# TLS 1.2 enable on elasticsearch output plugin

**URL:** <https://discuss.elastic.co/t/tls-1-2-enable-on-elasticsearch-output-plugin/246553>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [August 27, 2020, 6:12am UTC](https://discuss.elastic.co/t/tls-1-2-enable-on-elasticsearch-output-plugin/246553 "2020-08-27T06:12:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wasantha\_Herath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wasantha_herath/32/74084_2.png) [@Wasantha\_Herath](https://discuss.elastic.co/u/Wasantha_Herath)\
**Post date:** [August 27, 2020, 6:12am UTC](https://discuss.elastic.co/t/tls-1-2-enable-on-elasticsearch-output-plugin/246553/1 "2020-08-27T06:12:44Z")

</div>

Hi Team,

Currently we are using a ES cloud cluster and separate logstash (v6.3) instance which communicate with ES cloud cluster using HTTPS host name.

Like below

```auto
    output {
    elasticsearch {
    hosts => ["https://f2e7ce03eae34b35806XXXXXXXXXX.us-xxxx.gcp.cloud.es.io:9243/"]
    user => "elastic"
    password => "xxxxxxxxxxxxxxx"
    index => "transactions-d-%{+YYYY.MM.dd}"
    }
    }

```

https://www.elastic.co/blog/support-ending-for-tls-1-0-tls-1-1-http-traffic-to-elasticsearch-service

According to above blog, it suggests us to use HTTP over TLS (HTTPS) with support for TLS 1.2.

What sort of change are we expecting here ? or else is it already secured with TLS 1.2 since we already communicating via HTTPS url ?

Appreciate your prompt response

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 27, 2020, 3:14pm UTC](https://discuss.elastic.co/t/tls-1-2-enable-on-elasticsearch-output-plugin/246553/2 "2020-08-27T15:14:56Z")

</div>

If you are using an https URL then the connection is encrypted. Given that the blog says the change was implemented several months ago then if logstash is able to connect I think you are safe to assume that you are using TLS 1.2.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2020, 3:15pm UTC](https://discuss.elastic.co/t/tls-1-2-enable-on-elasticsearch-output-plugin/246553/3 "2020-09-24T15:15:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
