Noticed in logstash when looking at other monitoring that fails:
Within the last 2 days there were about 45k errors when monitoring attemps to check centrallog1001 but gets a TLS cert that is only valid for centralllog1002.
x509: certificate is valid for centrallog1002.eqiad.wmnet, not centrallog1001.eqiad.wmnet
So either the cert should have all the names or monitoring should stop checking the old host, I suppose.
