# Authentication using apikey failed

**URL:** <https://discuss.elastic.co/t/authentication-using-apikey-failed/333244>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 12, 2023, 2:23am UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244 "2023-05-12T02:23:26Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [May 23, 2023, 2:51am UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244/5 "2023-05-23T02:51:22Z")

</div>

> [@dmrlixos](#):
>
> `I'm using a free and the audit logs is not allowed.`

In that case, you can try HttpTracer which will report the remote address of each request.

```auto
PUT _cluster/settings
{
   "persistent" : {
      "logger.org.elasticsearch.http.HttpTracer" : "TRACE"
   }
}

```

The logs will get quite verbose. You should see something like the follows for the failed API key authentication

> received request from [Netty4HttpChannel{localAddress=/[0:0:0:0:0:0:0:1]:9200, remoteAddress=/[0:0:0:0:0:0:0:1]:53497}]org.elasticsearch.http.HttpHeadersValidationException: org.elasticsearch.ElasticsearchSecurityException: unable to authenticate with provided credentials and anonymous access is not allowed for this request

Hopefully the remote address will give you enough information to identify the agent that is using the invalid API key. Once you are done, you can remove HTTP tracer logging with

```auto
PUT _cluster/settings
{
   "persistent" : {
      "logger.org.elasticsearch.http.HttpTracer" : null
   }
}

```

---

_[View the full topic](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244)._
