# Logstash to Logstash configuration

**URL:** <https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038>\
**Category:** OpenSearch\
**Tags:** feature-request\
**Created:** [December 12, 2023, 5:45am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038 "2023-12-12T05:45:55Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![raj1209](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/raj1209/32/6115_2.png) [@raj1209](https://forum.opensearch.org/u/raj1209)\
**Post date:** [December 12, 2023, 5:45am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/1 "2023-12-12T05:45:55Z")

</div>

Hi Guys,

Can you please suggest a best way to configure logstash to logstash communication with SSL/TLS encryption.  
There are some of the articles in logstash input and output plugin  
lumberjack plugin but it did not work for me  
some of them are deprecated.

Please advice me on this  
Thank you

---

<div class="post-metadata">

**Author:** ![Gsmitt](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/gsmitt/32/1718_2.png) [@Gsmitt](https://forum.opensearch.org/u/Gsmitt)\
**Post date:** [December 12, 2023, 5:48am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/2 "2023-12-12T05:48:47Z")

</div>

Hey @raj1209

Simple configuration for Logstash using Beats input

```auto
# Sample Logstash configuration for creating a simple
# Beats -> Logstash -> Elasticsearch pipeline.

input {
  beats {
    port => 5044
  }
}

output {
  opensearch {
    hosts => ["https://opensearch.domain.com:9200"]
    auth_type => {
              type => 'basic'
              user => 'admin'
              password => 'changeit'
            }
    ecs_compatibility => disabled
    ssl => true   
    cacert => "/opt/logstash-8.6.1/root-ca.pem"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"    
    }
}

```

Hope that helps

---

<div class="post-metadata">

**Author:** ![raj1209](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/raj1209/32/6115_2.png) [@raj1209](https://forum.opensearch.org/u/raj1209)\
**Post date:** [December 12, 2023, 5:54am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/3 "2023-12-12T05:54:18Z")

</div>

Hi @Gsmitt Thanks for the lightning response , appreciated  
In my scenario, It requires the logstash to logstash communication and not filebeat to logstash

Recently we had a merger between two companies and they are using logstash as well and we are trying to receive logs from their logstash ( A ) to our logstash ( B ) and have a secure communication between these two and send this logs to Opensearch

---

<div class="post-metadata">

**Author:** ![Gsmitt](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/gsmitt/32/1718_2.png) [@Gsmitt](https://forum.opensearch.org/u/Gsmitt)\
**Post date:** [December 12, 2023, 6:02am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/4 "2023-12-12T06:02:00Z")

</div>

Hey

> [@raj1209](#):
>
> logstash ( A ) to our logstash ( B ) and have a secure

I havent seen that done yet. We use Logstash send directly to Opensearch. I guess you could

Here is another example of an input you could use.

```auto
input {
  tcp {
    host => "0.0.0.0"
    mode => "server"
    port => 5144
    ssl_enable => true
    ssl_cert => "/etc/ssl/logstash.crt"
    ssl_key => "/etc/ssl/ogstash.key"
    ssl_cacert => "/etc/ssl/certs/my_ca_cert.pem"
    ssl_verify => false
    type => "syslog"
  }
}

```

Sorry Havent sent logs from Logstash to logstash.

---

<div class="post-metadata">

**Author:** ![jasonrojas](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/jasonrojas/32/4902_2.png) [@jasonrojas](https://forum.opensearch.org/u/jasonrojas)\
**Post date:** [December 12, 2023, 4:25pm UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/5 "2023-12-12T16:25:49Z")

</div>

One of the routes I would suggest investigating is shipping logs to an intermediary buffer like redis, kafka etc, then have the other logstash pull from there.  
This avoids any issues if the last logstash in your chain is offline for whatever reason and should help prevent the shipping logstash from OOM’ing.

ie:

logstash\_shipper → Buffer(redis etc) → Logstash\_receiver → wherever.

---

<div class="post-metadata">

**Author:** ![raj1209](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/raj1209/32/6115_2.png) [@raj1209](https://forum.opensearch.org/u/raj1209)\
**Post date:** [December 15, 2023, 10:19am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/6 "2023-12-15T10:19:09Z")

</div>

Thank you for replying @jasonrojas  
Suppose If I use **tcp** output plugin in **logstash A** and tcp input plugin in **logstash B** does it have any impact of data loss if one of the logstash chain goes down ?

---

<div class="post-metadata">

**Author:** ![jasonrojas](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/jasonrojas/32/4902_2.png) [@jasonrojas](https://forum.opensearch.org/u/jasonrojas)\
**Post date:** [December 18, 2023, 3:00pm UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/7 "2023-12-18T15:00:42Z")

</div>

You would have to test that to be certain. I think logstash will buffer to a point however those internal buffers will be limited to heap size and system memory etc.

---

<div class="post-metadata">

**Author:** ![raj1209](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/raj1209/32/6115_2.png) [@raj1209](https://forum.opensearch.org/u/raj1209)\
**Post date:** [December 19, 2023, 9:57am UTC](https://forum.opensearch.org/t/logstash-to-logstash-configuration/17038/8 "2023-12-19T09:57:55Z")

</div>

Thank you for the suggestion
