# Error connecting to Kibana

**URL:** <https://discuss.elastic.co/t/error-connecting-to-kibana/184294>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [June 5, 2019, 7:44am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294 "2019-06-05T07:44:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Min\_Mah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/min_mah/32/46757_2.png) [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Post date:** [June 5, 2019, 7:44am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/1 "2019-06-05T07:44:33Z")

</div>

Hi,  
when i was typing

> metricbeat setup

then this error appear

> [root@localhost share]# metricbeat setup  
> Index setup complete.  
> Loading dashboards (Kibana must be running and reachable)  
> Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [https://192.168.0.85:5601/api/status](https://192.168.0.85:5601/api/status) fails: fail to execute the HTTP GET request: Get [https://192.168.0.85:5601/api/status:](https://192.168.0.85:5601/api/status:) x509: certificate signed by unknown authority. Response:

but when in my web - [https://192.168.0.85:5601/api/status](https://192.168.0.85:5601/api/status)  
it can be get kibana version

> {"name":"Kibana","uuid":"c1580b77-f439-4b99-9e11-8f4662b03747","version":{"number":"7.1.0","build\_hash":"7bdb99203c3b0d113668b9a96b1daaa920d654a2","build\_number":23222,"build\_snapshot":false},"status":{"overall":{"state":"green","title":"Green","nickname":"Looking good","icon":"success","uiColor":"secondary","since":"2019-06-05T07:37:17.662Z"},"statuses":[{"id":"plugin:kibana@undefined","state":"green","icon":"success","message":"Ready","uiColor":"secondary","since":"2019-06-05T07:37:17.662Z"} ~~~~~~~~~~~~~~~~ {"number\_of\_elapsed\_periods":0,"number\_of\_times\_throttled":0,"time\_throttled\_nanos":0}}}},"response\_times":{"avg\_in\_millis":173.875,"max\_in\_millis":1165},"requests":{"disconnects":0,"statusCodes":{},"total":7,"status\_codes":{"200":4,"304":4}},"concurrent\_connections":0}}

This is my metricbeat.yml

> #==================== Elasticsearch template setting ==========================
> 
> setup.template.name : "metricbeat"  
> setup.template.pattern: "metricbeat-\*"
> 
> setup.template.settings:  
> index.number\_of\_shards: 1  
> index.codec: best\_compression  
> #\_source.enabled: false
> 
> #============================== Kibana =====================================
> 
> #Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.  
> #This requires a Kibana endpoint configuration.  
> setup.kibana:
> 
> #kibana Host  
> #Scheme and port can be left out and will be set to the default (http and 5601)  
> #In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)  
> #IPv6 addresses should always be defined as: https://[2001:db8::1]:5601  
> host: "[https://192.168.0.85:5601](https://192.168.0.85:5601)"  
> ssl.certificate: /etc/pki/root/server2.crt  
> ssl.key: /etc/pki/root/server.key  
> ssl.certificateAuthorities: /etc/pki/root/server.cakey.pem  
> #ssl.vertification\_mode: none
> 
> #-------------------------- Elasticsearch output ------------------------------  
> output.elasticsearch:  
> #Array of hosts to connect to.  
> hosts: ["[https://192.168.0.85:9200](https://192.168.0.85:9200)"]
> 
> #Optional protocol and basic auth credentials.  
> protocol: "https"  
> username: "elastic"  
> password: "d8Z46pgoFEd1rQNdOfDX"  
> index: "metricbeat-%{[agent.version]}"  
> ssl.certificate\_authorities: "/etc/pki/root/root.crt"  
> ssl.certificate: "/etc/pki/root/client2.crt"  
> ssl.key: "/etc/pki/root/client.key"  
> #ssl.key\_passphrase: "qlalfqjsgh12!"  
> ssl.verification\_mode: "none"
> 
> #================================= Setup ILM ==================================  
> #The index lifecycle write alias name.  
> #The default is metricbeat-{agent.version}.  
> #Setting this option changes the prefix in the alias name.  
> #It doesn’t remove agent.version from the alias name.  
> #setup.ilm.rollover\_alias: "metricbeat"
> 
> #The rollover index pattern. The default is %{now/d}-000001  
> setup.ilm.pattern: "0000001"

