# Getting 401 Unauthorized with Elasticsearch module

**URL:** <https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 4, 2020, 2:56pm UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737 "2020-08-04T14:56:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![scriptdb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scriptdb/32/73318_2.png) [@scriptdb](https://discuss.elastic.co/u/scriptdb)\
**Post date:** [August 4, 2020, 2:56pm UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737/1 "2020-08-04T14:56:23Z")

</div>

Hi,

I'm using metricbeat 7.6.2 and trying to get elasticsearch metrics (with module).

```
- module: elasticsearch
  metricsets:
    - node
  period: 10s
  enabled: true
  hosts: ["http://internal:8081"]
  basepath: "/es/"
  headers:
    Authorization: ApiKey 123

```

In the log I'm seeing:

`error determining if connected Elasticsearch node is master: HTTP error 401 in : 401 Unauthorized`

When doing tcp dumps I see that there are two calls made to ES, one uses basepath and one doesn't:

```
GET /es/_nodes/_local HTTP/1.1
Host: internal:8081
User-Agent: Go-http-client/1.1
Authorization: ApiKey 123
Accept-Encoding: gzip

HTTP/1.1 200 OK
Content-Type: application/json; charset=UTF-8
Date: Tue, 04 Aug 2020 14:13:59 GMT
Server: nginx/1.14.0 (Ubuntu)
Content-Length: 17895
Connection: keep-alive

```

* * *

```
GET / HTTP/1.1
Host: internal:8081
User-Agent: Go-http-client/1.1
Authorization: ApiKey 123
Accept-Encoding: gzip

HTTP/1.1 401 Unauthorized
cache-control: no-cache
Content-Type: application/json; charset=utf-8
Date: Tue, 04 Aug 2020 14:13:59 GMT
kbn-license-sig: 40be531c422af7b7f068375b33133576e80275fb59e312e0a9f7c246484f331a
kbn-name: ip-10-0-1-14
kbn-xpack-sig: aa0ee91c5d21b37ab2fb620970c860bb
Server: nginx/1.14.0 (Ubuntu)
Content-Length: 66
Connection: keep-alive

```

Does anyone know what is the second call (GET / ) and why it doesn't use the "/es/" basepath as the first one?

Thanks!

---

<div class="post-metadata">

**Author:** ![scriptdb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scriptdb/32/73318_2.png) [@scriptdb](https://discuss.elastic.co/u/scriptdb)\
**Post date:** [August 9, 2020, 7:22am UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737/2 "2020-08-09T07:22:37Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 10, 2020, 3:31pm UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737/3 "2020-08-10T15:31:25Z")

</div>

Could you please share your full configuration formatted using `</>` and debug logs of Metricbeat?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 5:31pm UTC](https://discuss.elastic.co/t/getting-401-unauthorized-with-elasticsearch-module/243737/4 "2020-09-07T17:31:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
