# Kibana 401 Unauthorized

**URL:** <https://discuss.elastic.co/t/kibana-401-unauthorized/303954>\
**Category:** Kibana\
**Created:** [May 4, 2022, 2:35pm UTC](https://discuss.elastic.co/t/kibana-401-unauthorized/303954 "2022-05-04T14:35:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CemG](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CemG](https://discuss.elastic.co/u/CemG)\
**Post date:** [May 4, 2022, 2:35pm UTC](https://discuss.elastic.co/t/kibana-401-unauthorized/303954/1 "2022-05-04T14:35:37Z")

</div>

Hello,  
I would like to setup the dashboard of Winlogbeat in Kibana, but when I start Winlogbeat I have an error.  
I have done a curl, and saw that I got the error 401 as response.  
My architecture is : Winlogbeat → Kafka → Logstash → Elastic  
Here is **winlogbeat.yml**

```auto
# ======= Winlogbeat specific options ========

winlogbeat.event_logs:
  - name: Application
    ignore_older: 72h

  - name: System

  - name: Security

  - name: Microsoft-Windows-Sysmon/Operational

  - name: Windows PowerShell
    event_id: 400, 403, 600, 800

  - name: Microsoft-Windows-PowerShell/Operational
    event_id: 4103, 4104, 4105, 4106

  - name: ForwardedEvents
    tags: [forwarded]

setup.dashboards.enabled: true
setup.dashboards.url: "http://10.60.101.10:5601/"

setup.kibana:
  host: "http://10.60.101.10:5601"
  username: "elastic"
  password: "Yrl1d4Q_SQ3k3aX4EseO"

# ---------------------------- Kafka Output ----------------------------
output.kafka:
  codec.format:
    string: '%{[@timestamp]}%{[message]}'
  hosts: ["10.60.101.11:9092"]
  topic: 'windows'
  partition.round_robin:
    reachable_only: false
  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000

# =============== Processors ========
processors:
  - add_host_metadata:
      when.not.contains.tags: forwarded
  - add_cloud_metadata: ~

# ============ Winlogbeat Logs =============
logging.to_files: true
logging.files:
  path: C:\Program Files\Winlogbeat\Logs
logging.level: info

```

If you need more information do not hesitate  
Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2022, 10:38pm UTC](https://discuss.elastic.co/t/kibana-401-unauthorized/303954/2 "2022-05-04T22:38:17Z")

</div>

> [@CemG](#):
>
> ```auto
> setup.kibana:
> host: "http://10.60.101.10:5601"
> username: "elastic"
> password: "Yrl1d4Q_SQ3k3aX4EseO"
> 
> ```

You're getting a 401 when you use those details in your curl?

---

<div class="post-metadata">

**Author:** ![CemG](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CemG](https://discuss.elastic.co/u/CemG)\
**Post date:** [May 5, 2022, 7:12am UTC](https://discuss.elastic.co/t/kibana-401-unauthorized/303954/3 "2022-05-05T07:12:50Z")

</div>

When I do a curl with the following command

```auto
curl -u elastic http://10.60.101.10:5601/api/status

```

I get all information I need, but I don't know why it do not work with Winlogbeat

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 7:13am UTC](https://discuss.elastic.co/t/kibana-401-unauthorized/303954/4 "2022-06-02T07:13:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