this is my kibana.yml

> elasticsearch.username: "kibana"  
> elasticsearch.password: "Y3B2c5U0izQF2Who2qyj"
> 
> server.ssl.certificate: /etc/kibana/server2.crt  
> server.ssl.key: /etc/kibana/server.key  
> server.ssl.certificateAuthorities: /etc/kibana/ES/server.cakey.pem
> 
> elasticsearch.ssl.certificate: /etc/kibana/ES/client2.crt  
> elasticsearch.ssl.key: /etc/kibana/ES/client.key
> 
> elasticsearch.ssl.certificateAuthorities: /etc/kibana/ES/root.crt
> 
> elasticsearch.ssl.verificationMode: none

Help me please.  
Thanks.

---

<div class="post-metadata">

**Author:** ![AndWe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andwe/32/47532_2.png) [@AndWe](https://discuss.elastic.co/u/AndWe)\
**Post date:** [June 5, 2019, 8:25am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/2 "2019-06-05T08:25:31Z")

</div>

Hi Min\_Mah

In your config's you have just everywhere ssl.verification\_mode set to none except in the kibana section of your metricbeat.yml. Its comented out. Can you remove the # and retry?

Please keep in mind about the documentation: Setting ssl.verification\_mode to none will not verify the certificates.

Kind regards

---

<div class="post-metadata">

**Author:** ![Min\_Mah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/min_mah/32/46757_2.png) [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Post date:** [June 5, 2019, 8:28am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/3 "2019-06-05T08:28:50Z")

</div>

Thanks for reply

i was change like this

> #============================== Kibana =====================================
> 
> #Starting with Beats version 6.0.0, the dashboards are loaded via the Kibana API.  
> #This requires a Kibana endpoint configuration.  
> setup.kibana:
> 
> #kibana Host  
> #Scheme and port can be left out and will be set to the default (http and 5601)  
> #In case you specify and additional path, the scheme is required: [http://localhost:5601/path](http://localhost:5601/path)  
> #IPv6 addresses should always be defined as: https://[2001:db8::1]:5601  
> host: "[https://192.168.0.85:5601](https://192.168.0.85:5601)"  
> username: "elastic"  
> password: "d8Z46pgoFEd1rQNdOfDX"  
> #ssl.enabled: true  
> ssl.certificate: /etc/pki/root/server2.crt  
> ssl.key: /etc/pki/root/server.key  
> ssl.certificateAuthorities: /etc/pki/root/server.cakey.pem  
> #ssl.certificateAuthorities: /etc/pki/root/root.crt  
> ssl.vertification\_mode: none

but it still error

> [root@localhost metricbeat]# metricbeat setup  
> Index setup complete.  
> Loading dashboards (Kibana must be running and reachable)  
> Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to [https://192.168.0.85:5601/api/status](https://192.168.0.85:5601/api/status) fails: fail to execute the HTTP GET request: Get [https://192.168.0.85:5601/api/status:](https://192.168.0.85:5601/api/status:) x509: certificate signed by unknown authority. Response: .

---

<div class="post-metadata">

**Author:** ![Min\_Mah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/min_mah/32/46757_2.png) [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Post date:** [June 5, 2019, 8:34am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/4 "2019-06-05T08:34:30Z")

</div>

ahahaha.. sorry it's my fault i was type

ssl.vertification\_mode

it should be  
ssl.verification\_mode

Thanks for reply

---

<div class="post-metadata">

**Author:** ![AndWe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andwe/32/47532_2.png) [@AndWe](https://discuss.elastic.co/u/AndWe)\
**Post date:** [June 5, 2019, 9:08am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/5 "2019-06-05T09:08:15Z")

</div>

Is it working now?

---

<div class="post-metadata">

**Author:** ![Min\_Mah](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/min_mah/32/46757_2.png) [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Post date:** [June 7, 2019, 7:17am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/6 "2019-06-07T07:17:03Z")

</div>

Yes, it's working now  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2019, 9:28am UTC](https://discuss.elastic.co/t/error-connecting-to-kibana/184294/7 "2019-07-05T09:28:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
