# SSL Communication

**URL:** <https://discuss.elastic.co/t/ssl-communication/129440>\
**Category:** Elasticsearch\
**Created:** [April 25, 2018, 9:23am UTC](https://discuss.elastic.co/t/ssl-communication/129440 "2018-04-25T09:23:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Pm](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@Rahul\_Pm](https://discuss.elastic.co/u/Rahul_Pm)\
**Post date:** [April 25, 2018, 9:23am UTC](https://discuss.elastic.co/t/ssl-communication/129440/1 "2018-04-25T09:23:03Z")

</div>

Hi,

1. I'm trying to secure communication between Logstash and Filebeat using SSL (windows). After installing X-pack there is no data flowing in.
2. Also there is no logs in the filebeat folder despite manually creating Filebeat.log.

Please find the filebeat.yml and logstash.conf files below  
Filebeat.yml  
.  
.  
output.logstash:

# The Logstash hosts

hosts: ["192.x.x.x:5044"]

# Optional SSL. By default is off.

ssl.enabled: true

# List of root certificates for HTTPS server verifications

ssl.certificate\_authorities: "S:\IDM\filebeat-6.2.2-windows-x86\_64\NewCertificates\ca\ca.crt"

# Certificate for SSL client authentication

ssl.certificate: "S:\IDM\filebeat-6.2.2-windows-x86\_64\NewCertificates\IDM01-Filebeat\IDM01-Filebeat.crt"

# Client Certificate Key

ssl.key: "S:\IDM\filebeat-6.2.2-windows-x86\_64\NewCertificates\IDM01-Filebeat\IDM01-Filebeat.key"

#logging.selectors: ["\*"]

logging.to\_files: true  
logging.files.path: "S:\IDM\filebeat-6.2.2-windows-x86\_64\logs\filebeat.log"

Logstash.conf  
.  
.  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate\_authorities =\> "C:\ELK6.2.2\elasticsearch-6.2.2\bin\x-pack\NewCertificates\ca\ca.crt"  
ssl\_certificate =\> "C:\ELK6.2.2\elasticsearch-6.2.2\bin\x-pack\NewCertificates\ELK\ELK.crt"  
ssl\_key =\> "C:\ELK6.2.2\elasticsearch-6.2.2\bin\x-pack\NewCertificates\ELK\ELK.key"  
ssl\_verify\_mode =\> "peer"  
}  
}

Am I missing anything? Please help.  
Regards,  
Rahul

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [April 26, 2018, 8:45pm UTC](https://discuss.elastic.co/t/ssl-communication/129440/2 "2018-04-26T20:45:17Z")

</div>

All steps can be found here: [https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ssl-logstash.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ssl-logstash.html)

your filebeat output should look something like:

```auto
output.logstash:
  hosts: ["logs.mycompany.com:5044"]
  ssl.certificate_authorities: ["/etc/ca.crt"]
  ssl.certificate: "/etc/client.crt"
  ssl.key: "/etc/client.key"

```

logstash input should look something like:

```auto
input {
  beats {
    port => 5044
    ssl => true
    ssl_certificate_authorities => ["/etc/ca.crt"]
    ssl_certificate => "/etc/server.crt"
    ssl_key => "/etc/server.key"
    ssl_verify_mode => "force_peer"
  }
}

```

Before running Filebeat, you should validate the Logstash server’s certificate:  
`curl -v --cacert S:\IDM\filebeat-6.2.2-windows-x86_64\NewCertificates\ca\ca.crt 192.x.x.x:5044`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 8:45pm UTC](https://discuss.elastic.co/t/ssl-communication/129440/3 "2018-05-24T20:45:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
