# Blocking beats from hosts using Xpack Security IP filtering feature

**URL:** <https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 18, 2016, 8:27am UTC](https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509 "2016-11-18T08:27:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rs\_ela](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@rs\_ela](https://discuss.elastic.co/u/rs_ela)\
**Post date:** [November 18, 2016, 8:27am UTC](https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509/1 "2016-11-18T08:27:01Z")

</div>

I'm trying to filter ip addresses using Xpack Security (aka Shield). As far as I understand the documentation ([https://www.elastic.co/guide/en/x-pack/current/ip-filtering.html](https://www.elastic.co/guide/en/x-pack/current/ip-filtering.html)), it should block beats from given hosts. However, after editing configuration and restarting Elasticsearch, nothing happens - beat is allowed through anyway.

In my case the ELK is v5.0 and it runs on Debian Jessie.

Here's the config file:

```
# ---------------------------------- Various -----------------------------------
#
# Disable starting multiple nodes on a single system:
#
#node.max_local_storage_nodes: 1
#
# Require explicit names when deleting indices:
#
#action.destructive_requires_name: true
#
#
#-------------xpack security------------
#
#
xpack.security.transport.filter.allow: "192.168.10.11"
xpack.security.transport.filter.deny: _all
#

```

What am I doing wrong? I believe it's something obvious, since the config is rather simple...

Many thanks for your suggestions!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 18, 2016, 9:17am UTC](https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509/2 "2016-11-18T09:17:25Z")

</div>

Beats use the HTTP(S) protocol, so you need to configure [HTTP filtering](https://www.elastic.co/guide/en/x-pack/current/ip-filtering.html#_http_filtering).

---

<div class="post-metadata">

**Author:** ![rs\_ela](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@rs\_ela](https://discuss.elastic.co/u/rs_ela)\
**Post date:** [November 18, 2016, 10:23am UTC](https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509/3 "2016-11-18T10:23:07Z")

</div>

Thanks for the suggestion.

New config in /etc/elasticsearch/elasticsearch.yml:

```
#-------------xpack security------------
#
xpack.security.http.filter.deny: _all
#

```

Still all beats are allowed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2016, 10:23am UTC](https://discuss.elastic.co/t/blocking-beats-from-hosts-using-xpack-security-ip-filtering-feature/66509/4 "2016-12-16T10:23:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
