# Error activating rule…

**URL:** <https://discuss.elastic.co/t/error-activating-rule/248424>\
**Category:** SIEM\
**Tags:** docker\
**Created:** [September 12, 2020, 10:16pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424 "2020-09-12T22:16:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akash\_Upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_upadhyay/32/75476_2.png) [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Post date:** [September 12, 2020, 10:16pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/1 "2020-09-12T22:16:44Z")

</div>

Hey,

I have installed elk using docker. It is up and running fine. But the problem occurs when I try to activate pre-built rules.

 ![elk](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8ef6655069419151e7e3d818945d40df018dc046.png)

My docker-compose.yml configurations are:

```auto
version: '3'

services:

  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:7.8.0
    container_name: elasticsearch
    environment:
      - node.name=elasticsearch
      - discovery.seed_hosts=elasticsearch
      - cluster.initial_master_nodes=elasticsearch
      - cluster.name=docker-cluster
      - bootstrap.memory_lock=true
      - "ES_JAVA_OPTS=-Xms512m -Xmx512m"
      - xpack.security.enabled=true
      - xpack.security.transport.ssl.enabled=true
      - xpack.security.transport.ssl.keystore.type=PKCS12
      - xpack.security.transport.ssl.verification_mode=certificate
      - xpack.security.transport.ssl.keystore.path=elastic-stack-ca.p12
      - xpack.security.transport.ssl.truststore.path=elastic-stack-ca.p12
      - xpack.security.transport.ssl.truststore.type=PKCS12
    ulimits:
      memlock:
        soft: -1
        hard: -1
    volumes:
      - ./elastic-stack-ca.p12:/usr/share/elasticsearch/config/elastic-stack-ca.p12
      - esdata1:/usr/share/elasticsearch/data
    ports:
      - 9200:9200

  kibana:
    image: docker.elastic.co/kibana/kibana:7.8.0
    container_name: kibana
    environment:
      ELASTICSEARCH_URL: "http://elasticsearch:9200"
      ELASTICSEARCH_USERNAME: "kibana"
      ELASTICSEARCH_PASSWORD: "@elk1234"
    ports:
      - 5601:5601
    depends_on:
      - elasticsearch

volumes:
  esdata1:
    driver: local

```

Kindly help me out

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 13, 2020, 11:17pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/2 "2020-09-13T23:17:34Z")

</div>

Can you elaborate on what rules you are referring to here?

---

<div class="post-metadata">

**Author:** ![Akash\_Upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_upadhyay/32/75476_2.png) [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Post date:** [September 14, 2020, 5:08am UTC](https://discuss.elastic.co/t/error-activating-rule/248424/3 "2020-09-14T05:08:33Z")

</div>

The 92 Pre-built rules provided by elk for windows for testing RTA.

> **[Generating ATT&CK Signals in the Elastic SIEM](https://medium.com/@a.randomuserid/generating-att-ck-signals-in-the-elastic-siem-1c1e295404cc)**
>
> Sun, Feb So version 7.6 of the Elastic SIEM has a set of 92 detection rules for threat hunting and security analytics. These detection…

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [September 15, 2020, 3:06pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/4 "2020-09-15T15:06:01Z")

</div>

Do you have both http and https turned on there? I'm not a big developer on docker at the moment but before when there were problems:

> [@"path: /\_security/api\_key... api keys are not enabled" while loading prebuilt detection rules](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319):
>
> I upgraded to 7.6.0 today. I wanted to try Detections, but I'm getting error (below) when clicking "load prebuilt detection rules". My complete Kibana config: --- ## Default Kibana configuration from Kibana base image. ## https://github.com/elastic/kibana/blob/master/src/dev/build/tasks/os\_packages/docker\_generator/templates/kibana\_yml.template.js # server.name: kibana server.host: "0" elasticsearch.hosts: ["http://elasticsearch:9200"] xpack.monitoring.ui.container.elasticsearch.enabled: fa…

The solution usually was they had to ensure they were using the SSL/https within docker to be able to use the API keys feature.

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [September 15, 2020, 3:08pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/5 "2020-09-15T15:08:28Z")

</div>

You will need to enable API\_Key in elasticsearch  
Add this env into your compser  
`xpack.security.authc.api_key.enabled=true`

---

<div class="post-metadata">

**Author:** ![Akash\_Upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_upadhyay/32/75476_2.png) [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Post date:** [September 15, 2020, 7:11pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/6 "2020-09-15T19:11:41Z")

</div>

yes I tried this when I enable this it gives me an error of exit 78

---

<div class="post-metadata">

**Author:** ![Akash\_Upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_upadhyay/32/75476_2.png) [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Post date:** [September 15, 2020, 7:23pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/7 "2020-09-15T19:23:09Z")

</div>

`After adding xpack.security.authc.api_key.enabled=ture`

```auto
ERROR: [1] bootstrap checks failed
[1]: HTTPS is required in order to use the API key service; please enable HTTPS using the [xpack.security.http.ssl.enabled] setting or disable the API key service using the [xpack.security.authc.api_key.enabled] setting

```

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [September 15, 2020, 8:28pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/8 "2020-09-15T20:28:28Z")

</div>

That makes sense. It wants https. As pointed out above usually when we encounter this issue it's because https has to be enabled for the API keys to function which the detection engine relies on. I think once you have https enabled for it you should be good to go.

