# Help: Metricbeat to elasticsearch using ipv6

**URL:** <https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [December 10, 2019, 8:27pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373 "2019-12-10T20:27:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![briank5400](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/briank5400/32/59155_2.png) [@briank5400](https://discuss.elastic.co/u/briank5400)\
**Post date:** [December 10, 2019, 8:27pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/1 "2019-12-10T20:27:49Z")

</div>

I have elasticsearch/Kibana setup on another host and configured basic authentication. now I am trying to configure metricbeat to send some data (over ipv6) but I cant seem to figure out why its failing to authenticate when I try to run metricbeat setup. (ive tried both with and without using keystore). It works fine if I do a test curl -6 -u. e.g.  
root@10-245-76-9:/etc/metricbeat# curl -6 http://[2a00:47c0:511:1297:7aae:5e12:607f:7372]:9200 -u bk-test:Testing1234  
{  
"name" : "10-245-76-12",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "NOvxDXzaSVaOJynxfr8a6A",  
"version" : {  
"number" : "7.5.0",  
"build\_flavor" : "default",  
"build\_type" : "deb",  
"build\_hash" : "e9ccaed468e2fac2275a3761849cbee64b39519f",  
"build\_date" : "2019-11-26T01:06:52.518245Z",  
"build\_snapshot" : false,  
"lucene\_version" : "8.3.0",  
"minimum\_wire\_compatibility\_version" : "6.8.0",  
"minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
},  
"tagline" : "You Know, for Search"

root@10-245-76-9:/etc/metricbeat# metricbeat setup  
Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch http://[2a00:47c0:511:1297:7aae:5e12:607f:7372]:9200: 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication credentials for REST request [/]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}]

root@10-245-76-9:/etc/metricbeat# metricbeat test output  
elasticsearch: http://[2a00:47c0:511:1297:7aae:5e12:607f:7372]:9200...  
parse url... OK  
connection...  
parse host... ERROR address 2a00:47c0:511:1297:7aae:5e12:607f:7372:9200: too many colons in address

my metricbeat.yml has the following elements:  
#-------------------------- Elasticsearch output ------------------------------  
output.elasticsearch:

# Array of hosts to connect to.

hosts: ["http://[2a00:47c0:511:1297:7aae:5e12:607f:7372]:9200"]

# Optional protocol and basic auth credentials.

#protocol: "https"  
username: "bk-test"  
password: "${bk-test}"

any advise?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 11, 2019, 9:08am UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/2 "2019-12-11T09:08:35Z")

</div>

Hey!

could you try with `https://...` and see if this changes anything?

> <https://github.com/elastic/beats/blob/3bb845f50ed3ae76a1e7a5bb67f3d451fbd705f6/metricbeat/metricbeat.reference.yml#L1089>

Thanks!

---

<div class="post-metadata">

**Author:** ![briank5400](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/briank5400/32/59155_2.png) [@briank5400](https://discuss.elastic.co/u/briank5400)\
**Post date:** [December 11, 2019, 10:36am UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/3 "2019-12-11T10:36:07Z")

</div>

Hi, I tried to make it https but still the same error.

metricbeat test output  
elasticsearch: https://[2a00:47c0:511:1297:7aae:5e12:607f:7372]:9200...  
parse url... OK  
connection...  
parse host... ERROR address 2a00:47c0:511:1297:7aae:5e12:607f:7372:9200: too many colons in address

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 11, 2019, 3:56pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/4 "2019-12-11T15:56:24Z")

</div>

I think that the command is `test output` is buggy here since it removes `[` from the address. I will check it further.

However did you try with `metricbeat setup` or `metricbeat -e -d "*"`? This is irrelevant to `test output`.

---

<div class="post-metadata">

**Author:** ![briank5400](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/briank5400/32/59155_2.png) [@briank5400](https://discuss.elastic.co/u/briank5400)\
**Post date:** [December 13, 2019, 10:56am UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/5 "2019-12-13T10:56:46Z")

</div>

Thanks Chris. Yes looks broken. separate from this I have found an issue with the formatting in my .yml file (usuername/password in the wrong column). So metricbeat is now running (despite the output error msg). regards, Brian.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 13, 2019, 1:06pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/6 "2019-12-13T13:06:48Z")

</div>

Good to know!

Here is the Github issue for reference: [https://github.com/elastic/beats/issues/15078](https://github.com/elastic/beats/issues/15078)

Regards!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 1:07pm UTC](https://discuss.elastic.co/t/help-metricbeat-to-elasticsearch-using-ipv6/211373/7 "2020-01-10T13:07:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
