Securing Logstash Communication without CA

I'm trying to figure out how to secure communication with Logstash without a CA?

Can't I just generate a key pair on the Logstash instance, SCP the public cert it to each of my servers that are feeding into it, and tell them to use this certificate? I'm not dealing with hundreds of servers by any means, just a small handful of VPS's.

