# Got response code '403' contacting Elasticsearch at URL

**URL:** <https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [January 17, 2023, 10:18pm UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368 "2023-01-17T22:18:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 17, 2023, 10:18pm UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/1 "2023-01-17T22:18:21Z")

</div>

Hello World!

I'm trying to follow [Configuring Security in Logstash | Logstash Reference [7.17] | Elastic](https://www.elastic.co/guide/en/logstash/7.17/ls-security.html#ls-http-auth-basic), specifically these:

- Configuring Logstash to use Basic Authentication
- Granting Users Access to the Logstash Indices

yet when I start Logstash instance, I get the following error:

```auto
logstash | [2023-01-17T21:58:00,448][INFO][logstash.outputs.elasticsearch][gelf] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://elasticsearch:9200"]}
logstash | [2023-01-17T21:58:00,497][INFO][logstash.outputs.elasticsearch][gelf] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://logstash_user:xxxxxx@elasticsearch:9200/]}}
logstash | [2023-01-17T21:58:00,669][WARN][logstash.outputs.elasticsearch][gelf] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"http://logstash_user:xxxxxx@elasticsearch:9200/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '403' contacting Elasticsearch at URL 'http://elasticsearch:9200/'"}

```

the actual username is working fine:

```auto
% curl --silent --request GET "http://logstash_user:XYZ@elasticsearch:9200/_security/_authenticate?pretty"
{
  "username" : "logstash_user",
  "roles" : [
    "logstash_reader",
    "logstash_admin"
  ],
  "full_name" : "",
  "email" : "",
  "metadata" : { },
  "enabled" : true,
  "authentication_realm" : {
    "name" : "basic1",
    "type" : "native"
  },
  "lookup_realm" : {
    "name" : "basic1",
    "type" : "native"
  },
  "authentication_type" : "realm"
}
%

```

Please advise.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2023, 1:41am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/2 "2023-01-18T01:41:53Z")

</div>

It'd be useful if you could show us your Logstash config 🙂

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 18, 2023, 1:50am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/3 "2023-01-18T01:50:04Z")

</div>

you're absolutely right! and i should have included that with my initial question)

```auto
# docker exec -it logstash bash
logstash@b84ec064ef9a:~$ cat config/logstash.yml
http.host: 0.0.0.0
node.name: logstash
xpack.management.elasticsearch.hosts:
- http://elasticsearch:9200
xpack.management.elasticsearch.password: changeme
xpack.management.elasticsearch.username: elastic
xpack.management.enabled: true
xpack.management.pipeline.id:
- gelf
xpack.monitoring.elasticsearch.hosts:
- http://elasticsearch:9200
xpack.monitoring.elasticsearch.password: changeme
xpack.monitoring.elasticsearch.username: elastic
xpack.monitoring.enabled: false
logstash@b84ec064ef9a:~$

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2023, 2:00am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/4 "2023-01-18T02:00:35Z")

</div>

What about the config file where you are using those credentials?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [January 18, 2023, 2:27am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/5 "2023-01-18T02:27:40Z")

</div>

actually... i believe i have found an actual issue) and that is: i have granted `logstash_user` only `logstash_reader` role and not `logstash_writer`, and as soon as i added `logstash_writer` role, the error went away)

asking me about the config file where i have those credentials)))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2023, 2:28am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368/6 "2023-02-15T02:28:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
