# Kibana 7.7.0 Basic version: management tab missing Security panel when started from docker

**URL:** <https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [May 19, 2020, 8:56pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412 "2020-05-19T20:56:21Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 19, 2020, 8:56pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/1 "2020-05-19T20:56:21Z")

</div>

I can't find Security under Kibana 7.7 when I pull it from docker instead of downloading and installing manually Kibana. I posted same question in ([https://stackoverflow.com/questions/61900546/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-f](https://stackoverflow.com/questions/61900546/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-f)) with all details

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 19, 2020, 9:11pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/2 "2020-05-19T21:11:29Z")

</div>

Can you please check the output of `GET _license`?

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 2:12pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/3 "2020-05-20T14:12:19Z")

</div>

Here you are:

{  
"license" : {  
"status" : "active",  
"uid" : "01574148-3044-47d4-8d9e-6ac06615c7a5",  
"type" : "basic",  
"issue\_date" : "2020-05-19T19:29:41.432Z",  
"issue\_date\_in\_millis" : 1589916581432,  
"max\_nodes" : 1000,  
"issued\_to" : "docker-cluster",  
"issuer" : "elasticsearch",  
"start\_date\_in\_millis" : -1  
}  
}

How do you figure out the version if it is Open Source or Basic from this response?  
Kindly, run your eyes on [https://stackoverflow.com/questions/61900546/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-f?noredirect=1#comment109487828\_61900546](https://stackoverflow.com/questions/61900546/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-f?noredirect=1#comment109487828_61900546). I added more details there. Basically, now I can see the Security panel after added xpack.monitoring.elasticsearch but LogStash is failling to connect to ElasticSearch with

`logstash_1 | [2020-05-20T13:39:08,008][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://elasticsearch:9200/]}} logstash_1 | [2020-05-20T13:39:08,408][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"http://elasticsearch:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://elasticsearch:9200/'"} logstash_1 | [2020-05-20T13:39:08,506][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=>"Got response code '401' contacting Elasticsearch at URL 'http://elasticsearch:9200/_xpack'"}`

Do you know how set LogStash instead of trying [http://elasticsearch:9200/\_xpack](http://elasticsearch:9200/_xpack) try [http://my.ip.address.number:9200/\_xpack](http://my.ip.address.number:9200/_xpack)? I changed logstash.conf to use x.x.x.x but it seems it didn't affect.

Here is the logstash.conf out

`output { elasticsearch { index => "%{[fields][topic_name]}-%{+YYYY.MM.dd}" xpack.monitoring.elasticsearch.hosts: ["http://192.168.99.100:9200"] xpack.monitoring.elasticsearch.username: "logstash_system" xpack.monitoring.elasticsearch.password: => "l12345" } }`

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 20, 2020, 2:27pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/4 "2020-05-20T14:27:24Z")

</div>

Thanks for the answer.

You have a basic license installed.  
The OSS distribution of Elasticsearch has no license endpoint, so you would not get an answer.

Logstash is rejecting because it gets a **401 error** , meaning the credentials you've providing on the X-Pack monitoring and/or on the Elasticsearch output of your pipeline are wrong.

I see you're mixing up the `logstash.yml` file and the pipeline file.

The `logstash.yml` file requires the following to send the monitoring stats (see [documentation](https://www.elastic.co/guide/en/logstash/current/monitoring-internal-collection-legacy.html)):

```auto
xpack.monitoring.elasticsearch.hosts: ["http://192.168.99.100:9200"] 
xpack.monitoring.elasticsearch.username: "logstash_system" 
xpack.monitoring.elasticsearch.password: => "l12345"

```

Then you have the actual Logstash pipeline, which should be similar to [the one in the documentation](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html), e.g.

```auto
... your pipeline with input, filters...

output {
  elasticsearch {
    index => "%{[fields][topic_name]}-%{+YYYY.MM.dd}"
    hosts => ["http://the-target-cluster-node-1:9200", "http://the-target-cluster-node-2:9200"]
    user => "a user which has the rights to write to indices named as all the possible values of `topic_name`"
    password => "the password"
  }
}

```

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 3:06pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/5 "2020-05-20T15:06:15Z")

</div>

Thank you so much. Please, how do I create "  
"a user which has the rights to write to indices named as all the possible values of `topic_name`"? I went to ...[:5601/app/kibana#/management/security/users](http://192.168.99.100:5601/app/kibana#/management/security/users) and try to create an User with such rights and I didn't find how. I went also to ... :5601/app/kibana#/management/security/roles and I didn't find some role to write to "indices named as all the possible values of `topic_name`". I read the whole documentation it suggested and I didn't find the answer (I guess it is obvious for someone with more experience). Please, just give me the first steps

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 3:13pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/6 "2020-05-20T15:13:28Z")

</div>

I guess I have to pick up

indexwrite

below. But what do I type in Index box? Well, there is no index at all yet since LogStash didn't connect and create the index.

