# SASL\_PLAINTEXT AND SASL\_SSL ISSUE

**URL:** <https://discuss.elastic.co/t/sasl-plaintext-and-sasl-ssl-issue/383043>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 28, 2025, 10:32am UTC](https://discuss.elastic.co/t/sasl-plaintext-and-sasl-ssl-issue/383043 "2025-10-28T10:32:16Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thirupathi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thirupathi/32/145431_2.png) [@Thirupathi](https://discuss.elastic.co/u/Thirupathi)\
**Post date:** [October 28, 2025, 10:32am UTC](https://discuss.elastic.co/t/sasl-plaintext-and-sasl-ssl-issue/383043/1 "2025-10-28T10:32:16Z")

</div>

# Kafka Output Configuration (unified for both sources)

output.kafka:  
hosts: ["xxxxxxx:19094"] # Updated to use the SSL-enabled broker  
topic: 'npc-raw-msg'  
key: '%{[UUID]}'  
codec.format:  
string: '%{[message]}'  
partition.round\_robin:  
reachable\_only: false  
required\_acks: 1  
compression: gzip  
max\_message\_bytes: 1000000  
close\_inactive: 10m

# Enhanced Security Configuration

sasl.mechanism: SCRAM-SHA-512  
sasl.username: "admin"  
sasl.password: "admin-psswd"  
security.protocol: SASL\_PLAINTEXT  
#ssl.verification\_mode: full  
#ssl.certificate\_authorities: ["/etc/filebeat/certs/ca-cert.pem"]  
#ssl.verification\_mode: none  
timeout: 60s

# Retry configuration for better reliability

max\_retries: 3  
backoff.init: 1s  
backoff.max: 60s

"log.level":"error","@timestamp":"2025-10-28T06:20:15.900-0400","log.logger":"kafka","log.origin":{"function":"[github.com/elastic/beats/v7/libbeat/outputs/kafka.(\*client).errorWorker","file.name":"kafka/client.go","file.line":338},"message":"Kafka](http://github.com/elastic/beats/v7/libbeat/outputs/kafka.(*client).errorWorker%22,%22file.name%22:%22kafka/client.go%22,%22file.line%22:338%7D,%22message%22:%22Kafka) (topic=npc-raw-msg): kafka: couldn't fetch broker metadata (check that your client and broker are using the same encryption and authentication settings)","service.name":"filebeat","ecs.version":"1.6.0"}

{"log.level":"error","@timestamp":"2025-10-28T06:20:15.900-0400","log.logger":"kafka","log.origin":{"function":"[github.com/elastic/beats/v7/libbeat/outputs/kafka.(\*client).errorWorker","file.name":"kafka/client.go","file.line":338},"message":"Kafka](http://github.com/elastic/beats/v7/libbeat/outputs/kafka.(*client).errorWorker%22,%22file.name%22:%22kafka/client.go%22,%22file.line%22:338%7D,%22message%22:%22Kafka) (topic=npc-raw-msg): kafka: couldn't fetch broker metadata (check that your client and broker are using the same encryption and authentication settings)","service.name":"filebeat","ecs.version":"1.6.0"}

{"log.level":"error","@timestamp":"2025-10-28T06:20:15.900-0400","log.logger":"kafka","log.origin":{"function":"[github.com/elastic/beats/v7/libbeat/outputs/kafka.(\*client).errorWorker","file.name":"kafka/client.go","file.line":338},"message":"Kafka](http://github.com/elastic/beats/v7/libbeat/outputs/kafka.(*client).errorWorker%22,%22file.name%22:%22kafka/client.go%22,%22file.line%22:338%7D,%22message%22:%22Kafka) (topic=npc-raw-msg): kafka: couldn't fetch broker metadata (check that your client and broker are using the same encryption and authentication settings)","service.name":"filebeat","ecs.version":"1.6.0"}

{"log.level":"error","@timestamp":"2025-10-28T06:20:15.900-0400","log.logger":"kafka","log.origin":{"function":"[github.com/elastic/beats/v7/libbeat/outputs/kafka.(\*client).errorWorker","file.name":"kafka/client.go","file.line":338},"message":"Kafka](http://github.com/elastic/beats/v7/libbeat/outputs/kafka.(*client).errorWorker%22,%22file.name%22:%22kafka/client.go%22,%22file.line%22:338%7D,%22message%22:%22Kafka) (topic=npc-raw-msg): kafka: couldn't fetch broker metadata (check that your client and broker are using the same encryption and authentication settings)","service.name":"filebeat","ecs.version":"1.6.0"}
