Hmmm... Even if I added:
ssl.certificate: "/etc/kibana/es.crt.pem"
ssl.key: "/etc/kibana/es.key.pem"
in Kibana section gives tha same error.
I'm curious - can this be an error cause by nginx reverse proxy?
Edit: one step closer to solution - I forgot to change Kibana ip address in 'filebeat.yml' - as I use nginx and KeepAliveD it is necessary to do it.
This is log for filebeat setup -e
:
2022-09-02T11:56:39.685+0200 INFO [esclientleg] eslegclient/connection.go:285 Attempting to connect to Elasticsearch version 7.17.6
2022-09-02T11:56:40.046+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline"}
2022-09-02T11:56:40.358+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline-plaintext"}
2022-09-02T11:56:40.629+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline-json"}
2022-09-02T11:56:40.880+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline"}
2022-09-02T11:56:41.185+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline-json"}
2022-09-02T11:56:41.516+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline-plaintext"}
2022-09-02T11:56:41.743+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline"}
2022-09-02T11:56:41.963+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline-plaintext"}
2022-09-02T11:56:42.200+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline-json"}
2022-09-02T11:56:42.503+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-gc-pipeline"}
2022-09-02T11:56:42.739+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline"}
2022-09-02T11:56:43.038+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline-plaintext"}
2022-09-02T11:56:43.315+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline-json"}
2022-09-02T11:56:43.320+0200 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.320+0200 WARN [tls] tlscommon/tls_config.go:101 SSL/TLS verifications disabled.
2022-09-02T11:56:43.320+0200 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.320+0200 WARN [tls] tlscommon/tls_config.go:101 SSL/TLS verifications disabled.
2022-09-02T11:56:43.320+0200 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.321+0200 WARN [tls] tlscommon/tls_config.go:101 SSL/TLS verifications disabled.
2022-09-02T11:56:43.321+0200 WARN [tls] tlscommon/tls_config.go:101 SSL/TLS verifications disabled.
2022-09-02T11:56:43.349+0200 INFO [esclientleg] eslegclient/connection.go:285 Attempting to connect to Elasticsearch version 7.17.6
2022-09-02T11:56:43.577+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-log-pipeline"}
2022-09-02T11:56:43.897+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-log-pipeline-plaintext"}
2022-09-02T11:56:44.164+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-log-pipeline-json"}
2022-09-02T11:56:44.427+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline"}
2022-09-02T11:56:44.786+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline-plaintext"}
2022-09-02T11:56:45.018+0200 INFO [modules] fileset/pipelines.go:133 Elasticsearch pipeline loaded. {"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline-json"}
2022-09-02T11:56:45.018+0200 INFO cfgfile/reload.go:262 Loading of config files completed.
2022-09-02T11:56:45.018+0200 INFO [load] cfgfile/list.go:138 Stopping 2 runners ...
Loaded Ingest pipelines