Logstash
🔌 Basic Connection Setup
address (required, string)
The socket address to bind and listen for incoming connections.
Can also accept systemd#{N} to use a socket passed by systemd socket activation.
Must include a port if using an IP/hostname.
Example: 0.0.0.0:9000 or systemd#0
connection_limit (optional, uint)
Maximum number of simultaneous TCP connections allowed.
Prevents overload in high-traffic scenarios.
receive_buffer_bytes (optional, uint)
Buffer size (in bytes) allocated for each incoming connection.
Affects how much data is read at once.
Example: 8192
Permit_origin (optional, [string])
List of IP networks allowed to connect.
Must be in CIDR format.
Useful for restricting access.
Example: `["192.168.0.0/16", "10.0.0.0/8"]
♻️ TCP Keepalive
keepalive.time_secs (optional, uint)
Seconds to wait before sending keepalive probes on idle connections.
Helps detect and clean up stale connections.
🔐 TLS Configuration
- tls.enabled (optional, bool)
Enables TLS encryption for connections.
Required when serving secure traffic.
- tls.ca_file (optional, string)
Path to CA certificate (PEM or DER) used for validating client certificates.
Can also be provided inline in PEM format.
- tls.crt_file (optional, string)
Path to the server’s TLS certificate.
If not a PKCS#12 archive, key_file must also be set.
- tls.key_file (optional, string)
Path to the server’s private key file (PEM, PKCS#8).
Used alongside crt_file.
- tls.key_pass (optional, string)
Passphrase for unlocking an encrypted private key file.
- tls.server_name (optional, string)
Server Name Indication (SNI) used in outgoing TLS connections.
- tls.alpn_protocols (optional, [string])
List of ALPN protocols to negotiate with the peer, in order of preference.
- tls.client_metadata_key (optional, string)
Key name used to inject client certificate metadata into events.
- tls.verify_certificate (optional, bool)
Enables certificate validation.
Validates expiration and trust chain.
⚠️ Do not disable unless absolutely necessary.
- tls.verify_hostname (optional, bool)
Enables hostname verification against the certificate.
Only for outgoing connections.
⚠️ Disabling skips validation of the remote host identity.