# Got response code '403' contacting Elasticsearch at URL 'http://localhost:9200/

**URL:** <https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [June 24, 2022, 2:56am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067 "2022-06-24T02:56:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulohperes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulohperes/32/107556_2.png) [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Post date:** [June 24, 2022, 2:56am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067/1 "2022-06-24T02:56:50Z")

</div>

Hi,

My pipeline not working with ouput elasticsearch, I created user and role like this:

```auto
root@logserver:/home/g0004830# curl -k -u admin:my_password -XGET "http://localhost:9200/_security/user/syslog?pretty" 
{
  "syslog" : {
    "username" : "syslog",
    "roles" : [
      "syslog"
    ],
    "full_name" : null,
    "email" : null,
    "metadata" : { },
    "enabled" : true
  }
}
root@logserver:/home/g0004830# curl -k -u admin:my_password -XGET "http://localhost:9200/_security/role/syslog?pretty" 
{
  "syslog" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "syslog-*"
        ],
        "privileges" : [
          "read",
          "write"
        ],
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

And my output config:

```auto
output {
    stdout {
        codec => rubydebug        
    }

	elasticsearch {
        user => "syslog"
        password => "my_password" 
        hosts => ["http://localhost:9200/"]
		index => "syslog-%{+YYYY-MM-dd}"        
	}
	
}

```

When I run logstash I receive this error:

`[WARN] 2022-06-23 23:48:20.422 [Ruby-0-Thread-9: :1] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://syslog:xxxxxx@localhost:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '403' contacting Elasticsearch at URL 'http://localhost:9200/'"}`

How can I solve this?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 27, 2022, 12:21am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067/2 "2022-06-27T00:21:00Z")

</div>

Can you confirm a curl directly to Elasticsearch with your `syslog` users works?

---

<div class="post-metadata">

**Author:** ![paulohperes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulohperes/32/107556_2.png) [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Post date:** [June 27, 2022, 4:04am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067/3 "2022-06-27T04:04:38Z")

</div>

Hi,

with curl that's work.

```auto
g0004830@logserver:~/logstatsh$ curl -u syslog:mypassword -XPOST "http://localhost:9200/syslog-2022-06-27/_doc" -H "Content-Type: application/json" -d @ingest.json
{"_index":"syslog-2022-06-27","_id":"s9xSo4EBMMASQROr_aWn","_version":1,"result":"created","_shards":{"total":2,"successful":1,"failed":0},"_seq_no":0,"_primary_term":1}g0004830@logserver:~/logstatsh$ 
g0004830@logserver:~/logstatsh$ 
g0004830@logserver:~/logstatsh$ cat ingest.json 
      {
          "type" : "HL4",
          "vendor" : "Nokia",
          "tags" : [],
          "message" : "TMNX: 861880 Base PPPOE-WARNING-tmnxPppoeSessionFailure-2001 [PPPoE session failure]: PPPoE session failure on SAP lag-1:102.* in service 410 - [f4:54:20:c3:0f:31,1,cliente@cliente] Authentication failed\n",
          "@version" : "1",
          "hostname" : "i-br-mg-ssp-p14-hl4-01",
          "model" : "SR7750",
          "@timestamp" : "2022-06-27T19:29:11.680371Z",
          "ip" : "10.113.150.4"
        }

g0004830@logserver:~/logstatsh$

```

I changed logstash pipeline to using admin user and works..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2022, 4:05am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067/4 "2022-07-25T04:05:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
