# Filebeat output to elasticsearch (open kerberos), publisher\_pipeline\_output WWW-Authenticate Negotiate 401 No processing

**URL:** <https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 8, 2021, 12:02pm UTC](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539 "2021-01-08T12:02:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jing/32/81927_2.png) [@jing](https://discuss.elastic.co/u/jing)\
**Post date:** [January 8, 2021, 12:02pm UTC](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539/1 "2021-01-08T12:02:41Z")

</div>

**Connect to elasticsearch(open kerberos )，The authentication fails, when elasticsearch responds with 401(Negotiate), nothing happens,Normal logic should go to kdc to request processing**

Why doesn't filebeat request kerberos kdc in response to 401?

Successfully access elasticsearch,kibanan (open kerberos) from the browser

Access to elasticsearch in curl is also successful

Version: filebeat 7.10.1 elasticsearch 7.10.1 kibanan 7.10.1  
Operating System: centos7  
Discuss Forum URL:  
Steps to Reproduce:

debug log

2021-01-08T15:29:45.251+0800 INFO eslegclient/connection.go:99 elasticsearch url: [https://192.168.174.1:9200](https://192.168.174.1:9200)  
2021-01-08T15:29:45.253+0800 INFO eslegclient/connection.go:159 kerberos client created

2021-01-08T15:29:55.436+0800 ERROR [publisher\_pipeline\_output] pipeline/output.go:154 Failed to connect to backoff(elasticsearch([https://192.168.174.1:9200](https://192.168.174.1:9200))): 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm="security" charset="UTF-8"","Negotiate","Bearer realm="security"","ApiKey"]}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":["Basic realm="security" charset="UTF-8"","Negotiate","Bearer realm="security"","ApiKey"]}},"status":401}

filebeat.yml

output.elasticsearch:  
hosts: ["192.168.174.133:9200"]  
protocol: "https"  
kerberos.enabled: true  
kerberos.auth\_type: keytab  
kerberos.keytab: /etc/elastic.keytab  
kerberos.config\_path: /etc/krb5.conf  
kerberos.username: elastic  
kerberos.realm: [EXAMPLE.COM](http://EXAMPLE.COM)  
ssl.certificate\_authorities: ["/etc/filebeat/elasticsearch-ca.pem"]

elasticsearch config

xpack.security.enabled: true  
xpack.security.audit.enabled: true  
xpack.security.transport.ssl.enabled: true

xpack.security.http.ssl.enabled: true  
xpack.security.http.ssl.keystore.path: "http.p12"  
xpack.security.authc.token.enabled: true

http.cors.enabled: true  
http.cors.allow-origin: "\*"  
http.cors.allow-headers: Authorization

xpack.security.authc.realms.kerberos.kerb1:  
order: 1  
keytab.path: es24.keytab  
remove\_realm\_name: false  
krb.debug: true

krb5.conf  
includedir /etc/krb5.conf.d/

[logging]  
default = FILE:/var/log/krb5libs.log  
kdc = FILE:/var/log/krb5kdc.log  
admin\_server = FILE:/var/log/kadmind.log

[libdefaults]  
dns\_lookup\_realm = false  
ticket\_lifetime = 24h  
renew\_lifetime = 7d  
forwardable = true  
rdns = false  
pkinit\_anchors = FILE:/etc/pki/tls/certs/ca-bundle.crt  
default\_realm = [EXAMPLE.COM](http://EXAMPLE.COM)  
default\_ccache\_name = KEYRING:persistent:%{uid}

[realms]  
[EXAMPLE.COM](http://EXAMPLE.COM) = {  
kdc = 192.168.174.132  
admin\_server = 192.168.174.132  
default\_domain = [example.com](http://example.com)  
}

[domain\_realm]  
.example.com = [EXAMPLE.COM](http://EXAMPLE.COM)  
[example.com](http://example.com) = [EXAMPLE.COM](http://EXAMPLE.COM)

kdc.conf

[kdcdefaults]  
kdc\_ports = 88  
kdc\_tcp\_ports = 88

[realms]  
[EXAMPLE.COM](http://EXAMPLE.COM) = {  
acl\_file = /var/kerberos/krb5kdc/kadm5.acl  
dict\_file = /usr/share/dict/words  
admin\_keytab = /var/kerberos/krb5kdc/kadm5.keytab  
supported\_enctypes = aes256-cts:normal aes128-cts:normal des3-hmac-sha1:normal arcfour-hmac:normal camellia256-cts:normal camellia128-cts:normal des-hmac-sha1:normal des-cbc-md5:normal des-cbc-crc:normal  
}

---

<div class="post-metadata">

**Author:** ![jing](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jing/32/81927_2.png) [@jing](https://discuss.elastic.co/u/jing)\
**Post date:** [January 9, 2021, 8:21am UTC](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539/2 "2021-01-09T08:21:16Z")

</div>

Can you give me some suggestions and opinions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2021, 10:21am UTC](https://discuss.elastic.co/t/filebeat-output-to-elasticsearch-open-kerberos-publisher-pipeline-output-www-authenticate-negotiate-401-no-processing/260539/3 "2021-02-06T10:21:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