---

<div class="post-metadata">

**Author:** ![Akash\_Upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akash_upadhyay/32/75476_2.png) [@Akash\_Upadhyay](https://discuss.elastic.co/u/Akash_Upadhyay)\
**Post date:** [September 15, 2020, 10:11pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/9 "2020-09-15T22:11:49Z")

</div>

Hey Both the instances are up and running done getting error msg when trying to access kibana (This error is without https)

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb0217b1c0dffdb1c80efc64242c13be1975b2bb.png)

When accessing with https i am getting this error:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6d738f7f969fc6bf729b028f6d10bb9bfb93ad2.png)

Elastic:

![image](https://us1.discourse-cdn.com/elastic/original/3X/4/1/41c51e05991c5ba8a0a8cdc1358d97b70ceb55aa.png)

Kibana configuration:

```auto
#
# **THIS IS AN AUTO-GENERATED FILE**
#

# Default Kibana configuration for docker target
server.name: kibana
server.host: "0"
elasticsearch.hosts: ["https://elasticsearch:9200"]
elasticsearch.username: "kibana"
elasticsearch.password: ""
monitoring.ui.container.elasticsearch.enabled: true
elasticsearch.ssl.verificationMode: certificate
xpack.encryptedSavedObjects.encryptionKey: 'fhjskloppd678ehkdfdlliver123lfcr'

```

Elastic config

```auto
version: '3'

services:

  elasticsearch:
    image: docker.elastic.co/elasticsearch/elasticsearch:7.8.0
    container_name: elasticsearch
    environment:
      - node.name=elasticsearch
      - discovery.seed_hosts=elasticsearch
      - cluster.initial_master_nodes=elasticsearch
      - cluster.name=docker-cluster
      - bootstrap.memory_lock=true
      - "ES_JAVA_OPTS=-Xms512m -Xmx512m"
      - xpack.license.self_generated.type=basic
      - xpack.security.enabled=true
      - xpack.security.transport.ssl.enabled=true
      - xpack.security.transport.ssl.keystore.type=PKCS12
      - xpack.security.transport.ssl.verification_mode=certificate
      - xpack.security.transport.ssl.keystore.path=elastic-certificates.p12
      - xpack.security.transport.ssl.truststore.path=elastic-certificates.p12
      - xpack.security.transport.ssl.truststore.type=PKCS12
      - xpack.security.authc.api_key.enabled=true
      - xpack.security.http.ssl.enabled=true
      - xpack.security.http.ssl.keystore.path=elastic-certificates.p12
      - xpack.security.http.ssl.truststore.path=elastic-certificates.p12
      - xpack.security.http.ssl.client_authentication=optional
      - xpack.security.http.ssl.verification_mode=certificate 
    ulimits:
      memlock:
        soft: -1
        hard: -1
    volumes:
      - ./elastic-certificates.p12:/usr/share/elasticsearch/config/elastic-certificates.p12
      - esdata1:/usr/share/elasticsearch/data
    ports:
      - 9200:9200

  kibana:
    image: docker.elastic.co/kibana/kibana:7.8.0
    container_name: kibana
    environment:
      ELASTICSEARCH_URL: "https://elasticsearch:9200"
      ELASTICSEARCH_USERNAME: "kibana"
      ELASTICSEARCH_PASSWORD: ""
    ports:
      - 5601:5601
    depends_on:
      - elasticsearch

volumes:
  esdata1:
    driver: local

```

Kibana logs:

```auto
csearch","admin"],"pid":6,"message":"Unable to revive connection: https://elasticsearch:9200/"}
{"type":"log","@timestamp":"2020-09-15T21:53:22Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"No living connections"}
{"type":"log","@timestamp":"2020-09-15T21:53:25Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"Unable to revive connection: https://elasticsearch:9200/"}
{"type":"log","@timestamp":"2020-09-15T21:53:25Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"No living connections"}
{"type":"log","@timestamp":"2020-09-15T21:53:27Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"Unable to revive connection: https://elasticsearch:9200/"}
{"type":"log","@timestamp":"2020-09-15T21:53:27Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"No living connections"}
{"type":"log","@timestamp":"2020-09-15T21:53:30Z","tags":["warning","elasticsearch","admin"],"pid":6,"message":"Unable to revive connection: https://elasticsearch:9200/"}

```

more logs

```auto
{"type":"log","@timestamp":"2020-09-15T21:57:08Z","tags":["error","elasticsearch","monitoring"],"pid":6,"message":"Request error, retrying\nGET https://elasticsearch:9200/_xpack => self signed certificate in certificate chain"}
{"type":"log","@timestamp":"2020-09-15T21:57:08Z","tags":["error","elasticsearch","monitoring"],"pid":6,"message":"Request error, retrying\nGET https://elasticsearch:9200/_xpack => self signed certificate in certificate chain"}

```

Now kindly suggest me what should I do? This is so irritating why don't you people limit to single certificate.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2020, 10:11pm UTC](https://discuss.elastic.co/t/error-activating-rule/248424/10 "2020-10-13T22:11:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
