# Kibana error: Unable to retrieve version information from Elasticsearch nodes. socket hang up

**URL:** <https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [November 8, 2022, 10:52am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421 "2022-11-08T10:52:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![grigoryevandrey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grigoryevandrey/32/113083_2.png) [@grigoryevandrey](https://discuss.elastic.co/u/grigoryevandrey)\
**Post date:** [November 8, 2022, 10:52am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421/1 "2022-11-08T10:52:41Z")

</div>

I am getting this error inside the kibana container, therefore ingress returns 503 error and container is never ready.

When i am doing curl to elasticsearch from inside the kibana container, it successfully returns a response.

**Chart version:** 7.17.3

Values for elasticsearch chart:

```auto
clusterName: "elasticsearch"
nodeGroup: "master"

createCert: false

roles:
  master: "true"
  data: "true"
  ingest: "true"
  ml: "true"
  transform: "true"
  remote_cluster_client: "true"

protocol: https

replicas: 2

sysctlVmMaxMapCount: 262144

readinessProbe:
   failureThreshold: 3
   initialDelaySeconds: 90
   periodSeconds: 10
   successThreshold: 1
   timeoutSeconds: 10

imageTag: "7.17.3"

extraEnvs:
- name: ELASTIC_PASSWORD
  valueFrom:
    secretKeyRef:
      name: elasticsearch-creds
      key: password
- name: ELASTIC_USERNAME
  valueFrom:
    secretKeyRef:
      name: elasticsearch-creds
      key: username

clusterHealthCheckParams: "wait_for_status=green&timeout=20s"

antiAffinity: "soft"

resources:
  requests:
    cpu: "100m"
    memory: "1Gi"
  limits:
    cpu: "1000m"
    memory: "1Gi"

esJavaOpts: "-Xms512m -Xmx512m"

volumeClaimTemplate:
  accessModes: ["ReadWriteOnce"]
  resources:
    requests:
      storage: 30Gi

esConfig:
  elasticsearch.yml: |
    xpack.security.enabled: true
    xpack.security.transport.ssl.enabled: true
    xpack.security.transport.ssl.verification_mode: certificate
    xpack.security.transport.ssl.client_authentication: required
    xpack.security.transport.ssl.keystore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.transport.ssl.truststore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.http.ssl.enabled: true
    xpack.security.http.ssl.truststore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12
    xpack.security.http.ssl.keystore.path: /usr/share/elasticsearch/config/certs/elastic-certificates.p12

secretMounts:
  - name: elastic-certificates
    secretName: elastic-certificates
    path: /usr/share/elasticsearch/config/certs

```

Values for kibana chart:

```auto
elasticSearchHosts: "https://elasticsearch-master:9200"

extraEnvs:
  - name: ELASTICSEARCH_USERNAME
    valueFrom:
      secretKeyRef:
        name: elasticsearch-creds
        key: username
  - name: ELASTICSEARCH_PASSWORD
    valueFrom:
      secretKeyRef:
        name: elasticsearch-creds
        key: password
  - name: KIBANA_ENCRYPTION_KEY
    valueFrom:
      secretKeyRef:
        name: encryption-key  
        key: encryption_key

kibanaConfig:
  kibana.yml: |
    server.ssl:
      enabled: true
      key: /usr/share/kibana/config/certs/elastic-certificate.pem
      certificate: /usr/share/kibana/config/certs/elastic-certificate.pem
    xpack.security.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
    elasticsearch.ssl:
      certificateAuthorities: /usr/share/kibana/config/certs/elastic-certificate.pem
      verificationMode: certificate
    
protocol: https

secretMounts:
  - name: elastic-certificate-pem
    secretName: elastic-certificate-pem
    path: /usr/share/kibana/config/certs

imageTag: "7.17.3"

ingress:
  enabled: true
  ingressClassName: nginx
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-issuer
    kubernetes.io/ingress.allow-http: 'false'
  paths:
    - path: /
      pathType: Prefix
      backend:
        serviceName: kibana
        servicePort: 5601
  hosts:
    - host: mydomain.com
      paths:
        - path: /
          pathType: Prefix
          backend:
            serviceName: kibana
            servicePort: 5601
  tls:
    - hosts:
        - mydomain.com
      secretName: mydomain.com

```

---

<div class="post-metadata">

**Author:** ![grigoryevandrey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grigoryevandrey/32/113083_2.png) [@grigoryevandrey](https://discuss.elastic.co/u/grigoryevandrey)\
**Post date:** [November 9, 2022, 8:40am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421/2 "2022-11-09T08:40:18Z")

</div>

UPD: tried it with other image version (8.4.1), nothing has changed, i am getting the same error. By the way, logstash is successfully shipping logs to this elasticsearch instance, so i think problem is in kibana.

---

<div class="post-metadata">

**Author:** ![grigoryevandrey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grigoryevandrey/32/113083_2.png) [@grigoryevandrey](https://discuss.elastic.co/u/grigoryevandrey)\
**Post date:** [November 14, 2022, 8:50pm UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421/3 "2022-11-14T20:50:47Z")

</div>

Figured it out. It was a complete pain. I hope these tips will help others:

1. `xpack.security.http.ssl.enabled` should be set to false. I can't find another way around it, but if you do i'd be glad to hear any advices. As i see it, you don't need security for http layer since kibana connects to elastic via transport layer (correct me if i am wrong). Therefore `xpack.security.transport.ssl.enabled` should be still set to true, but `xpack.security.http.ssl.enabled` should be set to false. (don't forget to change your `protocol` field for readinessProbe to http, and also change protocol for elasticsearch in kibana chart to http.
2. `ELASTIC_USERNAME` env variable is pointless in elasticsearch chart, only password is used, user is always `elastic`
3. `ELASTICSEARCH_USERNAME` in kibana chart should be actually set to `kibana_systems` user with according password for that user

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 15, 2022, 6:07am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421/4 "2022-11-15T06:07:31Z")

</div>

Welcome to our community! 😃

Hopefully someone with ECK experience can jump in here, but I did want to comment on this;

> [@grigoryevandrey](#):
>
> As i see it, you don't need security for http layer since kibana connects to elastic via transport layer (correct me if i am wrong

Kibana uses the HTTP API.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2022, 6:07am UTC](https://discuss.elastic.co/t/kibana-error-unable-to-retrieve-version-information-from-elasticsearch-nodes-socket-hang-up/318421/5 "2022-12-13T06:07:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
