# Filebeat setup fails to authenticate against Kibana

**URL:** <https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 19, 2021, 11:05am UTC](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800 "2021-03-19T11:05:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sonoroot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sonoroot/32/85799_2.png) [@sonoroot](https://discuss.elastic.co/u/sonoroot)\
**Post date:** [March 19, 2021, 11:05am UTC](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800/1 "2021-03-19T11:05:04Z")

</div>

Hello!

I am setting up a PoC for ECK.

Kibana is exposed as a Kubernetes Ingress (nginx-controller) on port 80, and I can successfully access via web browser (using the credentials `elastic` and the password dynamically created).

### kibana-ingress.yml

```auto
apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
  name: kibana
  annotations:
    kubernetes.io/ingress.class: nginx
spec:
 rules:
 - host: kibana.mydomain.something
   http:
     paths:
     - path: /
       backend:
         serviceName: elasticsearch-sample-kb-http
         servicePort: 5601

```

However when I execute `filebeat setup -e` on a client (with a filebeat.yml setup with the relevant authentication and endpoint listening on port 80), it fails when attempting to authenticate against Kibana (but does not fail when authenticating against Elastic):

```auto
2021-03-19T10:41:12.121Z	INFO	kibana/client.go:119	Kibana url: http://kibana.elastic-mydomain.something:80
2021-03-19T10:41:12.142Z	ERROR	instance/beat.go:971	Exiting: 1 error: error loading index pattern: parsing kibana respo </html>nter>nginx/1.17.8</center>o Large</h1></center>d>. Response: <html>
Exiting: 1 error: error loading index pattern: parsing kibana response: invalid character '<' looking for beginning of value. Respo </html>nter>nginx/1.17.8</center>o Large</h1></center>d>

```

It looks like the Kubernetes Ingress needs some tweaking? Possibly filebeat is not expecting HTML...

If anyone has any idea or tip that would be appreciated,  
Thanks!

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [March 22, 2021, 9:32am UTC](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800/2 "2021-03-22T09:32:46Z")

</div>

Hi!

It looks like it fails to parse nginx's response? Does Filebeat actually sends the request to Kibana? What are your Kibana host settings in Filebeat's documentation?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 11:33am UTC](https://discuss.elastic.co/t/filebeat-setup-fails-to-authenticate-against-kibana/267800/3 "2021-04-19T11:33:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
