# Sending data to elasticsearch

**URL:** <https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941>\
**Category:** Elasticsearch\
**Created:** [May 16, 2020, 6:01pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941 "2020-05-16T18:01:28Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 16, 2020, 6:01pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/1 "2020-05-16T18:01:28Z")

</div>

Hi,

Below is the configuration I have for my 2 node elasticsearch cluster.

Pls let me know how I should configure the logstash elasticsearch output. Should the data be sent to both the below nodes?

I am fully aware that a 2 node setup is not the best way forward, but my company has resource constraints hence this is the best we can setup as of now.

node-1

```auto
cluster.name: es-cluster
node.name: node1
path.data: E:/elasticsearch/data
path.logs: E:/elasticsearch/logs
network.host: node1.org
discovery.seed_hosts: ["node1","node2"]
cluster.initial_master_nodes: ["node2"]
node.master: true
node.data: true

```

node-2

```auto
cluster.name: es-cluster
node.name: node2
path.data: E:/elasticsearch/data
path.logs: E:/elasticsearch/logs
network.host: node2.org
discovery.seed_hosts: ["node1","node2"]
cluster.initial_master_nodes: ["node2"]
node.master: true
node.data: true

```

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 16, 2020, 6:23pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/2 "2020-05-16T18:23:09Z")

</div>

Hi,  
Yes I would recommend to configure the output to both nodes.  
I would also recommend to have a look at ilm (index lifecycle management).  
The output configuration depends for each infrastructure. But in the documentation you can find multiple examples how to configure (with ilm/ without ilm, with ssl/ without ssl, etc.)

Regards,  
Simon

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 17, 2020, 2:52am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/3 "2020-05-17T02:52:02Z")

</div>

Ok thank you, i will take a look at that

I have enabled ssl/tls across the elk stack, what else do you recommend i do for a 2 node setup @KoettingSimon

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 17, 2020, 6:56am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/4 "2020-05-17T06:56:34Z")

</div>

You already have configured the 2 nodes to be both, data and Master node.  
So the only thing I further could recommend is to set the replica of all indexes to 1 (Default setting).

Best,  
Simon

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/5 "2020-05-17T14:54:35Z")

</div>

Sure, confirmed regarding the replicas, set to 1 🙂

Ok, when the data the sent to only one node in a cluster setup it gets replicated on the other node right? Why do we then need to send data to both nodes? @KoettingSimon

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 17, 2020, 3:02pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/6 "2020-05-17T15:02:21Z")

</div>

You do not send it to both nodes, you send it to either node, which allows you to load balance. If you had more than 2 nodes this is how you achieve high availability.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 17, 2020, 3:11pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/7 "2020-05-17T15:11:06Z")

</div>

Thanks @Christian_Dahlqvist. I will send it to only the master node.

Also, regarding encrypted communications between both the elasticsearch nodes. Do i need to generate 2 separate ssl certificates and add it this way -  
ssl cert of node1 in elasticsearch.yml of node2 AND  
ssl cert of node2 in elasticsearch.yml of node1

OR

just a single ssl certificate which contains domain names of both node1 and node2.

I currently have kibana installed on node2 and have the domain name as [node2.org](http://node2.org), so this should point to node1 as well right?

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 17, 2020, 6:51pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/8 "2020-05-17T18:51:33Z")

</div>

Hi @nityaraj06

> [@nityaraj06](#):
>
> Ok, when the data the sent to only one node in a cluster setup it gets replicated on the other node right?

Yes, thats right.

> [@nityaraj06](#):
>
> Why do we then need to send data to both nodes?

As Christian said, you do not send the data to both nodes simultaneously. If you configure multiple hosts in the output configuration Logstash will load-balance between the host.

From the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-hosts):

> Sets the host(s) of the remote instance. If given an array it will load balance requests across the hosts specified in the `hosts` parameter.

So you dont need to configure the output to both host, but i recommend it to use the load balancing.

> [@nityaraj06](#):
>
> I will send it to only the master node.

As i can see in the config you posted, both nodes are masters, so which node do you mean?

> [@nityaraj06](#):
>
> Also, regarding encrypted communications between both the elasticsearch nodes. Do i need to generate 2 separate ssl certificates and add it this way -  
> ssl cert of node1 in elasticsearch.yml of node2 AND  
> ssl cert of node2 in elasticsearch.yml of node1
> 
> OR
> 
> just a single ssl certificate which contains domain names of both node1 and node2.

You need to create a certificate for each node and configure in the elasticsearch.yml the certificate of the node, so on node1 you configure the node1 certificate.  
Each node need to trust the issuing CA.  
To get started with Elastic-Stack security i recommend this [blog article](https://www.elastic.co/blog/getting-started-with-elasticsearch-security).

