# Kibana Report Error: Failed to decrypt report job data

**URL:** <https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657>\
**Category:** Kibana\
**Created:** [June 11, 2021, 8:16am UTC](https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657 "2021-06-11T08:16:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [June 11, 2021, 8:16am UTC](https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657/1 "2021-06-11T08:16:05Z")

</div>

Hi there,

I am facing following error each time I want to generate a CSV Report from Kibana Discover Module.

Either immediately or after some time (like 30 seconds or so) I see following Error:

```auto
Error: Failed to decrypt report job data. Please ensure that xpack.reporting.encryptionKey is set and re-generate this report. Error: Unsupported state or unable to authenticate data

```

I am running kibana 7.6.2 on openshift. I have used the elastic helm chart for deploying that and I have set following configuration lines in my kibana.yaml

```auto
xpack.reporting.encryptionKey: ${KIBANA_ENCRYPTION_KEY}
xpack.reporting.csv.maxSizeBytes: 104857600

```

`KIBANA_ENCRYPTION_KEY` is mounted as secret into the container

I am thankful for any hint

thanks.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [June 14, 2021, 3:18pm UTC](https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657/2 "2021-06-14T15:18:31Z")

</div>

I'm not really confident the encryption\_key can be used with Openshift secrets. Do they work the same as environment variables? if they don't, i doubt it would work like that. The suggested method if you want it as a secure setting is to use the kibana-keystore.

---

<div class="post-metadata">

**Author:** ![Kosodrom](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kosodrom/32/99278_2.png) [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Post date:** [June 15, 2021, 10:56am UTC](https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657/3 "2021-06-15T10:56:05Z")

</div>

Yes this works actually for example for the password of the kibana user.

In the deployed container one can check the ../config/kibana.yaml file and you can acutally see the passwords in clear text there so they are resolved correctly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2021, 10:56am UTC](https://discuss.elastic.co/t/kibana-report-error-failed-to-decrypt-report-job-data/275657/4 "2021-07-13T10:56:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
