# Winlogbeat issue with ca\_trusted\_fingerprint keystore

**URL:** <https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [March 1, 2022, 8:37pm UTC](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561 "2022-03-01T20:37:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bcantrell](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Post date:** [March 1, 2022, 8:37pm UTC](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561/1 "2022-03-01T20:37:47Z")

</div>

Hello,

I am new to setting up ELK stack, currently working in a lab environment to understand setup before moving to production. Everything is on 8.0.

The problem I am having with Winlogbeat is that when I have a keystore variable in place for the CA fingerprint, the service will not start and an error is thrown in the logs. If I change it to be plaintext of the fingerprint, it works fine. Oddly enough, if I run winlogbeat setup -e with the variable in place, it connects and works fine. The winlogbeat service is running as the same user I am using to set the keystores. I am also having similar problems with keystores in filebeat, but I want to focus on this for now and will circle back.

Any thoughts on what I am doing wrong?

My config file:

```auto
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["https://ServerName:9200"]

  # Protocol - either `http` (default) or `https`.
  protocol: "https"

  # Authentication credentials - either API key or username/password.
  username: "winlogbeat_user"
  password: "${ES_PWD}"
  ssl.enabled: true
  ssl.ca_trusted_fingerprint: "${CA_FP}"

```

Winlogbeat error:

> {"log.level":"error","@timestamp":"2022-03-01T15:21:50.452-0500","log.origin":{"file.name":"instance/beat.go","file.line":1025},"message":"Exiting: error initializing publisher: missing field accessing 'output.elasticsearch.ssl.ca\_trusted\_fingerprint' (source:'C:\Program Files\Winlogbeat\winlogbeat.yml') accessing 'output.elasticsearch' (source:'C:\Program Files\Winlogbeat\winlogbeat.yml')","service.name":"winlogbeat","ecs.version":"1.6.0"}

Winlogbeat setup -e working:

> {"log.level":"info","@timestamp":"2022-03-01T15:23:22.545-0500","log.logger":"tls","log.origin":{"file.name":"tlscommon/  
> tls\_config.go","file.line":163},"message":"'ca\_trusted\_fingerprint' set, looking for matching fingerprints","service.nam  
> e":"winlogbeat","ecs.version":"1.6.0"}  
> {"log.level":"info","@timestamp":"2022-03-01T15:23:22.553-0500","log.logger":"tls","log.origin":{"file.name":"tlscommon/  
> tls\_config.go","file.line":174},"message":"CA certificate matching 'ca\_trusted\_fingerprint' found, adding it to 'certifi  
> cate\_authorities'","service.name":"winlogbeat","ecs.version":"1.6.0"}

---

<div class="post-metadata">

**Author:** ![bcantrell](https://avatars.discourse-cdn.com/v4/letter/b/ed655f/32.png) [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Post date:** [March 3, 2022, 9:39pm UTC](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561/2 "2022-03-03T21:39:10Z")

</div>

Is there anyone with any ideas? I am really lost at this point. Have searched around quite a bit and haven't found this particular message anywhere.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2022, 11:39pm UTC](https://discuss.elastic.co/t/winlogbeat-issue-with-ca-trusted-fingerprint-keystore/298561/3 "2022-03-31T23:39:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
