# SSL/TLS connection between ELK-Stack with Docker

**URL:** <https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [April 28, 2023, 10:00am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040 "2023-04-28T10:00:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lokutus25](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Post date:** [April 28, 2023, 10:00am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/1 "2023-04-28T10:00:19Z")

</div>

Hi,  
I have a big problem with my ELK-Stack (version 8.7.0) created with docker.  
I have created elasticsearch, kibana, logstash and filebeat with docker-compose.

elasticsearch and kibana connects per ssl with the token, I've created with elasticsearch, that works fine. But the other services did not work with SSL.

Here is the way it should work:  
Filebeat reads Logfiles that is connected per volume to filebeat.  
Filebeat should send it to Logstash. Logstash filter the data and send it to elasticsearch.

The Connection from filebeat to logstash could not established.  
I get this message:

```auto
Failed to publish events caused by: write tcp 192.168.13.6:49220->192.168.13.4:5044: write: connection reset by peer

```

The only documentation I've found is for local installations. I tried to adopt this, but it failed every time. I did not get a connection per SSL/TLS

Does anyone have experience with this and can help me?

---

<div class="post-metadata">

**Author:** ![Lokutus25](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Post date:** [May 19, 2023, 8:44am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/2 "2023-05-19T08:44:19Z")

</div>

Does nobody have a solution for this?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 19, 2023, 12:09pm UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/3 "2023-05-19T12:09:38Z")

</div>

> [@Lokutus25](#):
>
> Does nobody have a solution for this?

You didn't share your docker-compose, you need to share it.

The error you are getting is unrelated to any tool on the stack, it is a network error, you first need to check if the containers can talk with each other on the specified ports.

---

<div class="post-metadata">

**Author:** ![Lokutus25](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Post date:** [May 31, 2023, 7:48am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/4 "2023-05-31T07:48:27Z")

</div>

This is my docker-compose

```auto
---
### Version 1.0.4
services:
### Elasticsearch Installation ########################################        
    sq-docker-elasticsearch:
        image: elasticsearch:8.6.2
        container_name: sq-docker-elasticsearch
        ports:
            - 9200:9200
            - 9300:9300
        volumes:
            - ./elasticsearchdata/data:/usr/share/elasticsearch/data
            - ./elasticsearchlogs:/usr/share/elasticsearch/logs
            - ./elasticsearchconf/config:/usr/share/elasticsearch/config
        networks:
            brdo0:
                ipv4_address: 192.168.13.2
        hostname: elasticsearch
        restart: unless-stopped

### Kibana Installation ################################################
    sq-docker-kibana:
        image: kibana:8.6.2
        container_name: sq-docker-kibana
        ports:
            - 5601:5601
        volumes:
            - ./kibana/config:/usr/share/kibana/config
            - ./kibana_data:/usr/share/kibana/data
            - /etc/timezone:/etc/timezone:ro
            - /etc/localtime:/etc/localtime:ro
        networks:
            brdo0:
                ipv4_address: 192.168.13.3   
        hostname: kibana
        links:
          - sq-docker-elasticsearch:elasticsearch
        restart: unless-stopped

### Logstash Installation ###############################################
    sq-docker-logstash:
        image: logstash:8.6.2
        container_name: sq-docker-logstash
        ports:
            - 9500:9500
            - 9350:5000
            - 9351:5044
        volumes:
            - ./logstash/config/logstash.yml:/usr/share/logstash/config/logstash.yml
            - ./logstash/pipeline:/usr/share/logstash/pipeline
            - /etc/timezone:/etc/timezone:ro
            - /etc/localtime:/etc/localtime:ro
        networks:
            brdo0:
                ipv4_address: 192.168.13.4
        hostname: logstash
        links:
          - sq-docker-elasticsearch:elasticsearch
        restart: unless-stopped

### Filebeat Installation ################################################
    sq-docker-filebeat:
        image: docker.elastic.co/beats/filebeat:8.6.2
        container_name: sq-docker-filebeat
        volumes:
            - ./filebeat/config/filebeat.yml:/usr/share/filebeat/filebeat.yml
            - /var/lib/docker/containers:/var/lib/docker/containers:ro
            - /var/run/docker.sock:/var/run/docker.sock:ro
            - ./storage/jenkins:/usr/share/jenkins_home:ro
            - ./filebeat/prospectors.d/:/usr/share/filebeat/prospectors.d/
            - /etc/timezone:/etc/timezone:ro
            - /etc/localtime:/etc/localtime:ro
        user: root
        environment:
            - strict.perms=false
            - output.elasticsearch.hosts=["sq-docker-elasticsearch:9200"]
        links:
          - sq-docker-elasticsearch:elasticsearch
        networks:
            brdo0:
                ipv4_address: 192.168.13.6
        hostname: filebeat
        restart: unless-stopped

### Network Declaration ######################################################
networks:
  brdo0:
    external: true

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 31, 2023, 1:43pm UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/5 "2023-05-31T13:43:43Z")

</div>

> [@Lokutus25](#):
>
> `./filebeat/config/filebeat.yml`

You need to share this file as well and your Logstash configuration pipeline, with the `beats` input.

> [@Lokutus25](#):
>
> ```auto
> environment:
> - strict.perms=false
> - output.elasticsearch.hosts=["sq-docker-elasticsearch:9200"]
> 
> ```

This does not make much sense, you cannot have an elasticsearch output in filebeat if you have a logstash output, not sure why you have this setting.

---

<div class="post-metadata">

**Author:** ![Lokutus25](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Post date:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/6 "2023-06-05T08:01:08Z")

</div>

That's the filebeat.yml:

```auto
#filebeat.registry_file: /usr/share/filebeat/data/registry
filebeat.config.inputs:
#prospectors dynamically loaded from the sub-directory
  path: ${path.config}/prospectors.d/*.yml
  reload.enabled: false
filebeat.modules:
#All data to indexed to Elasticsearch
output.logstash:
  hosts: ["192.168.13.4:5044"]

```

I've copied the environment from the old Docker Server. Now I see that this does not make sense.

So I have to delete the line with the elasticsearch output, right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2023, 10:01am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040/7 "2023-07-03T10:01:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