 ![image.png](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32f5c1dbf79f4412d527b9f856272aea4ed09b1f.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 20, 2020, 3:54pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/7 "2020-05-20T15:54:45Z")

</div>

How many topic names do you have/expect to have? Do they follow a naming convention?

One way to handle this would be to give these indices a common prefix and create a role that can create and manage indices with that prefix.

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 5:56pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/8 "2020-05-20T17:56:33Z")

</div>

Christian, I will have two index prefixes. One is for request/response and other for java exceptions. Both will be pushed to Elastic throw FileBeat-\>Kafka-\>LogStash. My final goal is separate who can see the request/response dashboard from who can see java exceptions dashboard. In other words, separate Business viewers from Developers.

Here are my complete LogStash:

`  
xpack.monitoring.elasticsearch.hosts: ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: =\> "l12345"

input{  
kafka{  
codec =\> "json"  
bootstrap\_servers =\> "kafka1:9092"  
topics =\> ["app\_logs","request\_logs"]  
tags =\> ["my-app"]  
}  
}

filter {   
if [fields][topic\_name] == "app\_logs" {   
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} \*%{LOGLEVEL:level} %{DATA:pid} --- \*[%{DATA:application}] \*%{DATA:class} : %{GREEDYDATA:msglog}" }  
tag\_on\_failure =\> ["not\_date\_line"]  
}   
date {  
match =\> ["timestamp", "ISO8601"]  
target =\> "timestamp"  
}   
if "\_grokparsefailure" in [tags] {  
mutate {  
add\_field =\> { "level" =\> "UNKNOWN" }  
}  
}   
} else if [fields][topic\_name] == "request\_logs" {   
grok {  
match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} \*%{LOGLEVEL:level} %{GREEDYDATA:msglog}" }  
}   
date {  
match =\> ["timestamp", "ISO8601"]  
target =\> "timestamp"  
}   
json {  
source =\> "msglog"  
target =\> "parsed\_json"  
}   
if [level]=="INFO" or [level]=="WARN" {  
mutate {  
add\_field =\> {"appName" =\> "%{[parsed\_json][appName]}"}  
add\_field =\> {"logType" =\> "%{[parsed\_json][logType]}"}  
... several fields  
add\_field =\> {"src" =\> "%{[parsed\_json][src]}"}  
add\_field =\> {"transactionId" =\> "%{[parsed\_json][header][x-transaction-id]}"}  
remove\_field =\> ["json", "message"]  
remove\_field =\> ["json", "parsed\_json"]  
}  
} else {  
mutate {  
add\_field =\> {"msgerror" =\> "%{[parsed\_json][message]}"}  
remove\_field =\> ["json", "message"]  
remove\_field =\> ["json", "parsed\_json"]  
}  
}   
if [transactionId] == "%{[parsed\_json][header][x-transaction-id]}" {  
mutate {  
replace =\> ["transactionId","UNKNOWN"]  
}  
}  
mutate {  
convert =\> {"requestBytes" =\> "integer"}  
convert =\> {"responseTime" =\> "integer"}  
}   
if "\_grokparsefailure" in [tags] {  
mutate {  
add\_field =\> { "level" =\> "UNKNOWN" }  
}  
}   
}  
}

output {  
elasticsearch {  
hosts =\> ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
index =\> "%{[fields][topic\_name]}-%{+YYYY.MM.dd}"

}  
}`

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 5:59pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/9 "2020-05-20T17:59:44Z")

</div>

@Luca_Belluccini and @Christian_Dahlqvist, please, how create a role that can create and manage indices with certain prefix ?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 20, 2020, 7:59pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/10 "2020-05-20T19:59:05Z")

</div>

Just add the prefix in the Kibana UI with the prefix followed by `*`.

For the permissions, you might refer to [https://www.elastic.co/guide/en/logstash/current/ls-security.html](https://www.elastic.co/guide/en/logstash/current/ls-security.html)

I might invite you to prefix indices with `logstash-*` for easier maintainability.

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 10:31pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/11 "2020-05-20T22:31:33Z")

</div>

Luca, thanks. But I am still getting the same error.

I created the role bellow and created an user added to this role.

