# Filebeat cannot setup

**URL:** <https://discuss.elastic.co/t/filebeat-cannot-setup/272305>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 6, 2021, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305 "2021-05-06T13:54:22Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 6, 2021, 1:54pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/1 "2021-05-06T13:54:22Z")

</div>

i wanna setup my filebeat but i have a report like this

```
[root@bdi-uat-splunkes filebeat]# filebeat setup
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at https://10.194.11.67:9200: 401 Unauthorized: {"error":{"root_cause":[{"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}}],"type":"security_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm=\"security\" charset=\"UTF-8\"","Bearer realm=\"security\"","ApiKey"]}},"status":401}]

```

why?

btw how to make cert for filebeat

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 11:57am UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/2 "2021-05-07T11:57:14Z")

</div>

You have security enabled with TLS, but you're not sending any credentials to authenticate with elasticsearch. What do you mean make a cert for filebeat?

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 7, 2021, 1:39pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/3 "2021-05-07T13:39:29Z")

</div>

yes i have security with TLS.

i mean what should i do to make a credential to authenticate my elasticsearch?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 2:03pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/4 "2021-05-07T14:03:23Z")

</div>

If u haven't done this yet, [elasticsearch-setup-passwords | Elasticsearch Guide [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-passwords.html)

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 7, 2021, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/5 "2021-05-07T14:53:38Z")

</div>

yes i did that, but i using `elasticsearch-setup-passwords interactive`. what should i do next?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 3:33pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/6 "2021-05-07T15:33:23Z")

</div>

Set the user/pass in the ES output in the config file. See [Configure the Elasticsearch output | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#elasticsearch-output)

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 7, 2021, 3:46pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/7 "2021-05-07T15:46:49Z")

</div>

basic authentication, API key authentication, or PKI certificate authentication?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 3:47pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/8 "2021-05-07T15:47:46Z")

</div>

basic

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 7, 2021, 4:01pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/9 "2021-05-07T16:01:13Z")

</div>

```
[root@bdi-uat-splunkes filebeat]# filebeat setup
Overwriting ILM policy is disabled. Set `setup.ilm.overwrite: true` for enabling.

Index setup finished.
Loading dashboards (Kibana must be running and reachable)
Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://10.194.11.68:5601/api/status fails: fail to execute the HTTP GET request: Get "https://10.194.11.68:5601/api/status": x509: certificate signed by unknown authority (possibly because of "crypto/rsa: verification error" while trying to verify candidate authority certificate "Elastic Certificate Tool Autogenerated CA"). Response: .

```

still error

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 4:29pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/10 "2021-05-07T16:29:53Z")

</div>

I'm assuming you're using the automatically generated self signed certs. You need to set `output.elasticsearch.ssl.certificate_authorities` and `setup.kibana.ssl.certificate_authorities`. See [Configure SSL | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#configuration-ssl)

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 8, 2021, 2:35am UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/11 "2021-05-08T02:35:23Z")

</div>

for _.pem_ should i use from `/etc/pki/client/cert.pem` (elasticsearch authorities) and `/etc/pki/root/ca.pem` (kibana authorities) or from where?

btw there is a _.key_ where should I get it?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 9, 2021, 12:00pm UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/12 "2021-05-09T12:00:18Z")

</div>

So idk how u generated your SSL certs but if they're self signed than copy the cert from elasticsearch to the elasticsearch path and the kibana to the kibana path. If kibana and elasticsearch are using a keystore to hold the certs instead of on the filesystem, you'll have to use the Java `keytool` to extract them. You don't need to worry about the `.key` files for the certificate authority files.

---

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [May 10, 2021, 2:45am UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/13 "2021-05-10T02:45:43Z")

</div>

now it's work. thank you so much Alex

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 10, 2021, 3:11am UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/14 "2021-05-10T03:11:50Z")

</div>

glad I could help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2021, 5:12am UTC](https://discuss.elastic.co/t/filebeat-cannot-setup/272305/15 "2021-06-07T05:12:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
