# Certificates between Filebeat and Kibana for Filebeat to do setup.dashboards.enabled: true

**URL:** https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904
**Category:** Kibana
**Created:** [December 21, 2018, 11:06pm UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904 "2018-12-21T23:06:09Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)
#### Post date: [December 21, 2018, 11:06pm UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904/1 "2018-12-21T23:06:09Z")

</div>

I'm trying to enable dashboards in Kibana and, in the Filebeat log, I am getting:

```
ERROR instance/beat.go:743 Exiting: Error importing Kibana dashboards: \
    fail to create the Kibana loader: \
    Error creating Kibana client: Error creating Kibana client: \
    fail to get the Kibana version: \
    HTTP GET request to /api/status fails: \
    fail to execute the HTTP GET request: \
    Get http://elk-host:5601/api/status: dial tcp 10.0.1.174:5601: \
    connect: connection refused.

```

I run an ELK stack (sebp/elk) on one host and Filebeat on one or more remote nodes. I have a certificate/key between Filebeat and Logstash set up. Communication works perfectly and I get logs. Here's the Filebeat side of that:

```
output.logstash:
  hosts: ["elk-host:5044"]
  ssl.enabled: true
  ssl.certificate: "/etc/pki/tls/certs/logstash-beats.crt"
  ssl.key: "/etc/pki/tls/private/logstash-beats.key"

```

And the Logstash side:

```
input
{
  beats
  {
    port => 5044
    ssl => true
    ssl_certificate => "/etc/pki/tls/certs/logstash-beats.crt"
    ssl_key => "/etc/pki/tls/private/logstash-beats.key"
  }
}

```

Now I'm starting to try to use Filebeat configuration to enable dashboards in Kibana. With just this

```
setup.dashboards.enabled: true

```

I get the error reported above. At the end of _filebeat.yml_ I want to add this to sort out the problem:

```
setup.kibana.protocol: "https"
setup.kibana.host: "elk-host:5601"
setup.kibana.ssl.enabled: true
setup.kibana.ssl.certificate: "/etc/pki/tls/certs/kibana-beats.crt"
setup.kibana.ssl.key: "/etc/pki/tls/private/kibana-beats.key"

```

But, I don't know how to configure Kibana reciprocally to make use of this certificate. I've studied _kibana.yml_, but none of the certificate settings appear relevant to what I'm trying to do.

How is this wiring done?

---

<div class="post-metadata">

### Author: ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)
#### Post date: [December 22, 2018, 1:15am UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904/2 "2018-12-22T01:15:54Z")

</div>

`connect: connection refused` suggests to me that it's not a certificate error, but a more general networking error and that the beat is unable to connect to `elk-host:5601` at all. Are you running in containers? Are you sure that `elk-host:5601` is accessible from within the container the beat is running in?

---

<div class="post-metadata">

### Author: ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)
#### Post date: [December 26, 2018, 10:36pm UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904/3 "2018-12-26T22:36:46Z")

</div>

Many thanks for getting back to me. This got lost in the holiday shuffle.

Yes, I'm running in containers (Filebeat in its own; the rest of the ELK stack in their own container). I assumed that `elk-host:5601` can be connected to by Filebeat running in its container because it's already working perfectly to send log entries to Logstash via `elk-host:5044`. Maybe there's something about Filebeat's use of the Kibana API that I don't understand and the hostname isn't resolved by Docker DNS whereas Filebeat's configured `output.logstash` does somehow get this treatment?

---

<div class="post-metadata">

### Author: ![RussellBateman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/russellbateman/32/34928_2.png) [@RussellBateman](https://discuss.elastic.co/u/RussellBateman)
#### Post date: [January 4, 2019, 2:02pm UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904/4 "2019-01-04T14:02:54Z")

</div>

Well, back from the holidays, this is what I now think. I hope this comment helps someone else.

Especially since our multiple Filebeat containers are running potentially (very likely) on different hosts, we don't want to use _filebeat.yml_ to install dashboards in Kibana. Instead, we'll do it in our greater, ELK container. Right now, for instance, we're using the _saved-object_ API in Kibana to preinstall our index pattern ("filebeat-\*") and we'll find a similar solution for any dashboard we choose to deploy:

**_preinstall-index-pattern.sh_** :

```
#!/bin/sh
# Preinstall index pattern "filebeat-*" for Kibana's use:
curl -X POST \
  "http://localhost:5601/api/saved_objects/index-pattern/filebeat-pattern" \
  --header 'kbn-xsrf: true' \
  --header 'Content-Type: application/json' \
  --data '\
    {\
      "attributes" :\
      {\
        "title" : "filebeat-*",\
        "timeFieldName" : "@timestamp",\
        "notExpandable" : true\
      }\
    }'

```

This works; we don't need keys and certificates, etc., though in terms of automatic installation, I don't yet know if we're going to have to jury-rig it using `ENTRYPOINT` in _Dockerfile_ or find some other way to set it off after Kibana's API is up.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 1, 2019, 2:02pm UTC](https://discuss.elastic.co/t/certificates-between-filebeat-and-kibana-for-filebeat-to-do-setup-dashboards-enabled-true/161904/5 "2019-02-01T14:02:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
