# Sending logs to logstash securely

**URL:** <https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784>\
**Category:** Logstash\
**Created:** [January 9, 2016, 11:29am UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784 "2016-01-09T11:29:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pritchardjonathan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pritchardjonathan/32/7059_2.png) [@pritchardjonathan](https://discuss.elastic.co/u/pritchardjonathan)\
**Post date:** [January 9, 2016, 11:29am UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784/1 "2016-01-09T11:29:52Z")

</div>

Hi,

First, apologies for the noob question. I have my ELK server and application servers in different locations. I'm unclear about the best route to take to securely send my logs over the web. I know that lumberjack and Logstash use SSL to encrypt the data and ensure that the application servers are actually talking to the right elk server but does this guarantee that only my application servers can connect and send logs? Should I set up VPN or SSH tunnels between these servers? All the Logstash tutorials I've seen talk about private IPs which indicates that this might be the case.

Thanks in advance.

Jon

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2016, 3:42pm UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784/2 "2016-01-09T15:42:39Z")

</div>

Client certificate validation is currently not supported, i.e. TLS only helps with message integrity and privacy, not authentication. See [How to Setup FileBeat with Basic Auth for LogStash Output?](https://discuss.elastic.co/t/how-to-setup-filebeat-with-basic-auth-for-logstash-output/36937) and [https://github.com/logstash-plugins/logstash-input-beats/issues/8](https://github.com/logstash-plugins/logstash-input-beats/issues/8).

---

<div class="post-metadata">

**Author:** ![pritchardjonathan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pritchardjonathan/32/7059_2.png) [@pritchardjonathan](https://discuss.elastic.co/u/pritchardjonathan)\
**Post date:** [January 9, 2016, 4:55pm UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784/3 "2016-01-09T16:55:22Z")

</div>

Great, thanks for the reply. I've set up an OpenVPN connection between the servers and will send logs over that. I guess TLS is not really necessary if sending logs over vpn?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2016, 6:30pm UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784/4 "2016-01-09T18:30:47Z")

</div>

Indeed, since the VPN connection itself is encrypted you don't need to encrypt the log stream separately.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:16am UTC](https://discuss.elastic.co/t/sending-logs-to-logstash-securely/38784/5 "2017-07-06T05:16:15Z")

</div>


