# Setup Logstash to run via SSL (No FileBeats)

**URL:** <https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636>\
**Category:** Logstash\
**Created:** [February 8, 2019, 1:39pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636 "2019-02-08T13:39:43Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [February 8, 2019, 1:39pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/1 "2019-02-08T13:39:43Z")

</div>

Team, Am looking to see how I can enable TLS/SSL (similar to how Kibana can be run via SSL). The intent is to startup Logstash on an EC2 on SSL so that the ALB that the EC2 is registered does traffic/health on HTTPS and not HTTP. We have zero requirement for filebeats. Can someone suggest how I can do this?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 11, 2019, 12:03am UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/2 "2019-02-11T00:03:47Z")

</div>

Which logstash input are you looking to monitor via the ALB?  
Logstash doesn't necessarily open _any_ ports, so what you're asking for isn't as simple as it sounds.

For example, if you are using logstash to process data from files, or from a database then there's no HTTP/S port to monitor.

We need a bit more info from you to be able to give you any guidance.

---

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [February 11, 2019, 10:22am UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/3 "2019-02-11T10:22:28Z")

</div>

We are using http input only. The logstash instance I'm spinning up is via docker. The issue is more of the parent framework our enterprise uses to launch docker. The framework sets the ALB health check and instances port to Https and 443.  
We had the same issue spinning up kibana but since kibana has the ssl configuration natively, using SSL settings in kibana.yml allowed it's Alb to ping it correctly.

We're trying to do the same thing for logstash.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 11, 2019, 2:01pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/4 "2019-02-11T14:01:45Z")

</div>

Hi @titan1978,

you could use a [TCP input](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html#plugins-inputs-tcp-options) which lets you configure SSL.

There might be reasons why that would not work. I don't know AWS stuff...

Cheers,  
AB

---

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [February 11, 2019, 2:08pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/5 "2019-02-11T14:08:01Z")

</div>

why wouldnt Http Input work?

[https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html)

it does seem to have ssl support. Just looking for guidance on how to configure it!

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 11, 2019, 2:20pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/6 "2019-02-11T14:20:25Z")

</div>

Right, sorry... We only use UDP or TCP inputs where I work 😛

What issues do you have? Looks like the private key has to be in PKCS8 format. I have had to do that with _lumberjack_ inputs. Logstash will fail to start if the cert is in the wrong format. IIRC the logs did say that quite clearly when I finally took the time to read them.

You can convert the private key with

```
# openssl pkcs8 -topk8 -nocrypt -in privkey.pem
```

---

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [February 11, 2019, 2:23pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/7 "2019-02-11T14:23:44Z")

</div>

Could you paste your input config from the .conf file here?

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 11, 2019, 2:28pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/8 "2019-02-11T14:28:05Z")

</div>

As I said, we don't use `http` inputs but I would imagine this should work.

```
input {
  http {
    ssl => true
    ssl_certificate => "/etc/logstash/ssl/example.crt"
    ssl_key => "/etc/logstash/ssl/example.key"
  }
}

```

Default port is 8080. And the private key has to be in PKCS8 format.

---

<div class="post-metadata">

**Author:** ![titan1978](https://avatars.discourse-cdn.com/v4/letter/t/c37758/32.png) [@titan1978](https://discuss.elastic.co/u/titan1978)\
**Post date:** [February 12, 2019, 1:50pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/9 "2019-02-12T13:50:25Z")

</div>

> [@A\_B](#):
>
> Default port is 8080. And the private key has to be in PKCS8 format.

thanks. Curious - if SSL is enabled - shouldn't the default port be 443

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 12, 2019, 2:17pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/10 "2019-02-12T14:17:12Z")

</div>

> [@titan1978](#):
>
> thanks. Curious - if SSL is enabled - shouldn't the default port be 443

Just quoting the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http.html#plugins-inputs-http-port)

I guess it is because the default for `ssl` is false.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2019, 2:17pm UTC](https://discuss.elastic.co/t/setup-logstash-to-run-via-ssl-no-filebeats/167636/11 "2019-03-12T14:17:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
