# Elasticsearch, logstash, filebeat, kibana 6.4 x-pack Security issue

**URL:** <https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911>\
**Category:** Kibana\
**Created:** [October 10, 2018, 6:12pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911 "2018-10-10T18:12:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mreloysanchez](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mreloysanchez](https://discuss.elastic.co/u/mreloysanchez)\
**Post date:** [October 10, 2018, 6:12pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911/1 "2018-10-10T18:12:18Z")

</div>

Hello,

I configured my logstash output as noted here:[https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)

I created the logstash pipeline as noted here: [https://www.elastic.co/guide/en/elastic-stack-get-started/6.4/get-started-elastic-stack.html#logstash-setup](https://www.elastic.co/guide/en/elastic-stack-get-started/6.4/get-started-elastic-stack.html#logstash-setup)

When I go to load the template manually as noted here: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually)

I receive this message:

Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch http://"172.16.1.16:9200/%22: Get https://"172.16.1.16:920/%22: lookup "172.16.1.16: no such host]

I looked up the error and it seems that I need to create the filebeat\_writer user, as noted here: [https://www.elastic.co/guide/en/beats/filebeat/6.4/beats-basic-auth.html](https://www.elastic.co/guide/en/beats/filebeat/6.4/beats-basic-auth.html) When I attempt to do that within Kibana\Dev tools, I'm receiving the below message when I attempt to create a user as noted here: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually)

{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
}  
],  
"type" : "security\_exception",  
"reason" : "current license is non-compliant for [security]",  
"license.expired.feature" : "security"  
},  
"status" : 403  
}

It was my understanding that x-pack is now part of the latest version 6.4, so why am I receiving this error message?

Thank you,

Eloy Sanchez

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [October 11, 2018, 10:48am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911/2 "2018-10-11T10:48:36Z")

</div>

Hi,

What's your license? If you downloaded the default distribution - then your license is basic and doesn't have security. You can update to trial using license management under management and then try it up.

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![mreloysanchez](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mreloysanchez](https://discuss.elastic.co/u/mreloysanchez)\
**Post date:** [October 11, 2018, 4:30pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911/3 "2018-10-11T16:30:44Z")

</div>

Thanks bhavyarm,

I referred to [https://www.elastic.co/subscriptions](https://www.elastic.co/subscriptions) Can you tell me how to get a trial license for the Gold and how long it would be valid for? We need those features to successfully get logstash/beats to send syslog/pcap data to our elasticsearch/kibana server.

Eloy Sanchez

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 4:35pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-filebeat-kibana-6-4-x-pack-security-issue/151911/4 "2018-11-08T16:35:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
