# Authentication failed for null

**URL:** https://discuss.elastic.co/t/authentication-failed-for-null/314389
**Category:** Kibana
**Tags:** elastic-stack-alerting
**Created:** [September 14, 2022, 8:59am UTC](https://discuss.elastic.co/t/authentication-failed-for-null/314389 "2022-09-14T08:59:10Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![lcsb-sysadmins](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)
#### Post date: [September 14, 2022, 8:59am UTC](https://discuss.elastic.co/t/authentication-failed-for-null/314389/1 "2022-09-14T08:59:10Z")

</div>

Hello everyone!  
I'm setting up a new elastic cluster and I have an issue with with alerts in Kibana.  
I have the following error for each alert in `jarvis-cluster.log`

`[2022-09-14T10:43:56,623][WARN][c.f.s.a.b.RequestAuthenticationProcessor] [hot-01-node-01] Authentication failed for null from [request=/.kibana_7.17.5/_doc/space:default, directIpAddress=10.240.16.236, originatingIpAddress=x.x.x.x, clientCertSubject=null]`

related to this error in `kibana.log`

`{"type":"log","@timestamp":"2022-09-14T10:40:47+02:00","tags":["error","plugins","alerting"],"pid":2037229,"message":"Executing Alert default:monitoring_alert_cpu_usage:9fbe4fc1-3360-11ed-8c66-ab2baf834e7e has resulted in Error: Unauthorized"}`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1f10862303517c928fbc62606048901dd6c6e998.png)

In the cluster I already setup searchguard, logstash and openID. For monitoring I use metricbeat.  
Self monitoring seems to be working fine, but not the alerts.

Any idea what should I do ?  
Please let me know if you need more information.  
Best regards,  
Karim

---

<div class="post-metadata">

### Author: ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)
#### Post date: [September 26, 2022, 6:48pm UTC](https://discuss.elastic.co/t/authentication-failed-for-null/314389/2 "2022-09-26T18:48:53Z")

</div>

could you share rule definition for this rule please?

What version of the stack is this?

Lastly - has this always happened, or did it start suddenly? everything should work out of the box with the `elastic` user and `superuser` role, so would be worth it to see if we can get some additional details from the Kibana logs here.  
Additionally, can you speak more to your deployment configuration -- are you running multiple kibana instances? Is this all within the default space? Does this happen with all Rule Types within Stack Management or only Security Rules? Would be interested to see if you could create non-security rules without error.

cc @pmuellr for additional insights

Thanks  
Rashmi

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 24, 2022, 6:49pm UTC](https://discuss.elastic.co/t/authentication-failed-for-null/314389/3 "2022-10-24T18:49:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
