# Https endpoint for LB healthcheck

**URL:** <https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641>\
**Category:** Kibana\
**Created:** [November 21, 2018, 7:43am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641 "2018-11-21T07:43:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ronchav](https://avatars.discourse-cdn.com/v4/letter/r/35a633/32.png) [@ronchav](https://discuss.elastic.co/u/ronchav)\
**Post date:** [November 21, 2018, 7:43am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/1 "2018-11-21T07:43:34Z")

</div>

Hi,

What is the recommended api endpoint in Kibana for my LB to conduc healthcheck at defined interval via https connection?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [November 22, 2018, 11:28am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/2 "2018-11-22T11:28:51Z")

</div>

You can use the /api/status endpoint and look for the overall state to be green.

---

<div class="post-metadata">

**Author:** ![ronchav](https://avatars.discourse-cdn.com/v4/letter/r/35a633/32.png) [@ronchav](https://discuss.elastic.co/u/ronchav)\
**Post date:** [November 29, 2018, 6:27am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/3 "2018-11-29T06:27:40Z")

</div>

Thanks, we will try this. Health check will be conducted by load balancer, so it will wait for 200 response code if it is up to validate that the packet can be forwarded to kibana host.

---

<div class="post-metadata">

**Author:** ![ronchav](https://avatars.discourse-cdn.com/v4/letter/r/35a633/32.png) [@ronchav](https://discuss.elastic.co/u/ronchav)\
**Post date:** [December 4, 2018, 6:50am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/4 "2018-12-04T06:50:00Z")

</div>

@Marius_Dragomir, our load balancer will access kibana /api/status over ssl.

How can LB access it without providing username and password? or if there is any best practice to encrypt it and pull that credential during healthcheck?

curl -I --cacert ./certs/ca.crt '[https://kibana:5601/api/status](https://kibana:5601/api/status)'  
HTTP/1.1 401 Unauthorized

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [December 4, 2018, 3:16pm UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/5 "2018-12-04T15:16:01Z")

</div>

passing the username and password is the easiest way. you could set up a an user with no role assigned: this way he will have no permission to do or modify anything, and it still has access to the status API.

---

<div class="post-metadata">

**Author:** ![ronchav](https://avatars.discourse-cdn.com/v4/letter/r/35a633/32.png) [@ronchav](https://discuss.elastic.co/u/ronchav)\
**Post date:** [December 5, 2018, 4:00am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/6 "2018-12-05T04:00:01Z")

</div>

I tried it but didn't work. I am testing it at 6.5 version. I even escalated it to superuser role... With the reserve role (kibana), it is working fine. with the custom role, it didn't work. I am sure my password is correct because I logged in to kibana using that account.

bash-4.2$ curl -I -u kibana:###### --cacert ./ca.crt '[https://kibana.local:5601/api/status](https://kibana.local:5601/api/status)'  
HTTP/1.1 200 OK  
kbn-name: kibana  
kbn-xpack-sig: 32a2457688f21bd7fbb13c6cefbb1447  
content-type: application/json; charset=utf-8  
set-cookie: sid=Fe26.2 **06dc603ec054ffdcb8893ea07bd43019f6d59e13cab87bd2cec52cea4826b7ec_8f3jO7GK53sI15EK04kj2Q_Wt5YgypubItbKLEFqTFD8zRpmNqxWT7ie5qG5nwGZkcwdlMlfp4GSM5RNRaDb7E\_IyhTb3SVbfb93FQ-220aYapCrSfX0kbktpI1-f4X1GssbpSKEEt5M\_McyTluYHNsvh-QTFyAO8tgDIxGoQRR6w** 813928d7d71e5c63b0768d977a318be67eee5b722c33e47526760812f6553074\*tvb0WwIWWOYNWTHyiV58WXzlFGOKrGmKcjTT6poLYeU; Secure; HttpOnly; Path=/  
cache-control: no-cache  
connection: close  
Date: Wed, 05 Dec 2018 03:39:10 GMT

bash-4.2$ curl -I -u f5lb:###### --cacert ./ca.crt '[https://kibana.local:5601/api/status](https://kibana.local:5601/api/status)'  
HTTP/1.1 401 Unauthorized  
WWW-Authenticate: Bearer realm="security"  
WWW-Authenticate: Basic realm="security" charset="UTF-8"  
kbn-name: kibana  
kbn-xpack-sig: 32a2457688f21bd7fbb13c6cefbb1447  
content-type: application/json; charset=utf-8  
cache-control: no-cache  
connection: close  
Date: Wed, 05 Dec 2018 03:39:15 GMT

 ![f5lb_user](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7dab101ed4984125ba9c927c4482b7af897995a.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2019, 4:15am UTC](https://discuss.elastic.co/t/https-endpoint-for-lb-healthcheck/157641/7 "2019-01-02T04:15:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
