# Using certificates on logstash output plugin

**URL:** <https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967>\
**Category:** Logstash\
**Created:** [May 22, 2020, 9:27pm UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967 "2020-05-22T21:27:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![francisaugusto](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@francisaugusto](https://discuss.elastic.co/u/francisaugusto)\
**Post date:** [May 22, 2020, 9:27pm UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/1 "2020-05-22T21:27:49Z")

</div>

Hi,

Is it possible to use certificates to connect logstash to elasticsearch, the same way it is possible with the beat input plugin?

Best,

Francis

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [May 22, 2020, 9:57pm UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/2 "2020-05-22T21:57:24Z")

</div>

@francisaugusto using the https scheme for your hosts or specifying [ssl](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ssl) in your output will secure the communication between Elasticsearch and Logstash.

For PKI authentication, see [this](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-pki) section of the docs.

---

<div class="post-metadata">

**Author:** ![francisaugusto](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@francisaugusto](https://discuss.elastic.co/u/francisaugusto)\
**Post date:** [May 23, 2020, 7:27am UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/3 "2020-05-23T07:27:48Z")

</div>

Thanks a lot @Coinology! So the certificates cannot be referenced directly, right? You cannot simply point at them like when using ssl options for the input plugin, right?  
I never used a keystore or trust store, so I dunno where to start.  
I want to secure the communication, but also to authenticate. Maybe using user/password will do it.

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 24, 2020, 5:07am UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/4 "2020-05-24T05:07:09Z")

</div>

you can. if your ES uses TLS and you are using custom CA cert, you can reference the CA file in elasticsearch output plugin using cacert directives. it’s in the same link as @Coinology provided

---

<div class="post-metadata">

**Author:** ![francisaugusto](https://avatars.discourse-cdn.com/v4/letter/f/c37758/32.png) [@francisaugusto](https://discuss.elastic.co/u/francisaugusto)\
**Post date:** [May 24, 2020, 11:47am UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/5 "2020-05-24T11:47:51Z")

</div>

Great! Thanks @ptamba! Will check that out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2020, 11:47am UTC](https://discuss.elastic.co/t/using-certificates-on-logstash-output-plugin/233967/6 "2020-06-21T11:47:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
