# TLS Logstash

**URL:** <https://discuss.elastic.co/t/tls-logstash/318865>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [November 14, 2022, 11:18am UTC](https://discuss.elastic.co/t/tls-logstash/318865 "2022-11-14T11:18:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![diegz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@diegz](https://discuss.elastic.co/u/diegz)\
**Post date:** [November 14, 2022, 11:18am UTC](https://discuss.elastic.co/t/tls-logstash/318865/1 "2022-11-14T11:18:14Z")

</div>

Hello,

I have an ELK stack secured in TLS.  
Exchanges between nodes and with kibana are secure.  
I have set up logstash to collect logs from the different equipments via the syslog protocol.  
I have questions about the certificate part to secure the exchanges in output logstash to elasticsearch  
but also if possible from the syslog equipment to logstash.

Here is my current configuration:

```auto
input {
  tcp {
    port => 5000
    type => syslog
  }
  udp {
    port => 5000
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}])? %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://192.168.1.30:9200", "https://192.168.1.40:9200", "https://192.168.1.50:9200"]
    ssl => true
    ssl_certificate_verification => true
    keystore => /etc/logstash/certs/logstash1.p12
    truststore => /etc/logstash/certs/logstash1.p12
    api_key => "66GKX9GYT36ziqNjXv3vvw"

}

```

In output, which certificate(s) should be specified?  
In keystore, the certificate of logstash or the one of elasticsearch ? of all nodes ?

I would also like to leave out the keystore\_password and trustore\_password parameters.  
Is the solution as follows?

```auto
set +o history
export LOGSTASH_KEYSTORE_PASS=mypassword
set -o history
sudo -E /usr/share/logstash/bin/logstash-keystore --path.settings /etc/logstash create

```

Same for the trustore?

Thanks a lot for your help,

---

<div class="post-metadata">

**Author:** ![diegz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@diegz](https://discuss.elastic.co/u/diegz)\
**Post date:** [November 17, 2022, 2:50pm UTC](https://discuss.elastic.co/t/tls-logstash/318865/2 "2022-11-17T14:50:45Z")

</div>

to define the passwords of the keystore and of the variables indicated in the output

```auto
set +o history
export LOGSTASH_KEYSTORE_PASS=password
set -o history
bin/logstash-keystore create --path.settings /etc/logstash
chown logstash:root /etc/logstash/logstash.keystore ; chmod 0600 /etc/logstash/logstash.keystore

```

```auto
output {
  elasticsearch {
    hosts => ["https://192.168.1.30:9200", "https://192.168.1.40:9200", "https://192.168.1.50:9200"]
    ssl => true
    ssl_certificate_verification => true
    keystore => /etc/logstash/certs/logstash1.p12
    keystore_password => "${KEY_PWD}"
    truststore => /etc/logstash/certs/logstash1.p12
    truststore_password => "${TRUST_PWD}"
    api_key => "66GKX9GYT36ziqNjXv3vvw"

}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2022, 2:51pm UTC](https://discuss.elastic.co/t/tls-logstash/318865/3 "2022-12-15T14:51:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