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 18, 2020, 5:14am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/9 "2020-05-18T05:14:30Z")

</div>

I'm a little confused here, so should I add both hosts or no? I would like the setup to be load balanced

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 18, 2020, 5:17am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/10 "2020-05-18T05:17:03Z")

</div>

Yes, if you want to use load balancing you need to configure both hosts in the elasticsearch output.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 18, 2020, 5:18am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/11 "2020-05-18T05:18:20Z")

</div>

ok thanks for all your help!

Also when i hit the kibana link the request would go to either node1 or node2 if i configure both in logstash output (since that would make it load balanced) ?

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 18, 2020, 5:31am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/12 "2020-05-18T05:31:32Z")

</div>

> [@nityaraj06](#):
>
> when i hit the kibana link the request would go to either node1 or node2 if i configure both in logstash output (since that would make it load balanced) ?

No, you just configure it for logstash.  
You can also configure multiple host in the kibana config, so kibana will also load balance.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 18, 2020, 6:00am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/13 "2020-05-18T06:00:04Z")

</div>

Ok so I have already set this in kibana.yml

`elasticsearch.hosts: ["http://node1:9200","http://node2:9200"]`

> You need to create a certificate for each node and configure in the elasticsearch.yml the certificate of the node, so on node1 you configure the node1 certificate.  
> Each node need to trust the issuing CA.

Since my setup will be load balanced now, do i still have 2 get 2 separate certificates or can i include both node1 and node2 domains in the single certificate. I have raised a request for a single cert for node2, just thinking if i should include node1 in it or raise a separate cert for node1.

> As i can see in the config you posted, both nodes are masters, so which node do you mean?

I meant node2 but now i will add both nodes in my logstash output

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 18, 2020, 6:16am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/14 "2020-05-18T06:16:23Z")

</div>

> [@nityaraj06](#):
>
> can i include both node1 and node2 domains in the single certificate

Im not an SSL-Pro but as i can read [here](https://security.stackexchange.com/questions/62690/can-i-use-a-single-ssl-cert-on-two-different-servers) this should be possible.  
But why do you want to use the same certificate? I would recommend to generate seperate certificates.

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 18, 2020, 1:07pm UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/15 "2020-05-18T13:07:42Z")

</div>

Hi @KoettingSimon as suggested I have got separate ssl certificates for node1 and node2 and I have configured node1 ssl certificate in node1 and likewise for node2.

However, I am receiving the below error now:

[server] failed to establish trust with server at []; certificate is not trusted in this ssl context ([xpack.security.transport.ssl])

node1

```auto
xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: E:/node1.pfx
xpack.security.http.ssl.truststore.path: E:/node1.pfx 

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: E:/node1.pfx
xpack.security.transport.ssl.truststore.path: E:/node1.pfx 

```

node2

```auto
xpack.security.enabled: true

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: E:/node2.pfx
xpack.security.http.ssl.truststore.path: E:/node2.pfx 

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: E:/node2.pfx
xpack.security.transport.ssl.truststore.path: E:/node2.pfx 

```

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 19, 2020, 5:06am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/16 "2020-05-19T05:06:39Z")

</div>

Is the issuing CA-Certificate included in the pfx files?

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 19, 2020, 7:20am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/17 "2020-05-19T07:20:14Z")

</div>

yes it is included

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 19, 2020, 7:29am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/18 "2020-05-19T07:29:19Z")

</div>

I am currently getting this error :

`java.security.cert.CertificateException: No subject alternative names matching IP address <ip-add> found`

---

<div class="post-metadata">

**Author:** ![KoettingSimon](https://avatars.discourse-cdn.com/v4/letter/k/ba9def/32.png) [@KoettingSimon](https://discuss.elastic.co/u/KoettingSimon)\
**Post date:** [May 19, 2020, 8:12am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/19 "2020-05-19T08:12:37Z")

</div>

> [@nityaraj06](#):
>
> No subject alternative names matching IP address

Sounds like you trying to access via the IP and SSL but in the Certificate the IP is not included as a subject alternative name.  
Some infos about the subject alternative name you can find [here](https://www.digicert.com/subject-alternative-name.htm).

---

<div class="post-metadata">

**Author:** ![nityaraj06](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@nityaraj06](https://discuss.elastic.co/u/nityaraj06)\
**Post date:** [May 19, 2020, 8:43am UTC](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941/20 "2020-05-19T08:43:25Z")

</div>

I haven't mentioned any IP(only DNS name which matches SAN of that node) in elasticsearch.yml so not sure why I am receiving this error.

Should I try adding the certificate of node2 in elasticsearch.yml settings

[Next page](https://discuss.elastic.co/t/sending-data-to-elasticsearch/232941.md?page=2)