My logstash.conf out now is:

xpack.monitoring.elasticsearch.hosts: ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: =\> "l12345"

input{  
kafka{  
codec =\> "json"  
bootstrap\_servers =\> "kafka1:9092"  
topics =\> ["app\_logs","request\_logs"]  
tags =\> ["alcd"]  
}  
}

filter {  
\*\*\* removed  
}

output {  
elasticsearch {  
hosts =\> ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
index =\> "%{[fields][topic\_name]}-%{+YYYY.MM.dd}"  
user =\> "userlog"  
password =\> "userlog"  
}  
}

 ![image.png](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25f5d1ffb49f330222203c2f3d8b323c6fa57d76.png)

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 20, 2020, 11:08pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/12 "2020-05-20T23:08:46Z")

</div>

Any extra idea what I am missing? Any clue how to force logstash connect to an Ip Address (I mean instead of elastic:9200 be my.ip.address.x:9200)? I added a new and specific queston regard this issue in  
[https://stackoverflow.com/questions/61924438/logstash-unable-to-retrieve-license-information-from-license-response-code-401](https://stackoverflow.com/questions/61924438/logstash-unable-to-retrieve-license-information-from-license-response-code-401)

 ![image.png](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25f5d1ffb49f330222203c2f3d8b323c6fa57d76.png)

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 21, 2020, 6:55am UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/13 "2020-05-21T06:55:55Z")

</div>

You did not follow the instructions detailed at the point one of [https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic) as the role you've created is missing some cluster settings which are required.

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 21, 2020, 12:47pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/14 "2020-05-21T12:47:50Z")

</div>

Thanks Luca. You are right. I fixed it. But I am still getting same error. Do you know if there is some way to force LogStash to use an Ip Address instead of URL '[http://elasticsearch:9200/](http://elasticsearch:9200/)?

logstash\_1 | WARNING: All illegal access operations will be denied in a future release  
logstash\_1 | Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties  
logstash\_1 | [2020-05-21T12:41:12,468][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
logstash\_1 | [2020-05-21T12:41:12,488][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.7.0"}  
logstash\_1 | [2020-05-21T12:41:13,543][WARN][logstash.monitoringextension.pipelineregisterhook] xpack.monitoring.enabled has not been defined, but found elasticsearch configuration. Please explicitly set `xpack.monitoring.enabled: true` in logstash.yml  
logstash\_1 | [2020-05-21T12:41:13,548][WARN][deprecation.logstash.monitoringextension.pipelineregisterhook] Internal collectors option for Logstash monitoring is deprecated and targeted for removal in the next major version.  
logstash\_1 | Please configure Metricbeat to monitor Logstash. Documentation can be found at:  
logstash\_1 | [https://www.elastic.co/guide/en/logstash/current/monitoring-with-metricbeat.html](https://www.elastic.co/guide/en/logstash/current/monitoring-with-metricbeat.html)  
logstash\_1 | [2020-05-21T12:41:15,361][INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://elasticsearch:9200/]](http://elasticsearch:9200/%5D)}}  
logstash\_1 | [2020-05-21T12:41:15,763][WARN][logstash.licensechecker.licensereader] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://elasticsearch:9200/](http://elasticsearch:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://elasticsearch:9200/](http://elasticsearch:9200/)'"}  
logstash\_1 | [2020-05-21T12:41:15,861][ERROR][logstash.licensechecker.licensereader] Unable to retrieve license information from license server {:message=\>"Got response code '401' contacting Elasticsearch at URL '[http://elasticsearch:9200/\_xpack](http://elasticsearch:9200/_xpack)'"}  
logstash\_1 | [2020-05-21T12:41:15,939][ERROR][logstash.monitoring.internalpipelinesource] Failed to fetch X-Pack information from Elasticsearch. This is likely due to failure to reach a live Elasticsearch cluster.  
logstash\_1 | [2020-05-21T12:41:16,538][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "input", "filter", "output" at line 1, column 1 (byte 1)", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:58:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:66:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:28:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:27:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:181:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:67:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:43:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:342:in `block in converge\_state'"]}  
logstash\_1 | [2020-05-21T12:41:17,011][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
logstash\_1 | [2020-05-21T12:41:21,818][INFO][logstash.runner] Logstash shut down.  
dockercomposelogs\_logstash\_1 exited with code 1  
filebeat\_1 | 2020-05-21T12:40:54.126Z INFO log/harvester.go:324 File is inactive: /sample-logs/request-2019-10-24.log. Closing because close\_inactive of 5m0s reached.  
logstash\_1 | OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release.  
logstash\_1 | WARNING: An illegal reflective access operation has occurred  
logstash\_1 | WARNING: Illegal reflective access by com.headius.backport9.modules.Modules (file:/usr/share/logstash/logstash-core/lib/jars/jruby-complete-9.2.11.1.jar) to method sun.nio.ch.NativeThread.signal(long)  
logstash\_1 | WARNING: Please consider reporting this to the maintainers of com.headius.backport9.modules.Modules  
logstash\_1 | WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations

