# Failed to connect AWS ES cluster

**URL:** <https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 8, 2021, 3:12pm UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314 "2021-06-08T15:12:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![richzw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richzw/32/90002_2.png) [@richzw](https://discuss.elastic.co/u/richzw)\
**Post date:** [June 8, 2021, 3:12pm UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314/1 "2021-06-08T15:12:39Z")

</div>

Hi

We try to connect to AWS ES through file beat, However, the following errors comes up

```auto
pipeline/output.go:100	Failed to connect to backoff(elasticsearch(https://xxx.us-east-1.es.amazonaws.com:443)): 
Connection marked as failed because the onConnect callback failed: 
cannot retrieve the elasticsearch license: unauthorized access, 
could not connect to the xpack endpoint, verify your credentials

```

and the config file as

```auto
  filebeat.yml: |-
    filebeat.config:
      inputs:
        enabled: true
        path: ${path.config}/inputs.d/*.yml
        reload.enabled: true
        reload.period: 60s
      modules:
        enabled: true
        path: ${path.config}/modules.d/*.yml
        reload.enabled: true
        reload.period: 60s

    output.elasticsearch:
      protocol: "https"
      hosts: ["xxxx.us-east-1.es.amazonaws.com:443"]
      username: "user_id"
      password: "password"
      index: "test-log--%{+yyyy.MM.dd}"
    setup.template.name: "test-log"
    setup.template.pattern: "test-log-*"
    setup.ilm.enabled: false

```

The filebeat docker image is `docker.elastic.co/beats/filebeat:7.13.1`

The ES version of Amazon Elasticsearch Service is `7.10`

Could someone help us to find the invalid configuration here?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 8, 2021, 8:09pm UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314/2 "2021-06-08T20:09:34Z")

</div>

Please see [Breaking changes in 7.13 | Beats Platform Reference [7.13] | Elastic](https://www.elastic.co/guide/en/beats/libbeat/7.13/breaking-changes-7.13.html)

---

<div class="post-metadata">

**Author:** ![richzw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richzw/32/90002_2.png) [@richzw](https://discuss.elastic.co/u/richzw)\
**Post date:** [June 9, 2021, 3:50am UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314/3 "2021-06-09T03:50:35Z")

</div>

Hi @warkolm

Thank you for your response, we connect to AWS ES with filebeat 7.10.2. The incorrect filebeat version is root cause.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 9, 2021, 6:13am UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314/4 "2021-06-09T06:13:58Z")

</div>

FYI the aws service is a fork and we cannot provide support for it.

If you want to upgrade to our Elasticsearch Service you will be able to run the latest version of everything.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2021, 8:14am UTC](https://discuss.elastic.co/t/failed-to-connect-aws-es-cluster/275314/5 "2021-07-07T08:14:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
