =\> logstash\_internal  
> password =\> test  
> }  
> if [fileset][module] == "nginx" {  
> if [fileset][name] == "access" {  
> grok {  
> match =\> { "message" =\> ["%{IPORHOST:[nginx][access][remote\_ip]} - %{DATA:[nginx][access][user\_name]} [%{HTTPDATE:[nginx][access][time]}] "%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http\_version]}" %{NUMBER:[nginx][access][response\_code]} %{NUMBER:[nginx][access][body\_sent][bytes]} "%{DATA:[nginx][access][referrer]}" "%{DATA:[nginx][access][agent]}""] }  
> remove\_field =\> "message"  
> }  
> mutate {  
> add\_field =\> { "read\_timestamp" =\> "%{@timestamp}" }  
> }  
> date {  
> match =\> ["[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]  
> remove\_field =\> "[nginx][access][time]"  
> }  
> useragent {  
> source =\> "[nginx][access][agent]"  
> target =\> "[nginx][access][user\_agent]"  
> remove\_field =\> "[nginx][access][agent]"  
> }  
> geoip {  
> source =\> "[nginx][access][remote\_ip]"  
> target =\> "[nginx][access][geoip]"  
> }  
> }  
> else if [fileset][name] == "error" {  
> grok {  
> match =\> { "message" =\> ["%{DATA:[nginx][error][time]} [%{DATA:[nginx][error][level]}] %{NUMBER:[nginx][error][pid]}#%{NUMBER:[nginx][error][tid]}: (\*%{NUMBER:[nginx][error][connection\_id]} )?%{GREEDYDATA:[nginx][error][message]}"] }  
> remove\_field =\> "message"  
> }  
> mutate {  
> rename =\> { "@timestamp" =\> "read\_timestamp" }  
> }  
> date {  
> match =\> ["[nginx][error][time]", "YYYY/MM/dd H:m:s" ]  
> remove\_field =\> "[nginx][error][time]"  
> }  
> }  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> localhost  
> user =\> logstash\_internal  
> password =\> test  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> }  
> }

**filebeat.yml**

> filebeat:  
> prospectors:  
> -  
> paths:  
> - /var/log/auth.log  
> - /var/log/syslog  
> - /opt/rails/farad/current/log/_.log  
> # - /var/log/_.log  
> document\_type: syslog
> 
> ```
> -
> paths:
> - /var/log/nginx/access.log
> fields:
> nginx: true
> fields_under_root: true
> document_type: nginx
> 
> input_type: log
> 
> ```
> 
> registry\_file: /var/lib/filebeat/registry
> 
> output:  
> logstash:  
> hosts: ["elkd01.scw.local:5044"]  
> username: "filebeat\_internal"  
> password: "test"  
> bulk\_max\_size: 1024
> 
> ```
> tls:
> certificate_authorities: ["/etc/pki/tls/certs/logstash-forwarder.crt"]
> 
> ```
> 
> shipper:
> 
> logging:  
> files:  
> rotateeverybytes: 10485760 # = 10MB

I have had filebeat communicating to logstash, and then logstash communicating the parsed information to Elasticsearch so that it could be viewed within Kibana. I'm not sure what I'm missing here, but I feel like it has to do with authentication (since it worked perfectly fine before).[I've been following this guide](https://www.elastic.co/guide/en/x-pack/current/ssl-tls.html#enable-ssl).

---

<div class="post-metadata">

**Author:** ![tvoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tvoll/32/33651_2.png) [@tvoll](https://discuss.elastic.co/u/tvoll)\
**Post date:** [September 19, 2018, 7:23pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/2 "2018-09-19T19:23:08Z")

</div>

Looking at my logstash logs, I do see a: _Exception: Elasticsearch::Transport::Transport::Errors::Forbidden_. Although the information that I am using for the username and password is correct. I also verified that the role (logstash\_writer) had all of the correct indices and privileges.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 19, 2018, 9:13pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/3 "2018-09-19T21:13:04Z")

</div>

Can you run a curl with the username and password you setup for Logstash?

---

<div class="post-metadata">

**Author:** ![tvoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tvoll/32/33651_2.png) [@tvoll](https://discuss.elastic.co/u/tvoll)\
**Post date:** [September 20, 2018, 1:20pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/4 "2018-09-20T13:20:09Z")

</div>

When I run:

> curl -u logstash\_internal:test localhost:9200

It returns:

> {  
> "name" : "x8xIclD",  
> "cluster\_name" : "elasticsearch",  
> "cluster\_uuid" : "2WaoioYjSbKLqWNbX6rAiQ",  
> "version" : {  
> "number" : "6.3.2",  
> "build\_flavor" : "default",  
> "build\_type" : "deb",  
> "build\_hash" : "053779d",  
> "build\_date" : "2018-07-20T05:20:23.451332Z",  
> "build\_snapshot" : false,  
> "lucene\_version" : "7.3.1",  
> "minimum\_wire\_compatibility\_version" : "5.6.0",  
> "minimum\_index\_compatibility\_version" : "5.0.0"  
> },  
> "tagline" : "You Know, for Search"  
> }

---

<div class="post-metadata">

**Author:** ![tvoll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tvoll/32/33651_2.png) [@tvoll](https://discuss.elastic.co/u/tvoll)\
**Post date:** [September 20, 2018, 4:40pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/5 "2018-09-20T16:40:51Z")

</div>

Strangely enough, everything is working now. I'm not sure if the services just needed to restart, but as long as I have the protocol set to http, and have the username and password at the end of the configuration files, it appears to work just fine!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2018, 4:40pm UTC](https://discuss.elastic.co/t/no-more-logs-after-enabling-ssl-and-x-pack/149161/6 "2018-10-18T16:40:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
