# Secure communication with Elasticsearch (SSL)

**URL:** <https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569>\
**Category:** Logstash\
**Created:** [September 1, 2016, 2:46pm UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569 "2016-09-01T14:46:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tsury](https://avatars.discourse-cdn.com/v4/letter/t/71c47a/32.png) [@Tsury](https://discuss.elastic.co/u/Tsury)\
**Post date:** [September 1, 2016, 2:46pm UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/1 "2016-09-01T14:46:58Z")

</div>

What are the best practices to secure the communication between Logstash and Elasticsearch? I'm looking for a non-commercial solution.

It is possible to direct Logstash to NGINX with SSL? If so, how would you go about achieving it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 4:40pm UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/2 "2016-09-01T16:40:13Z")

</div>

> It is possible to direct Logstash to NGINX with SSL?

Sure.

> If so, how would you go about achieving it?

Like you would set up NGinx as a reverse proxy for any other service. The only difference is that the port is 9200.

---

<div class="post-metadata">

**Author:** ![vinod\_hy](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Post date:** [June 5, 2017, 9:53am UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/3 "2017-06-05T09:53:31Z")

</div>

Even i have the same situation.  
I would like to make every communication secure.  
I have already achieved secure communiction between filebeat and logstash using SSL certificates.

Same thing i would like to achieve for logstash -\> elasticseach and kibana-\>elasticsearch.  
May i please know what is the easiest and preferred way to achieve this. I am looking for non commercial approach.

My setup is there is single central machine running kibana and elasticsearch. There are other machines running logstash and filebeat. Individual machine's logstash communicates to the central machine's elastic search which kibana picks up and displays it.

Please help me in knowing the preferred approach in securing the communication link.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 7, 2017, 5:57am UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/4 "2017-06-07T05:57:40Z")

</div>

@vinod_hy, please start a new thread for your question.

---

<div class="post-metadata">

**Author:** ![Ferrow](https://avatars.discourse-cdn.com/v4/letter/f/7bcc69/32.png) [@Ferrow](https://discuss.elastic.co/u/Ferrow)\
**Post date:** [December 5, 2017, 9:14am UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/5 "2017-12-05T09:14:51Z")

</div>

One reason why Vinod\_hy has to spam the forum, with yet another thread, instead of giving him an answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:27am UTC](https://discuss.elastic.co/t/secure-communication-with-elasticsearch-ssl/59569/6 "2022-11-04T04:27:33Z")

</div>


