# Apm-server failed connect to ElasticSearch with Xpack enabled (401 Unauthorized )

**URL:** <https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929>\
**Category:** APM\
**Created:** [June 27, 2019, 8:51pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929 "2019-06-27T20:51:14Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![blump](https://avatars.discourse-cdn.com/v4/letter/b/df788c/32.png) [@blump](https://discuss.elastic.co/u/blump)\
**Post date:** [June 27, 2019, 8:51pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/1 "2019-06-27T20:51:14Z")

</div>

Hello,

ELK\_VERSION = 7.2.0

On my docker environment, I can not connect apm-server with elastic Search when xpack (basic mode) is enabled. When Xpack is disabled, it's work

> ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://elasticsearch:9200](http://elasticsearch:9200))): 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}

While Kibana connects well with Elastic Search with Xpack (basic mode) enabled.

_config/elasticsearch.yml_

```yml
...
xpack.license.self_generated.type: basic
xpack.security.enabled: true

```

_config/kibana.yml_

```yml
...
xpack.security.enabled: true
elasticsearch.username: elastic
elasticsearch.password: changeme

```

_config/apm-server.yml_

```yml
apm-server:
  host: localhost:8200

output.elasticsearch:
    enabled: true
    protocol: "http"
    hosts: ["elasticsearch:9200"]
    ssl.enabled: false
    username: elastic
    password: changeme

```

How can I connect apm-server to elastic Search with Basic Authentication?

Thx !

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [June 28, 2019, 1:29am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/2 "2019-06-28T01:29:02Z")

</div>

Hey @blump, thanks for joining the forum. Are you able to log into kibana with those credentials? If so, you might consider enabling [security audting](https://www.elastic.co/guide/en/elasticsearch/reference/current/auditing-settings.html#general-audit-settings) in elasticsearch and expect the elasticsearch logs to point you in the right direction.

I don't see anything obviously wrong with the apm-server.yml provided.

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Zimnitskiy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy_zimnitskiy/32/49669_2.png) [@Evgeniy\_Zimnitskiy](https://discuss.elastic.co/u/Evgeniy_Zimnitskiy)\
**Post date:** [July 9, 2019, 6:26am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/3 "2019-07-09T06:26:05Z")

</div>

Hi Gil, I have the same case. Can there be a problem in the type of license?

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Zimnitskiy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy_zimnitskiy/32/49669_2.png) [@Evgeniy\_Zimnitskiy](https://discuss.elastic.co/u/Evgeniy_Zimnitskiy)\
**Post date:** [July 9, 2019, 7:21am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/4 "2019-07-09T07:21:25Z")

</div>

Checked, the problem is not in the license.

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Zimnitskiy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy_zimnitskiy/32/49669_2.png) [@Evgeniy\_Zimnitskiy](https://discuss.elastic.co/u/Evgeniy_Zimnitskiy)\
**Post date:** [July 9, 2019, 9:46am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/5 "2019-07-09T09:46:51Z")

</div>

Solved

---

<div class="post-metadata">

**Author:** ![alza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alza/32/50143_2.png) [@alza](https://discuss.elastic.co/u/alza)\
**Post date:** [July 15, 2019, 10:46am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/6 "2019-07-15T10:46:42Z")

</div>

I have the same issue!  
Would you mind let us know how you solved it?

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Zimnitskiy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy_zimnitskiy/32/49669_2.png) [@Evgeniy\_Zimnitskiy](https://discuss.elastic.co/u/Evgeniy_Zimnitskiy)\
**Post date:** [July 15, 2019, 11:43am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/7 "2019-07-15T11:43:49Z")

</div>

Can you provide your docker-compose for apm-server?

---

<div class="post-metadata">

**Author:** ![alza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alza/32/50143_2.png) [@alza](https://discuss.elastic.co/u/alza)\
**Post date:** [July 15, 2019, 12:40pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/8 "2019-07-15T12:40:34Z")

</div>

Actually I have this similar issue in Metricbeats with this docker-compose file:

```
version: "2.1"
services:
 metricbeat:
    container_name: metricbeat
    hostname: metricbeat
    user: root
    image: docker.elastic.co/beats/metricbeat:${ELASTIC_VERSION}
    volumes:
      - ./config/beats/metricbeat/metricbeat.yml:/usr/share/metricbeat/metricbeat.yml
      - ./config/beats/metricbeat/modules.d/:/usr/share/metricbeat/modules.d/
      - /proc:/hostfs/proc:ro
      - /sys/fs/cgroup:/hostfs/sys/fs/cgroup:ro
      - /var/run/docker.sock:/var/run/docker.sock
      - /:/hostfs:ro
    command: metricbeat -e -system.hostfs=/hostfs -E output.elasticsearch.username=elastic -E output.elasticsearch.password=xxxx -strict.perms=false
    restart: on-failure
```

---

<div class="post-metadata">

**Author:** ![Evgeniy\_Zimnitskiy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evgeniy_zimnitskiy/32/49669_2.png) [@Evgeniy\_Zimnitskiy](https://discuss.elastic.co/u/Evgeniy_Zimnitskiy)\
**Post date:** [July 15, 2019, 1:55pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/9 "2019-07-15T13:55:46Z")

</div>

My problem was exactly the same as Mr. Blumb. The solution was simple, the configuration was mounted the wrong way. I do not use metricbeat. But I suggest you not to use the command to pass arguments, but to do it in the config.

---

<div class="post-metadata">

**Author:** ![alza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alza/32/50143_2.png) [@alza](https://discuss.elastic.co/u/alza)\
**Post date:** [July 16, 2019, 6:57am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/10 "2019-07-16T06:57:15Z")

</div>

Thanks, I have the same issue!  
I removed any parameters from docker-compose `command` and just used config to pass arguments (elastic user and pass).

---

<div class="post-metadata">

**Author:** ![blump](https://avatars.discourse-cdn.com/v4/letter/b/df788c/32.png) [@blump](https://discuss.elastic.co/u/blump)\
**Post date:** [July 16, 2019, 12:24pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/11 "2019-07-16T12:24:22Z")

</div>

I did not have time to look again at this problem. I do not pass my arguments by a command. I could look again at the problem in September.

Good luck to you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 8:24am UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929/12 "2019-08-06T08:24:27Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
