# Filebeat does not work while using cloud.id and cloud.auth

**URL:** <https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 15, 2020, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167 "2020-01-15T15:44:40Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/1 "2020-01-15T15:44:40Z")

</div>

Hello -  
I am trying to use cloud.id and cloud.auth in my file beat configuration file. But that seems not working.

This Works perfectly without using cloud.id and cloud\_auth.

output.elasticsearch:  
hosts: ["https://4d90d9c2814c429xxxxxxxxxx:99999"]  
protocol: https  
ssl: null  
ignoreversion: true  
username: "xxxxxxx"  
password: "yyyyyyy"

This does not work while using cloud.id and cloud\_auth, getting error like below.

401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm="securit.......

output.elasticsearch:  
hosts: ["https://4d90d9c2814c429xxxxxxxxxx:99999"]  
ssl: null  
ignorversion: true  
cloud.id: "temps:am9uxxxxxxxxxxxxxxxxxxxxxx"  
cloud.auth: "xxxxxxxx:yyyyyyyyy"

Can someone help?

Thank you.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 4:41pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/2 "2020-01-15T16:41:53Z")

</div>

Hi,  
You need to configure the permissions of your user 😉

Here is my logstash\_writer :

 ![Sélection_057](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1b05df96e697e9f33eae23968c84695cc8492b42.png)

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 4:54pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/3 "2020-01-15T16:54:55Z")

</div>

Thank you.

We are using ECE 2.4 deployed on our internal cloud.

Where or how to get to this screen?

BTW, I am not using Logstash in my filebeat.yml. Filebeat (on local instance in cloud) --\> ElasticSearch (on cloud).

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/4 "2020-01-15T17:09:10Z")

</div>

In Kibana Users / Roles creating a new role,

if you're not using logstash this should work the same way 😉 i hope

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 6:37pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/5 "2020-01-15T18:37:29Z")

</div>

Hi -

I don't see that screen in my Kibana.

I have assigned all the available roles existed for my user under Management -\> Security -\> Users and still filebeat fails while using cloud.id and cloud.auth and my user.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/9/09d8c0085174f51c052a25f4f74c81edbd674ee6.png)

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 7:14pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/6 "2020-01-15T19:14:14Z")

</div>

Didn't dig deep enough.

So, I created a new role with the cluster and index privileges as you have specified. (And, i don't see monitor\_transform privileges on my dropdown).

I assigned this new role to the user and still filebeat fails.

2020-01-15T14:10:32.434-0500 ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([https://4d90d9c2814c429d9ce4a416921ca611.xxxxxxxx-test](https://4d90d9c2814c429d9ce4a416921ca611.xxxxxxxx-test):xxxx)): 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}}],"type":"security\_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}},"status":401}

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 7:45pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/7 "2020-01-15T19:45:47Z")

</div>

force monitor privileges into the textbox

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 7:52pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/8 "2020-01-15T19:52:25Z")

</div>

I did that as well and tried giving "all" privileges. nothing works.

If I use plain username and password, it works. cloud.id and cloud.auth does not work.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 8:13pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/9 "2020-01-15T20:13:32Z")

</div>

401 look like you maybe miss typed password or check for wrong endpoint url.

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 9:21pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/10 "2020-01-15T21:21:07Z")

</div>

no still same. just using the some simple password and I double checked the Cloud ID (took the cloud id under my deployment name).

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 15, 2020, 9:23pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/11 "2020-01-15T21:23:23Z")

</div>

I used the same username and password as below and it works perfectly. can't figure out why throwing 401 while using in cloud.auth

output.elasticsearch:  
hosts: ["[https://xxxxxxxx:9999](https://xxxxxxxx:9999)"]  
username: "newuser"  
password: "newuser"

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 16, 2020, 4:43pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/12 "2020-01-16T16:43:03Z")

</div>

Hi @newKibanaUser

If you're using `cloud.id`/`cloud.auth` I think you have to remove all of `hosts`/`username`/`password` fields from `output.elasticsearch` - it wasn't clear from your snippets if you were doing that

If that doesn't help, can you run the second half of the cloud id through a base64 decoder and confirm that it is the URL (including port) you are expecting?

Alex

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 16, 2020, 5:57pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/13 "2020-01-16T17:57:57Z")

</div>

Hi Alex-

If I remove hosts, it gives below error so I have to include the hosts.

ERROR instance/beat.go:916 Exiting: error initializing publisher: missing required field accessing 'output.elasticsearch.hosts'

I used online tool to decode cloud.id (without the deployment name), but the results are flipped. Is that normal?

for cloud ID "aaaaaaaaaaaa", result is like below. The URL after second dollar sign does not match with my original URL.

```
  non-production.ece.iaas-test:9243$aaaaaaaaa$another set of string

```

Here is my YML file.

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9c9f8e3aae49bda851892e5fab5eff14db3eb55e.png)

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 16, 2020, 7:14pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/14 "2020-01-16T19:14:42Z")

</div>

Oh `cloud.id` and `cloud.auth` live at the top level I think, not under `output.elasticsearch`?

---

<div class="post-metadata">

**Author:** ![newKibanaUser](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Post date:** [January 16, 2020, 7:42pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/15 "2020-01-16T19:42:22Z")

</div>

you nailed it. It works now. Thanks.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/1/61c2047e165b62b3a181e4407070d228ae7faa89.png)

Another follow-up question before we can close this. The filebeat gives below error and I am OK for now since I am not using modules in filebeat yet.

ERROR fileset/modules.go:125 Not loading modules. Module directory not found: /usr/share/filebeat/bin/module

Actually the modules resides in the **/usr/share/filebeat/module** directory at my instance (not under bin). How to tell filebeat to look into this particular folder for modules (or) move those modules to the folder it is looking?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [January 17, 2020, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/16 "2020-01-17T14:48:04Z")

</div>

I suggest asking that question in a different thread so that people who know lots about beats but not about beats/cloud aren't put off by the title (and vice versa!) 🙂

It seems like there are already some similar Q/As kicking around for that though - eg ["Module directory not found" - filebeat looking in wrong place?](https://discuss.elastic.co/t/module-directory-not-found-filebeat-looking-in-wrong-place/80805)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2020, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167/17 "2020-02-14T14:48:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
