# Help with Basic out of box logstash config

**URL:** <https://forum.opensearch.org/t/help-with-basic-out-of-box-logstash-config/1045>\
**Category:** Open Source Elasticsearch and Kibana\
**Created:** [July 3, 2019, 4:41pm UTC](https://forum.opensearch.org/t/help-with-basic-out-of-box-logstash-config/1045 "2019-07-03T16:41:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![plarsen](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@plarsen](https://forum.opensearch.org/u/plarsen)\
**Post date:** [July 3, 2019, 4:41pm UTC](https://forum.opensearch.org/t/help-with-basic-out-of-box-logstash-config/1045/1 "2019-07-03T16:41:40Z")

</div>

I have a working cluster. But I can’t get the logstash to Open ES AWS data node connection to work.

https:|| to bypass new user link posting error. ignore that typo

My curl command test is good from logstash node to the elk data node.  
curl -XGET https:||esdatanode.elk.elk:9200/\_cat/nodes?v -u admin:xxxxxxx --insecure

Error I get in logstash log.

[2019-07-03T11:35:16,029][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>“https:||admin:xxxxxx@datanode.elk.elk:9200/”, :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=\>“Elasticsearch Unreachable: [https:||admin:xxxxxx@elkdatanode:9200/][Manticore::ClientProtocolException] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target”}

It is something to do with security and the cert. I want to use the out of the box certs for now.  
Which one do I use?

kirk.pem  
esnode.pem  
root-ca.pem  
esnode-key.pem  
kirk-key.pem

output {  
elasticsearch {  
id=\> “network-output”  
hosts =\> [“https:||datanode.elk.elk:9200”]  
index =\> “linux-%{+YYYY.MM.dd}”  
document\_type =\> “syslog”  
user =\> “admin”  
password =\> “xxxxxxx”  
ssl =\> true  
cacert =\> “/etc/elasticsearch/???.pem”  
}  
}

---

<div class="post-metadata">

**Author:** ![plarsen](https://avatars.discourse-cdn.com/v4/letter/p/eb9ed0/32.png) [@plarsen](https://forum.opensearch.org/u/plarsen)\
**Post date:** [July 8, 2019, 9:23pm UTC](https://forum.opensearch.org/t/help-with-basic-out-of-box-logstash-config/1045/2 "2019-07-08T21:23:34Z")

</div>

Got it working with these settings using root cert and added ilm setting

index =\> “linux-%{+YYYY.MM.dd}”  
document\_type =\> “syslog”  
user =\> “admin”  
password =\> “xxxxxxxxxx”  
ssl =\> true  
ssl\_certificate\_verification =\> false  
cacert =\> “/etc/elasticsearch/root-ca.pem”  
ilm\_enabled =\> false
