# Logstash SSL TCP input

**URL:** <https://forum.opensearch.org/t/logstash-ssl-tcp-input/11090>\
**Category:** OpenSearch\
**Created:** [September 29, 2022, 8:37am UTC](https://forum.opensearch.org/t/logstash-ssl-tcp-input/11090 "2022-09-29T08:37:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vnovotny98](https://avatars.discourse-cdn.com/v4/letter/v/53a042/32.png) [@vnovotny98](https://forum.opensearch.org/u/vnovotny98)\
**Post date:** [September 29, 2022, 8:37am UTC](https://forum.opensearch.org/t/logstash-ssl-tcp-input/11090/1 "2022-09-29T08:37:30Z")

</div>

Hello, first, I am sorry. I don’t know in which category should I post this.

I have logback in my application that sends logs to logstash, I use this logstash in docker: [Docker Hub](https://hub.docker.com/layers/opensearchproject/logstash-oss-with-opensearch-output-plugin/7.16.3/images/sha256-828d675d37a272e375efa4208622d6c2d66ba5b9bed28a4c36d8c85ede3ffbd3?context=explore)

i want to find something like this: [Tcp input plugin | Logstash Reference [8.4] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-tcp.html#plugins-inputs-tcp-ssl_supported_protocols)  
because it communicates with TLS 1.1and I would like to set it only to TLS 1.3 or do you have any other ideas? thanks 😉

---

<div class="post-metadata">

**Author:** ![vnovotny98](https://avatars.discourse-cdn.com/v4/letter/v/53a042/32.png) [@vnovotny98](https://forum.opensearch.org/u/vnovotny98)\
**Post date:** [September 29, 2022, 8:55am UTC](https://forum.opensearch.org/t/logstash-ssl-tcp-input/11090/2 "2022-09-29T08:55:00Z")

</div>

I tried that.  
[ERROR][logstash.inputs.tcp] Unknown setting ‘ssl\_supported\_protocols’ for tcp

I think it is added in Logstash 8.2

> **[Logstash 8.2.0 Release Notes | Logstash Reference \[8.4\] | Elastic](https://www.elastic.co/guide/en/logstash/current/logstash-8-2-0.html)**

