# Filebeat 6.7.0 not working with AWS Elasticsearch

**URL:** <https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 4, 2019, 12:26pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407 "2019-04-04T12:26:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarekObu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marekobu/32/43491_2.png) [@MarekObu](https://discuss.elastic.co/u/MarekObu)\
**Post date:** [April 4, 2019, 12:26pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407/1 "2019-04-04T12:26:03Z")

</div>

After upgrading filebeat to 6.7.0, I've noticed that it doesn't ship logs anymore. I'm using AWS managed Elasticsearch, which does not provide license information.

Related to: [https://github.com/elastic/beats/pull/11296](https://github.com/elastic/beats/pull/11296)

filebeat.log:

```
2019-04-04T12:21:58.641Z	ERROR	pipeline/output.go:100	Failed to connect to backoff(elasticsearch(http://elk:80)): Connection marked as failed because the onConnect callback failed: cannot retrieve the elasticsearch license: unauthorized access, could not connect to the xpack endpoint, verify your credentials

```

AWS Elasticsearch is configured to allow connections without authorisation from selected instances (access policy allows es:\* calls).

In this setup, Elasticsearch does not allow to list xpack licenses:

```
$ curl -i elk/_xpack/license
HTTP/1.1 401 Unauthorized
Access-Control-Allow-Origin: *
Content-Type: application/json
x-amzn-RequestId: 760c652a-56d4-11e9-a7b5-8b0e14beb14d
Content-Length: 61
Connection: keep-alive

{"Message":"Your request: '/_xpack/license' is not allowed."}

```

Is there any way to run Filebeat (versions 6.7+) with AWS Elasticsearch service?

Best regards,  
Marek Obuchowicz  
[KoreKontrol - managed cloud hosting for eCommerce](https://www.korekontrol.eu/)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 4, 2019, 12:55pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407/2 "2019-04-04T12:55:55Z")

</div>

You should be able to use [the oss distribution](https://www.elastic.co/downloads/beats/filebeat-oss).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 4, 2019, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407/3 "2019-04-04T13:09:59Z")

</div>

This request will fail with AWS managed Elasticsearch as you need to run the Beats OSS versions, still the HTTP response returned by AWS is not correct if you say that authorization is no problem.

---

<div class="post-metadata">

**Author:** ![MarekObu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marekobu/32/43491_2.png) [@MarekObu](https://discuss.elastic.co/u/MarekObu)\
**Post date:** [April 4, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407/4 "2019-04-04T14:06:51Z")

</div>

Thanks for the hint... Is it possible to get opensource packages also from any debian repository?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-6-7-0-not-working-with-aws-elasticsearch/175407/5 "2019-05-02T14:06:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
