# Secure Logstash and Filebeats communication

**URL:** <https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912>\
**Category:** Logstash\
**Created:** [August 2, 2023, 9:21am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912 "2023-08-02T09:21:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Seemant\_Bind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seemant_bind/32/107045_2.png) [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Post date:** [August 2, 2023, 9:21am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/1 "2023-08-02T09:21:54Z")

</div>

We are working on an integration where we need to take logs from Filebeat through Logstash. However, Filebeat and Logstash are hosted in different networks. In order to secure the communication, we want to implement SSL. My question, is self-signed CA certificate sufficient to secure the communication? or is it mandatory to deploy a third-party CA certificate?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 2, 2023, 12:21pm UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/2 "2023-08-02T12:21:30Z")

</div>

> [@Seemant\_Bind](#):
>
> My question, is self-signed CA certificate sufficient to secure the communication?

Yes, it is.

The example in the [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ssl-logstash.html#configuring-ssl-logstash) uses a self-signed CA to secure communications between the beats and logstash.

---

<div class="post-metadata">

**Author:** ![Seemant\_Bind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seemant_bind/32/107045_2.png) [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Post date:** [August 2, 2023, 2:15pm UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/3 "2023-08-02T14:15:58Z")

</div>

Thanks for the quick response. Wish you a Happy Birthday.

I have generated and deployed the self- signed certificate. Now Filebeat and Logstash are communicating and getting the data in Logstash.

Here is my configurations –

**Logstash=\>**

```auto
input {

beats {

port => 5044

type => test_data

ssl => true

ssl_key => '/etc/logstash/logstash_dev.pkcs8.key'

ssl_certificate => '/etc/logstash/logstash_dev.crt'

ssl_verify_mode => "force_peer"

ssl_certificate_authorities => ["/etc/logstash/ca.crt"]

}

}

```

**Filebeat=\>**

```auto
output.logstash:

hosts: ["x.x.x.xxx:5044"]

ssl.certificate_authorities: ["C:/Elastic/ca.crt"]

ssl.certificate: "C:/Elastic/filebeat_local.crt"

ssl.key: "C:/Elastic/filebeat_local.key"

```

However when I am trying to verify the certificate using the following command –

`openssl s_client -connect localhost:5044`

Getting verification error -

**SSL handshake has read 1345 bytes and written 416 bytes**

**Verification error: unable to verify the first certificate**

`openssl s_client -connect localhost:5044`

**output -**

CONNECTED(00000005)

depth=0 CN = logstash\_dev

verify error:num=20:unable to get local issuer certificate

verify return:1

depth=0 CN = logstash\_dev

verify error:num=21:unable to verify the first certificate

verify return:1

139967055057344:error:14094412:SSL routines:ssl3\_read\_bytes:sslv3 alert bad certificate:../ssl/record/rec\_layer\_s3.c:1528:SSL alert number 42

* * *

Certificate chain

0 s:CN = logstash\_dev

i:CN = Elastic Certificate Tool Autogenerated CA

Can you please help me to resolve this issue? Your help will be highly appreciated.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 2, 2023, 3:10pm UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/4 "2023-08-02T15:10:43Z")

</div>

> [@Seemant\_Bind](#):
>
> Can you please help me to resolve this issue?

I'm not sure what is the issue, is Filebeat and Logstash communicating with each other? If so, then there is no issue.

If I'm not wrong, the `openssl` error you are getting is expected as you are using a self-signed CA that is not on the certificates path of your system, you would need to use the `-CAfile` pointing to your CA file, I think.

---

<div class="post-metadata">

**Author:** ![Seemant\_Bind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seemant_bind/32/107045_2.png) [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Post date:** [August 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/5 "2023-08-03T07:51:17Z")

</div>

Thanks for your response.  
Is there any way to verify if my self signed certificate? Want to ensure my deployed certificate is working properly and can be moved into production.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2023, 7:51am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912/6 "2023-08-31T07:51:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
