# Authentication using apikey failed - unable to find apikey with id

**URL:** <https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217>\
**Category:** Elasticsearch\
**Created:** [June 29, 2023, 2:33pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217 "2023-06-29T14:33:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![p\_vimal](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Post date:** [June 29, 2023, 2:33pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217/1 "2023-06-29T14:33:00Z")

</div>

Hello,

We are running Elasticsearch 7.17.8 and have many error entries like this on in the elastic logs:  
[WARN][o.e.x.s.a.ApiKeyAuthenticator] [NODENAMEE] Authentication using apikey failed - unable to find apikey with id TH6xaoMBpxRmcd35O5Wv

Probable root cause : Our security index got deleted somehow. So we recreated the API keys from scratch but still we are getting this in our logs.

When we try to invalidate/delete the API keys,we couldnt find it in the index.  
GET /\_security/api\_key --\> doesnt give the API keys which shows in logs.

We need help in disable this warnings from logs. Can you guide us how to do it?  
Regards,  
Vimal

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 29, 2023, 6:05pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217/2 "2023-06-29T18:05:28Z")

</div>

> [@p\_vimal](#):
>
> We are running Elasticsearch 7.17.8 and have many error entries like this on in the elastic logs:  
> [WARN][o.e.x.s.a.ApiKeyAuthenticator] [NODENAMEE] Authentication using apikey failed - unable to find apikey with id TH6xaoMBpxRmcd35O5Wv

That looks to me like a client is trying to authenticate using an old / invalid key... did you check that?

---

<div class="post-metadata">

**Author:** ![p\_vimal](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Post date:** [June 29, 2023, 9:52pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217/3 "2023-06-29T21:52:43Z")

</div>

We dont have any external client accessing our cluster using API keys. Do we have anyway we can find the source IP of this request?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 29, 2023, 9:58pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217/4 "2023-06-29T21:58:01Z")

</div>

see here, not easy

> [@Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/336330/6):
>
> Hi @aaronlbk Something does not make sense you have an empty elasticsearch.yml yet you have authentication enabled ... that is not normal / highly unusual (basically not sure how that is even possible) Are you sure that is the elasticsearch.yml that is being used? How did you install elasticsearch? is this an upgrade from 7.x? Normally you would turn on Audit logging but that requires a License. Something is definitely attempting to authenticate... You might be able to see which process…

Also Found This

> [@\[Creating new rule \]: ERROR Authentication using apikey failed - api key has been invalidated](https://discuss.elastic.co/t/creating-new-rule-error-authentication-using-apikey-failed-api-key-has-been-invalidated/261407/2):
>
> In the current 7.10.x series when a long running rule is still running and you go to update the rule while it is currently running, the API key which represents the rule is invalidated immediately which can result in that rule execution immediately showing an error within that current rule run. The next rule run interval should clear out the error and you should see it run correctly. If on the second rule run it does not clear out and you are consistently seeing this error appear again and agai…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2023, 9:58pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217/5 "2023-07-27T21:58:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