Here is my role updated

 ![image.png](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f34b1f26b9264510f89af64a2085d05003354bb.png)

And my logstash.conf out is:

output {  
elasticsearch {  
hosts =\> ["[http://192.168.99.100:9200](http://192.168.99.100:9200)"]  
#index =\> "%{[fields][topic\_name]}-%{+YYYY.MM.dd}"  
index =\> "logstash-{+YYYY.MM.dd}"  
user =\> "userlog"  
password =\> "userlog"  
}  
}

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 21, 2020, 3:43pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/15 "2020-05-21T15:43:18Z")

</div>

The error shows there is a syntax error in the Logstash pipeline.

The message just before also shows 401 meaning you have a wrong username or password.

Try to run the following commands and share the output:

```auto
curl http://192.168.99.100:9200/_license -u userlog:userlog -vvv

curl -X POST http://192.168.99.100:9200/logstash-test/_doc/1 -d'{"test":1}' -u userlog:userlog -vvv

```

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 21, 2020, 4:35pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/16 "2020-05-21T16:35:52Z")

</div>

C:\Users\mycomp\>curl [http://192.168.99.100:9200/\_license](http://192.168.99.100:9200/_license) -u userlog:userlog -vvv

- Trying 192.168.99.100...
- TCP\_NODELAY set
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> GET /\_license HTTP/1.1  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.55.1  
> Accept: _/_

\< HTTP/1.1 200 OK  
\< content-type: application/json; charset=UTF-8  
\< content-length: 338  
\<  
{  
"license" : {  
"status" : "active",  
"uid" : "01574148-3044-47d4-8d9e-6ac06615c7a5",  
"type" : "basic",  
"issue\_date" : "2020-05-19T19:29:41.432Z",  
"issue\_date\_in\_millis" : 1589916581432,  
"max\_nodes" : 1000,  
"issued\_to" : "docker-cluster",  
"issuer" : "elasticsearch",  
"start\_date\_in\_millis" : -1  
}  
}

- Connection #0 to host 192.168.99.100 left intact

C:\Users\mycomp\>curl -X POST [http://192.168.99.100:9200/logstash-test/\_doc/1](http://192.168.99.100:9200/logstash-test/_doc/1) -d'{"test":1}' -u userlog:userlog -vvv  
Note: Unnecessary use of -X or --request, POST is already inferred.

- Trying 192.168.99.100...
- TCP\_NODELAY set
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> POST /logstash-test/\_doc/1 HTTP/1.1  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.55.1  
> Accept: _/_  
> Content-Length: 10  
> Content-Type: application/x-www-form-urlencoded

- upload completely sent off: 10 out of 10 bytes  
\< HTTP/1.1 406 Not Acceptable  
\< content-type: application/json; charset=UTF-8  
\< content-length: 97  
\<  
{"error":"Content-Type header [application/x-www-form-urlencoded] is not supported","status":406}\* Connection #0 to host 192.168.99.100 left intact

C:\Users\mycomp\>

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 21, 2020, 4:38pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/17 "2020-05-21T16:38:35Z")

</div>

I tried also from inside Docker Logstash container and I got same exception from second command:

C:\Users\mycomp\>docker exec -it dockercomposelogs\_logstash\_1 bash  
bash-4.2$  
C:\Users\Cast\>docker exec -it dockercomposelogs\_logstash\_1 bash  
bash-4.2$ curl [http://192.168.99.100:9200/\_license](http://192.168.99.100:9200/_license) -u userlog:userlog -vvv

- About to connect() to 192.168.99.100 port 9200 (#0)
- Trying 192.168.99.100...
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> GET /\_license HTTP/1.1  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.29.0  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Accept: _/_

\< HTTP/1.1 200 OK  
\< content-type: application/json; charset=UTF-8  
\< content-length: 338  
\<  
{  
"license" : {  
"status" : "active",  
"uid" : "01574148-3044-47d4-8d9e-6ac06615c7a5",  
"type" : "basic",  
"issue\_date" : "2020-05-19T19:29:41.432Z",  
"issue\_date\_in\_millis" : 1589916581432,  
"max\_nodes" : 1000,  
"issued\_to" : "docker-cluster",  
"issuer" : "elasticsearch",  
"start\_date\_in\_millis" : -1  
}  
}