> <https://github.com/elastic/logstash/issues/10494>
>
> TLS v1.3 is available since Java \`8u262-b10\` (AdoptOpenJDK) or\` 8u261-b12\` in th…e Oracle build.
> https://java.com/en/jre-jdk-cryptoroadmap.html
> 
> Logstash 7.15/16 ships with Java 11 and 8.0 will even drop support for Java 8 -\> TLS v1.3 could be assumed available.
> 
> This issue intends to track all the work towards being confident that Logstash supports TLS v1.3.
> 
> \--- 
> 
> \### Core
> 
> \- \[\] Secured LS API endpoint should support TLSv1.3
> \* atm this is \[\*blocked\*\](https://github.com/elastic/logstash/issues/13406) by Puma providing 1.3 support under JRuby
> 
> \- \[x\] using the vendor-ed JDK LS should default to enabling TLSv1.2 and TLSv1.3 in the Java SSL engine
> 
> \---
> 
> \### Dependencies
> 
> \- \[x\] confirm Manticore (Apache HttpClient 4.x) works as expected against TLSv1.3
> \- \[x\] JRuby-OpenSSL lacks support for TLSv1.3 (initial support available in 0.12.1)
> scope unknown -\> need to review Ruby OpenSSL + C-OpenSSL changes
> \- \[x\] extra JOSSL support to be able to select Java cipher names for an SSL context
> to allow easy \`cipher\_suites =\> ...\` support for low level plugins such as the tcp input (requested feature)
> \- \[x\] Puma does not support TLSv1.3 using it's MiniSSL JRuby implementation
> scope should be relatively simple
> 
> \---
> 
> \### Plugins
> 
> \- \[x\] ES output - https://github.com/logstash-plugins/logstash-output-elasticsearch/pull/1055 - should work out-of-the box against ES when secured or even restricted to 1.3 only
> \* \[x\] integration tests against ES using \`xpack.security.http.ssl.supported\_protocols: TLSv1.3\`
> \* \[x\] (optional) support for \`ssl\_supported\_protocols\` option (default \`=\> \['TLSv1.2', 'TLSv1.3'\]\`)
> would be nice if the naming prefix would align with planned TLS configuration unification
> 
> \- \[x\] \*\*ES input\*\* - https://github.com/logstash-plugins/logstash-input-elasticsearch/pull/162 - should work out-of-the box against ES when secured or even restricted to 1.3 only
> \* \[x\] integration tests against ES using \`xpack.security.http.ssl.supported\_protocols: TLSv1.3\`
> should be working -\> ~~testing relies on using the Elasticsearch transport Ruby http adapter (need TLSv1.3 in JOpenSSL)~~
> \* \[\] ~~(optional) enabled protocol version configuration~~ does not make much sense given only \`ca\_file\` TLS configuration is supported atm
>   
> \- \[x\] \*\*ES filter\*\* - should work out-of-the box against ES when secured or even restricted to 1.3 only
> https://github.com/logstash-plugins/logstash-filter-elasticsearch/pull/154
> \* \[x\] integration tests against ES using \`xpack.security.http.ssl.supported\_protocols: TLSv1.3\`
> \* \[\] ~~(optional) enabled protocol version configuration~~ does not make much sense given only \`ca\_file\` TLS setting
> 
> \- \[x\] \*\*HTTP mixin\*\* https://github.com/logstash-plugins/logstash-mixin-http\_client/pull/40
>   
> \- \[x\] \*\*HTTP output\*\* https://github.com/logstash-plugins/logstash-output-http/pull/131
> \* \[x\] (optional) enabled protocol version configuration
>   
> \- \[x\] \*\*HTTP Poller input\*\* - Manticore based (HTTP mixin)
> https://github.com/logstash-plugins/logstash-input-http\_poller/pull/133
> \* \[x\] (optional) enabled protocol version configuration
>   
> \- \[x\] \*\*HTTP filter\*\* - Manticore based (HTTP mixin)
> https://github.com/logstash-plugins/logstash-filter-http/pull/38
> \* \[x\] (optional) enabled protocol version configuration
>   
> \- \[x\] \*\*TCP input\*\* - Netty based for server mode, JOpenSSL in client mode (blocked by JRuby-OpenSSL 1.3 support)
> https://github.com/logstash-plugins/logstash-input-tcp/pull/198
> \* \[x\] need a new configuration option e.g. \`ssl\_supported\_protocols\`
> \* \[x\] ~~plugin is lacking TLS tests~~
> \* \[x\] support for configuring TLS \`ssl\_cipher\_suites\`
> 
> \- \[x\] \*\*HTTP input\*\* https://github.com/logstash-plugins/logstash-input-http/pull/146
> \* \[x\] expose TLSv1.3 in min/max version configuration (consider deprecating the min/max options)
> \* \[x\] new configuration option (\`ssl\_supported\_protocols\`) in favor of \`tls\_min\_version\` / \`tls\_max\_version\`
> https://github.com/logstash-plugins/logstash-input-http/pull/151
> \* \[x\] plugin is lacking TLS tests (testing depends on Manticore)
> 
> \- \[x\] \*\*TCP output\*\* - using JOpenSSL (blocked by JRuby-OpenSSL TLS 1.3 support)
> https://github.com/logstash-plugins/logstash-output-tcp/pull/47
> \* \[x\] need a new configuration option
> \* \[x\] TLSv1.3 testing
> \* \[x\] (extra) ~~support for configuring TLS cipher\_suites (similar to Beats input)~~
> 
> \- \[x\] \*\*Beats input\*\* - Netty based - does only enable TLS 1.2 review plugin for TLS 1.3 
> https://github.com/logstash-plugins/logstash-input-beats/pull/447
> \* \[x\] need a new configuration option \`ssl\_supported\_protocols\` (Beats naming \`ssl.supported\_protocols\`)
> https://github.com/logstash-plugins/logstash-input-beats/pull/450
> \* \[x\] \`cipher\_suites\` setting should account for TLS 1.3 suite names
> \* \[x\] ~~consider abandoning the \`cipher\_suites\` default on recent LS (Java \>= 11) to rely on Java defaults~~
> \* \[x\] TLS 1.3 (integration) testing

Will this be included in any Logstash OSS with OpenSearch Output Plugin

> **[Opensearch 2.3.0](https://opensearch.org/downloads.html#:~:text=verification%20how%20to-,Ingest%20Tools,-OpenSearch%20is%20compatible)**
>
> OpenSearch is a community-driven, Apache 2.0-licensed open source search and analytics suite that makes it easy to ingest, search, visualize, and analyze data.

---

<div class="post-metadata">

**Author:** ![vnovotny98](https://avatars.discourse-cdn.com/v4/letter/v/53a042/32.png) [@vnovotny98](https://forum.opensearch.org/u/vnovotny98)\
**Post date:** [September 29, 2022, 9:04am UTC](https://forum.opensearch.org/t/logstash-ssl-tcp-input/11090/3 "2022-09-29T09:04:51Z")

</div>

Okay, after quick searching I must say this works. [Docker Hub](https://hub.docker.com/r/opensearchproject/logstash-oss-with-opensearch-output-plugin/tags?page=1&ordering=last_updated&name=8.4.0)  
And it can push data to Opensearch 1 as well, nice
