# Connect to Elastic Cloud with Java Low Level Rest Client

**URL:** <https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801>\
**Category:** Elasticsearch\
**Created:** [January 25, 2019, 3:49pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801 "2019-01-25T15:49:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefan5](https://avatars.discourse-cdn.com/v4/letter/s/9d8465/32.png) [@stefan5](https://discuss.elastic.co/u/stefan5)\
**Post date:** [January 25, 2019, 3:49pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801/1 "2019-01-25T15:49:06Z")

</div>

I want to connect to my AWS Elasticsearch cloud but it only works for my localhost.

When i connect to localhost i type this, and this works:  
`RestClient restClient = RestClient.builder(new HttpHost("localhost", 9200, "http"), new HttpHost("localhost", 9200, "http")).build();`

However when i try to connect to my AWS version of Elasticsearch I dont understand how to connect. This is whay i've tried to do.

`RestClient restClient = RestClient.builder( new HttpHost("xxxxxxxxxx.eu-central-1.aws.cloud.es.io", 9243, "https"), new HttpHost("xxxxxxxxxx.eu-central-1.aws.cloud.es.io", 9243, "https")).build();`

I get this error:

`Caused by: org.elasticsearch.client.ResponseException: method [GET], host [https://xxxxxxxxx.eu-central-1.aws.cloud.es.io:9243], URI [/], status line [HTTP/1.1 401 Unauthorized] {"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm=\"security\"","Basic realm=\"security\" charset=\"UTF-8\""]}}],"type":"security_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm=\"security\"","Basic realm=\"security\" charset=\"UTF-8\""]}},"status":401}`

I believe i somehow need to authenticate myself, how do i do that?

TLDR;  
I can connect to my localhost but not to a AWS Cloud. How do i authenticate?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 28, 2019, 11:50pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801/2 "2019-01-28T23:50:34Z")

</div>

There seems to be some confusion in your post. You talk about `AWS Elasticsearch` and `AWS Cloud`, but your URL is `xxxxxxxxxx.eu-central-1.aws.cloud.es.io` which is part of **Elastic Cloud** running on AWS, but it is not AWS Elasticsearch. Those are different services.

We can help you with Elastic Cloud, but we don't have expertise in AWS Elasticsearch. I assume this is just some confusion in terminology, and your URLs are correct and you are trying to connect to Elastic Cloud.

So, with respect to your problem:

> [@stefan5](#):
>
> Caused by: org.elasticsearch.client.ResponseException: method [GET], host [[https://xxxxxxxxx.eu-central-1.aws.cloud.es.io:9243](https://xxxxxxxxx.eu-central-1.aws.cloud.es.io:9243)], URI [/], status line [HTTP/1.1 401 Unauthorized]

Yes, you definitely need to Authenticate yourself.

There's 2 parts to that answer:

1. Configuring users on your cluster
2. Using a username and password in your client.

**Configuring users on your cluster**  
When you signed up to Elastic Cloud you would have been given a username and password to connect to your cluster / Kibana. The user would be `elastic` and the password would have been auto generated.  
While you _can_ use that username/password to connect from your client, we strongly discourage it. That user is a _superuser_ that can do _everything_ on the cluster. It can delete all your data, change all your configurations, etc. You should keep that password protected, and not use it within your client.  
Instead, you should login to Kibana (using `elastic`) and create a new username + password for your client. There's some instructions on using the Kibana Security Management UI here:

- [Security | Kibana User Guide [6.5] | Elastic](https://www.elastic.co/guide/en/kibana/6.5/xpack-security.html)  
(that's for v6.5, you didn't mention which version you're running)  
For starters, you'll want to:

1. create a new **role** , that has the "monitor" cluster privilege, and then appropriate read/write access to whatever indices your client is going to read from/write to.
2. create a new **user** , and grant them your new role.

**Using a username and password in your client.**  
The docuentation for how to do this in the Low Level Rest Client is here:

- [Basic authentication | Java REST Client [6.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/client/java-rest/6.5/_basic_authentication.html)

It's fairly self explanatory, but ask if you have any issues.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 28, 2019, 11:51pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801/3 "2019-01-28T23:51:29Z")

</div>

_I changed the title of this thread so that it reflects "Elastic Cloud" rather than "AWS Elasticsearch"._

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2019, 11:51pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-with-java-low-level-rest-client/165801/4 "2019-02-25T23:51:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