- Connection #0 to host 192.168.99.100 left intact  
bash-4.2$ curl -X POST [http://192.168.99.100:9200/logstash-test/\_doc/1](http://192.168.99.100:9200/logstash-test/_doc/1) -d'{"test":1}' -u userlog:userlog -vvv
- About to connect() to 192.168.99.100 port 9200 (#0)
- Trying 192.168.99.100...
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> POST /logstash-test/\_doc/1 HTTP/1.1  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.29.0  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Accept: _/_  
> Content-Length: 10  
> Content-Type: application/x-www-form-urlencoded

- upload completely sent off: 10 out of 10 bytes  
\< HTTP/1.1 406 Not Acceptable  
\< content-type: application/json; charset=UTF-8  
\< content-length: 97  
\<
- Connection #0 to host 192.168.99.100 left intact  
{"error":"Content-Type header [application/x-www-form-urlencoded] is not supported","status":406}bash-4.2$

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 21, 2020, 4:44pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/18 "2020-05-21T16:44:55Z")

</div>

I changed a bit your second command adding the header to application/json and I got  
mapper\_parsing\_exception but it seems it did connect successfully because I see

- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

curl -X POST -H "Content-Type: application/json" [http://192.168.99.100:9200/logstash-test/\_doc/1](http://192.168.99.100:9200/logstash-test/_doc/1) -d'{"test":1}' -u userlog:userlog -vvv  
Note: Unnecessary use of -X or --request, POST is already inferred.

- Trying 192.168.99.100...
- TCP\_NODELAY set
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> POST /logstash-test/\_doc/1 HTTP/1.1  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.55.1  
> Accept: _/_  
> Content-Type: application/json  
> Content-Length: 10

- upload completely sent off: 10 out of 10 bytes  
\< HTTP/1.1 400 Bad Request  
\< content-type: application/json; charset=UTF-8  
\< content-length: 313  
\<  
{"error":{"root\_cause":[{"type":"mapper\_parsing\_exception","reason":"failed to parse"}],"type":"mapper\_parsing\_exception","reason":"failed to parse","caused\_by":{"type":"not\_x\_content\_exception","reason":"Compressor detection can only be called on some xcontent bytes or compressed xcontent bytes"}},"status":400}\* Connection #0 to host 192.168.99.100 left intact

---

<div class="post-metadata">

**Author:** ![jimisdrpc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimisdrpc/32/47451_2.png) [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Post date:** [May 21, 2020, 4:53pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/19 "2020-05-21T16:53:37Z")

</div>

It seems the mapper exception is regard Windows format flavour on command line. I tried from inside Docker Logstash since it is linux and I got a different error.

Does "...  
blocked by: [TOO\_MANY\_REQUESTS/12/index read-only / allow delete (api)];"},"status":429 ..." ring a bell in your mind?

> docker exec -it dockercomposelogs\_logstash\_1 bash  
> bash-4.2$ curl -X POST -H "Content-Type: application/json" [http://192.168.99.100:9200/logstash-test/\_doc/1](http://192.168.99.100:9200/logstash-test/_doc/1) -d'{"test":1}' -u userlog:userlog -vvv

- About to connect() to 192.168.99.100 port 9200 (#0)
- Trying 192.168.99.100...
- Connected to 192.168.99.100 (192.168.99.100) port 9200 (#0)
- Server auth using Basic with user 'userlog'

> POST /logstash-test/\_doc/1 HTTP/1.1  
> Authorization: Basic dXNlcmxvZzp1c2VybG9n  
> User-Agent: curl/7.29.0  
> Host: [192.168.99.100:9200](http://192.168.99.100:9200)  
> Accept: _/_  
> Content-Type: application/json  
> Content-Length: 10

- upload completely sent off: 10 out of 10 bytes  
\< HTTP/1.1 429 Too Many Requests  
\< content-type: application/json; charset=UTF-8  
\< content-length: 319  
\<
- Connection #0 to host 192.168.99.100 left intact  
{"error":{"root\_cause":[{"type":"cluster\_block\_exception","reason":"index [logstash-test] blocked by: [TOO\_MANY\_REQUESTS/12/index read-only / allow delete (api)];"}],"type":"cluster\_block\_exception","reason":"index [logstash-test] blocked by: [TOO\_MANY\_REQUESTS/12/index read-only / allow delete (api)];"},"status":429}bash-4.2$

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 21, 2020, 5:07pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412/20 "2020-05-21T17:07:13Z")

</div>

Given the last response it seems your cluster has no more disk space: the disk flooding stage (95% disk full) kicked in and sets the indices in read only.

[Next page](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412.md?page=2)
