# ERROR: Invalid Host Header Requests

**URL:** <https://discuss.elastic.co/t/error-invalid-host-header-requests/328885>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, language-clients\
**Created:** [March 30, 2023, 6:09am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885 "2023-03-30T06:09:02Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![irfancankaleli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/irfancankaleli/32/119130_2.png) [@irfancankaleli](https://discuss.elastic.co/u/irfancankaleli)\
**Post date:** [March 30, 2023, 6:09am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/1 "2023-03-30T06:09:02Z")

</div>

We are running Elasticsearch v6.8.0 on AWS OpenSearch Service, through VPN, and we use following elasticsearch client in our NodeJS server: [elasticsearch - npm](https://www.npmjs.com/package/elasticsearch)  
Our client version is v16.7.2. When I check the metrics on AWS CloudWatch, I observe that we are getting Invalid Host Header request errors.

I have tried creating client instance using different notations as suggested here:

> <https://stackoverflow.com/questions/57003880/invalid-host-header-when-using-elasticsearch-client>

```auto
const elasticsearchClient = new ElasticsearchClient.Client({
  host: elasticsearchUrl,
  requestTimeout: 120000,
});

```

and

```auto
const elasticsearchClient = new ElasticsearchClient.Client({
  host: {
    protocol: 'https',
    host: ' **********',
    port: '443',
    path: '/'
  },
  requestTimeout: 120000,
});

```

But still no luck, we are getting this error in the CloudWatch. I also tried switching to the new version of the Elasticsearch client, which is:

> **[@elastic/elasticsearch](https://www.npmjs.com/package/@elastic/elasticsearch)**
>
> The official Elasticsearch client for Node.js. Latest version: 8.6.0, last published: 3 months ago. Start using @elastic/elasticsearch in your project by running \`npm i @elastic/elasticsearch\`. There are 979 other projects in the npm registry using...

But result is same, after running queries I am able to observe these warnings in the metrics. I suspect issue is not client oriented and should be fixed by the Elasticsearch configuration, but I could not find a related configuration.

 ![Screen Shot 2023-03-30 at 10.03.46](https://us1.discourse-cdn.com/elastic/original/3X/6/0/609d4b5a6f4e8dcbff8da1e5fdd07d5af9c0a8b0.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2023, 6:09am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/2 "2023-03-30T06:09:02Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 30, 2023, 6:11am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/3 "2023-03-30T06:11:43Z")

</div>

Welcome to our community! 😃

> [@irfancankaleli](#):
>
> I suspect issue is not client oriented and should be fixed by the Elasticsearch configuration

Unfortunately we may not be able to help there as aws runs a fork of Elasticsearch with unknown changes to it. Hopefully one of the clients team can stop by and comment further though!

---

<div class="post-metadata">

**Author:** ![irfancankaleli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/irfancankaleli/32/119130_2.png) [@irfancankaleli](https://discuss.elastic.co/u/irfancankaleli)\
**Post date:** [March 30, 2023, 6:20am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/4 "2023-03-30T06:20:39Z")

</div>

Hello warkolm thank you for welcoming, OpenSearch is derived from Elasticsearch 7.10.2. As I mentioned, we are using the Elasticsearch 6.8.0 on AWS, we did not switch to OpenSearch and as far as I know, there are no explicit changes made by AWS to this served version 6.8.0. It should be Can we please reconsider from this point of view.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2023, 6:20am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/5 "2023-03-30T06:20:39Z")

</div>

Elasticsearch 6.8.0 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 30, 2023, 6:29am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/6 "2023-03-30T06:29:53Z")

</div>

> [@irfancankaleli](#):
>
> As I mentioned, we are using the Elasticsearch 6.8.0 on AWS

I understand that, but the build hash doesn't match the one that we released, so there are definitely unknown changes to Elasticsearch involved.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 30, 2023, 7:18am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/7 "2023-03-30T07:18:18Z")

</div>

You are using an AWS managed service, which means we do not know what changes they may or may not have made, what plugins they may be running that have an impact on this nor how any proxies or layers between you and the nodes are set up. The official clients are not and have never been tested against this kind of setup, so this is something you need to address with AWS support.

---

<div class="post-metadata">

**Author:** ![irfancankaleli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/irfancankaleli/32/119130_2.png) [@irfancankaleli](https://discuss.elastic.co/u/irfancankaleli)\
**Post date:** [March 30, 2023, 7:31am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/8 "2023-03-30T07:31:22Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> You are using an AWS managed service, which means we do not know what changes they may or may not have made, what plugins they may be running that have an impact on this nor how any proxies or layers between you and the nodes are set up. The official clients are not and have never been tested against this kind of setup, so this is something you need to address with AWS support.

Thank you for the response. I will check with AWS support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2023, 7:31am UTC](https://discuss.elastic.co/t/error-invalid-host-header-requests/328885/9 "2023-04-27T07:31:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
