# Elastic ITSM Connector shows CORS error

**URL:** <https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [February 3, 2022, 8:58pm UTC](https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230 "2022-02-03T20:58:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pindropviolence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pindropviolence/32/101494_2.png) [@pindropviolence](https://discuss.elastic.co/u/pindropviolence)\
**Post date:** [February 3, 2022, 8:58pm UTC](https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230/1 "2022-02-03T20:58:25Z")

</div>

Hello Folks,

I have tried to configured Elastic ITSM connector in Kb instance, i get CORS error when i try to create a new connection or add a connection to a rule. When I disabled CORS on browser level , I was able to create the connection but when i try to test the connection i am getting a response in the browser's network tab but the values in the drop down such as (Urgency , Severity , Impact, Category) are not populating in the browser and are hidden.  
Please note that i have followed the steps in below documentation to install Elastic ITSM on the SNOW instance. [ServiceNow ITSM connector and action | Kibana Guide [7.16] | Elastic](https://www.elastic.co/guide/en/kibana/7.16/servicenow-action-type.html#configuring-servicenow)  
I have tried to add a header Access-Control-Allow-Origin on the SNOW server.

Below is my config for kibana :

```auto
apiVersion: kibana.k8s.elastic.co/v1
kind: Kibana
metadata:
  name: kibana
spec:
  version: 7.16.3
  http:
    tls:
      selfSignedCertificate:
        disabled: true
    service:
      spec:
        type: LoadBalancer
  count: 4
  elasticsearchRef:
    name: elasticsearch
  config:
     server:
      maxPayloadBytes: 4294967296
      cors.enabled: true
      cors.allowOrigin: ["https://domain"]
      cors.allowCredentials: true
      customResponseHeaders:
         Access-Control-Allow-Origin: "https://domain"

```

Below is the screen shots of the issue.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e12cd1c659b181ee3f9107e16e33feb528d92772.jpeg)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/7/67103e78c2d0beb0772562120e5ed6ec5ba60771.jpeg)

I am hopeful there is some settings that i have to configure in order to have this working. Any guidance is very appreciated.

---

<div class="post-metadata">

**Author:** ![pindropviolence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pindropviolence/32/101494_2.png) [@pindropviolence](https://discuss.elastic.co/u/pindropviolence)\
**Post date:** [February 8, 2022, 1:00pm UTC](https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230/2 "2022-02-08T13:00:22Z")

</div>

I have upgraded ES , KB to 7.17.0 the error now is 500 Internal Server Error.

```auto

> General

```

```auto
Request URL: https://domain/api/actions/connector/dca18eb0-7fbb-11ec-b063-513931ce911a/_execute
Request Method: POST
Status Code: 500 Internal Server Error
Remote Address: xx.xxx.xx.xx:443
Referrer Policy: no-referrer-when-downgrade

```

```auto
> Response Headers

```

```auto
HTTP/1.1 500 Internal Server Error
Date: Tue, 08 Feb 2022 12:55:00 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 97
Connection: keep-alive
X-Content-Type-Options: nosniff
Referrer-Policy: no-referrer-when-downgrade
kbn-name: kibana
kbn-license-sig: 
cache-control: private, no-cache, no-store, must-revalidate

```

```auto
> Request Headers

```

```auto
Accept: */*
Accept-Encoding: gzip, deflate, br
Accept-Language: en-US,en;q=0.9
Connection: keep-alive
Content-Length: 123
Content-Type: application/json
Cookie: sid=
Host: domain
kbn-version: 7.17.0
Origin: https://domain
Referer: https://domain/app/management/insightsAndAlerting/triggersActions/connectors
Sec-Fetch-Dest: empty
Sec-Fetch-Mode: cors
Sec-Fetch-Site: same-origin
Sec-GPC: 1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.99 Safari/537.36

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/3/53bc05d9f253b443aabe433cfa29f23e10fd952e.png)

---

<div class="post-metadata">

**Author:** ![pindropviolence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pindropviolence/32/101494_2.png) [@pindropviolence](https://discuss.elastic.co/u/pindropviolence)\
**Post date:** [February 8, 2022, 1:08pm UTC](https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230/3 "2022-02-08T13:08:03Z")

</div>

My Guess is it is blocked at the browser due to Content Security Policy blocks inline execution of scripts and stylesheets.

If anyone can confirm that and provide an alternative solution or a way around, it would be really helpful and deeply appreciated.

I have notices there is an open issue for the CSP error in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2022, 1:08pm UTC](https://discuss.elastic.co/t/elastic-itsm-connector-shows-cors-error/296230/4 "2022-03-08T13:08:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
