# Rsyslog logs stop when any security is enabled

**URL:** <https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, docker\
**Created:** [June 13, 2023, 12:19pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869 "2023-06-13T12:19:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 13, 2023, 12:19pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/1 "2023-06-13T12:19:46Z")

</div>

I have installed ELK 7.17.10 with podman, it works until I turn on security, even minimal security seems to block rsyslog from being received. What am I missing?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/2 "2023-06-13T13:05:01Z")

</div>

Hello and welcome,

You need to provide more context.

How are you sending your data to Elasticsearch?

---

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 13, 2023, 6:47pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/3 "2023-06-13T18:47:29Z")

</div>

it is set up in the server producing the logs, and does work when no security is enabled...its only when any security, even the bare minimum, (passwords) is enabled in elk, the indices stop being produced

> Blockquote

```auto
# elasticsearch
action(type="omelasticsearch"
    name="elasticsearch"
    dynSearchIndex="on"
    errorfile="/var/log/rsyslog/omelasticsearch.log"
    searchIndex="rsyslog-node-index"
    server="logs-devaron-dfw3.ole.redhat.com:9200"
    template="rsyslog-record"
    usehttps="off"

```

Going to give it a few more hours to see if the log rotation may give me something, maybe I am just unlucky in my timing. In the meantime is there anything I am missing when security is initially enable I may be missing? Makes no sense to me why it would not accept the logs into the server

---

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 13, 2023, 8:46pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/4 "2023-06-13T20:46:06Z")

</div>

So I waited and nothing, I turned off security and bam logs showed up  
`xpack.security.enabled: false`  
`control01-devaron-dfw3.ole.redhat.com-2023.06.13`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 13, 2023, 10:30pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/5 "2023-06-13T22:30:45Z")

</div>

> [@Ryan\_Caputo](#):
>
> ```auto
> # elasticsearch
> action(type="omelasticsearch"
> name="elasticsearch"
> dynSearchIndex="on"
> errorfile="/var/log/rsyslog/omelasticsearch.log"
> searchIndex="rsyslog-node-index"
> server="logs-devaron-dfw3.ole.redhat.com:9200"
> template="rsyslog-record"
> usehttps="off"
> 
> ```

Where is the `username` and `password` to authenticate on Elasticsearch?

If you enable security every request needs to be authenticated.

I do not use rsyslog to send logs to Elasticsearch, so I'm not sure on how or if it is possible to configure it, but you need to specify username and password.

---

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 14, 2023, 3:52am UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/6 "2023-06-14T03:52:48Z")

</div>

ah I see thanks!

---

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 21, 2023, 9:22pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/7 "2023-06-21T21:22:48Z")

</div>

Is it possible to wildcard or turn off user and password authentication?..all I want it transport layer talk between clusters so I can set up a single consolidation server.

---

<div class="post-metadata">

**Author:** ![Ryan\_Caputo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_caputo/32/122191_2.png) [@Ryan\_Caputo](https://discuss.elastic.co/u/Ryan_Caputo)\
**Post date:** [June 28, 2023, 2:04pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/8 "2023-06-28T14:04:29Z")

</div>

I set the anonymous user with full inicies rights and can curl Elasticsearch from the clients, I am able to PUT logs into the index without issue but connection from rsyslog doesn't seem to be fully working. Whats weird is occasionally logs come in but it is not consistent. Should the anonymous basically bypass the need for a username and password? What am I missing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2023, 2:04pm UTC](https://discuss.elastic.co/t/rsyslog-logs-stop-when-any-security-is-enabled/335869/9 "2023-07-26T14:04:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
