Logstash HTTP Input and Monitoring API binding without authentication boundary
0 reputation · 12 Jan 2026, 14:47 UTC
Goal is to avoid accidental public access to Logstash HTTP Input and the monitoring API while keeping local development usable.
The HTTP Input plugin binds to all interfaces when host is unspecified and does not provide built-in authentication. The monitoring API for metrics and pipeline management is enabled by default and is unauthenticated in standard OSS builds. Reachability is determined by the process bind address and network placement, with no built-in per-endpoint authorization for either the HTTP Input or the monitoring API.
Default settings prioritize operational convenience over explicit permission constraints, leaving the permission boundary to external controls. Behavior varies by Logstash version and distribution, and changing bind settings affects monitoring, pipeline reload and HTTP Input reachability together.
Is the HTTP Input plugin documented to require external network controls for authentication when host is unspecified? Is api.bind_address independent of the HTTP Input plugin host setting for access control? What is the documented permission boundary for the monitoring API in OSS builds?