# Can't setup Winlogbeat or Filebeat dashboards for Kibana

**URL:** <https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962>\
**Category:** Beats\
**Tags:** filebeat, winlogbeat\
**Created:** [August 19, 2021, 12:49pm UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962 "2021-08-19T12:49:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JulienL](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@JulienL](https://discuss.elastic.co/u/JulienL)\
**Post date:** [August 19, 2021, 12:49pm UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/1 "2021-08-19T12:49:42Z")

</div>

Hello!

Firstly, sorry for any mistake in my english. I'm not a native english speaker 🙂

Hope can someone help me with this.

I have installed and configured ELK with "Basic Security plus HTTPS", I receive logs from multiples server authenticated with API keys. So it's working well here.

The only thing that I can't understand is why I can't **setup dashboard** with _Filebeat_ or _Winlogbeat_?

When I run the command `sudo filebeat setup --dashboards` on Debian or `.\winlogbeat.exe setup --dashboards` on Windows, this end with the following error:

```auto
Loading dashboards (Kibana must be running and reachable)
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://kibana:5601/api/status fails: <nil>. Response: {"statusCode":401,"error":"Unauthorized","message":"Unauthorized"}.

```

I know it's not recommended in production environnement but the **API Keys** are using the **"elastic" user** for testing purposes and to avoid permissions problems.  
I'll change this once the problem is solved.

FYI, the CA certificate is installed on the clients and the server.

Did I miss something?

Please find all the configuration files below.

Filebeat `/etc/filebeat/filebeat.yml`:

```auto
filebeat.inputs:
- type: log
  enabled: false
  paths:
    - /var/log/*.log

- type: filestream
  enabled: false
  paths:
    - /var/log/*.log

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1

setup.kibana:
  host: "https://kibana:5601"

output.elasticsearch:
  hosts: ["https://kibana:9200"]
  protocol: "https"
  api_key: 'api:key'

setup.ilm:
  enabled: auto
  rollover_alias: "filebeat-srvlinux"
  pattern: "{now/d}-000001"

processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

Kibana `/etc/kibana/kibana.yml`:

```auto
server.host: "0.0.0.0"
server.name: "kibana.domain.lan"

elasticsearch.hosts: ["https://kibana.domain.lan:9200"]
elasticsearch.username: "kibana_system"
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/certs/DOMAIN-CA.crt"]

server.ssl.certificate: /etc/kibana/certs/srv-log.crt
server.ssl.key: /etc/kibana/certs/srv-log.key
server.ssl.enabled: true

xpack.encryptedSavedObjects.encryptionKey: censored
xpack.reporting.encryptionKey: censored
xpack.security.encryptionKey: censored

```

Elasticsearch `/etc/elasticsearch/elasticsearch.yml`:

```auto
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
cluster.name: domain_elk
node.name: SRV-LOG

network.host: 0.0.0.0
http.port: 9200
discovery.seed_hosts: ["127.0.0.1"]
discovery.type: single-node

xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.client_authentication: required
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/certs/elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/certs/elastic-certificates.p12

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.certificate: /etc/elasticsearch/certs/http-SRV-LOG.crt
xpack.security.http.ssl.key: /etc/elasticsearch/certs/http-SRV-LOG.key
xpack.security.http.ssl.certificate_authorities: ["/etc/elasticsearch/certs/DOMAIN-CA.crt"]

```

Thanks for any kind of help!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 19, 2021, 2:33pm UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/2 "2021-08-19T14:33:29Z")

</div>

I think you are hitting this bug. [Kibana authentication is not inheriting the Elasticsearch output api\_key value · Issue #24015 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/24015)

---

<div class="post-metadata">

**Author:** ![JulienL](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@JulienL](https://discuss.elastic.co/u/JulienL)\
**Post date:** [August 20, 2021, 7:53am UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/3 "2021-08-20T07:53:49Z")

</div>

Hi! Thanks for your answer.

As you suggested, I've set the header manually in the filebeat.yml, and it worked 🙂

This look like this now:

```auto
setup.kibana:
  host: "https://kibana:5601"
  headers:
    Authorization: "ApiKey censored_base64_key"

```

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![JulienL](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@JulienL](https://discuss.elastic.co/u/JulienL)\
**Post date:** [August 23, 2021, 9:32am UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/4 "2021-08-23T09:32:15Z")

</div>

Hello,

I'm back with some problems.  
The workaround works well on Windows Systems with Winlogbeat but not on Linux with Filebeat.  
Still the same error.

What could be missing?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 30, 2021, 5:11pm UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/5 "2021-08-30T17:11:06Z")

</div>

Are you getting the same 401 error? If so then can you show your config. Maybe it's an indentation issue with the options. The code for Windows and Linux is the same so it should behave the same.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2021, 7:11pm UTC](https://discuss.elastic.co/t/cant-setup-winlogbeat-or-filebeat-dashboards-for-kibana/281962/6 "2021-09-27T19:11:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
