# Problem with logstash output to elastic via ssl

**URL:** <https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248>\
**Category:** Logstash\
**Created:** [November 27, 2017, 4:18pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248 "2017-11-27T16:18:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![111126](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111126/32/36818_2.png) [@111126](https://discuss.elastic.co/u/111126)\
**Post date:** [November 27, 2017, 4:18pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/1 "2017-11-27T16:18:05Z")

</div>

Hello.  
I have the next output config:

> ```
> output {
> file {
> path => "/var/log/logstash/output"
> }
> 
> elasticsearch {
> hosts => ["https://127.0.0.1:9200"]
> index => "example-test"
> ssl => true
> cacert => "/etc/logstash/keys/logstash-test.key"
> user => "logstash_system"
> password => "qwerty"
> }
> }
> 
> ```

And logstash do not connected to es. In log, I view next messages:

> [WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/)",  
> :error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError, :error=\>"Elasticsearch Unreachable: [[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/)][Manticore::ClientProt  
> ocolException] 127.0.0.1:9200 failed to respond"}
> 
> [WARN][logstash.licensechecker.licensereader] Marking url as dead. Last error: [LogStash::Outputs::Elasticsearch::HttpClient::Pool::HostUnreachableError] Elast  
> icsearch Unreachable: [[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/)][Manticore::ClientProtocolException] 127.0.0.1:9200 failed to respond {:url=\>[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/), :error\_m  
> essage=\>"Elasticsearch Unreachable: [[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/)][Manticore::ClientProtocolException] 127.0.0.1:9200 failed to respond", :error\_class=\>"LogStash::Outputs::Elas  
> ticSearch::HttpClient::Pool::HostUnreachableError"}
> 
> [ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"#\<LogStash::OutputDelegator:0x158b7b08 @namespaced\_metric=#\<LogStas  
> h::Instrument::NamespacedMetric:0x7fcd616e @metric=#\<LogStash::Instrument::Metric:0xe43efe9 @collector=#\<LogStash::Instrument::Collector:0x4e3e8046 @agent=nil, @metric\_store=#\<LogStash:  
> :Instrument::MetricStore:0xa3f1b2 @store=#\<Concurrent:🗺0x00000000000fb8 entries=3 default\_proc=nil\>, @structured\_lookup\_mutex=#\<Mutex:0x147

I set hosts =\> ["[https://127.0.0.1:9200](https://127.0.0.1:9200)"] in config,but in logs say taht logstash connected to [[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/)].

I check connect from console:  
curl -k -XGET [https://127.0.0.1:9200](https://127.0.0.1:9200) -u logstash\_system  
and it work!

---

<div class="post-metadata">

**Author:** ![111126](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111126/32/36818_2.png) [@111126](https://discuss.elastic.co/u/111126)\
**Post date:** [November 30, 2017, 9:03am UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/2 "2017-11-30T09:03:49Z")

</div>

help please

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 30, 2017, 9:36am UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/3 "2017-11-30T09:36:54Z")

</div>

Have you gone through [these settings](https://www.elastic.co/guide/en/logstash/6.0/configuring-logstash.html)?

---

<div class="post-metadata">

**Author:** ![111126](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111126/32/36818_2.png) [@111126](https://discuss.elastic.co/u/111126)\
**Post date:** [December 1, 2017, 2:55pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/4 "2017-12-01T14:55:11Z")

</div>

I do these settings and after that I have next error:

> :error=\>"Host name '127.0.0.1' does not match the certificate subject provided by the peer (CN=N4xpr8W)"

---

<div class="post-metadata">

**Author:** ![111126](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/111126/32/36818_2.png) [@111126](https://discuss.elastic.co/u/111126)\
**Post date:** [December 1, 2017, 3:27pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/5 "2017-12-01T15:27:37Z")

</div>

I regenerate certs, with ip. and it work. But logstash can not create template

> [ERROR][logstash.outputs.elasticsearch] Failed to install template. {:message=\>"Got response code '403' contacting Elasticsearch at URL '[https://127.0.0.1:9200/\_template/logstash](https://127.0.0.1:9200/_template/logstash)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 3:27pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-to-elastic-via-ssl/109248/6 "2017-12-29T15:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
