TLS with anonymous rsyslog clients

I want anonymous rsyslog clients using the Logstash server’s x509/fingerprint to authenticate the Logstash server for a secure TLS connection; however, I don’t want the Logstash server to authenticate all of the clients that are pushing data. In short, I want the numerous clients to be anonymous and the data being sent be secure. I can x509/fingerprint an rsyslog client to work with an rsyslog server, but I cannot get the same client to work with logstash.

