# "license","warning","xpack"

**URL:** <https://discuss.elastic.co/t/license-warning-xpack/192600>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [July 29, 2019, 3:53am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600 "2019-07-29T03:53:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![flyboyacsrao](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@flyboyacsrao](https://discuss.elastic.co/u/flyboyacsrao)\
**Post date:** [July 29, 2019, 3:53am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/1 "2019-07-29T03:53:38Z")

</div>

Hi Team

I installed Elasticsearch 6.8 and kibana 6.8, with basic license, for some time both were working find. now i am unable to get my Kibana working, though the ES is green and i can see all my app logs being pumped to ES with auth enabled...

My kibana log says:  
{"type":"log","@timestamp":"2019-07-29T03:41:39Z","tags":["license","warning","xpack"],"pid":28265,"message":"License information from the X-Pack plugin could not be obtained from Elasticsearch for the [data] cluster. Error: Request Timeout after 30000ms"}  
{"type":"log","@timestamp":"2019-07-29T03:42:09Z","tags":["warning","task\_manager"],"pid":28265,"message":"PollError Request Timeout after 30000ms"}  
{"type":"log","@timestamp":"2019-07-29T03:42:39Z","tags":["license","warning","xpack"],"pid":28265,"message":"License information from the X-Pack plugin could not be obtained from Elasticsearch for the [data] cluster. Error: Request Timeout after 30000ms"}  
{"type":"log","@timestamp":"2019-07-29T03:42:42Z","tags":["warning","task\_manager"],"pid":28265,"message":"PollError Request Timeout after 30000ms"}

My kibana yml:

elasticsearch.url: "[http://x.x.x.x:9200](http://x.x.x.x:9200)"  
server.host: "x.x.x.x"

elasticsearch.username: "kibana"  
elasticsearch.password: "xxxxxx"

xpack.security.enabled: true  
xpack.graph.enabled: false  
xpack.ml.enabled: false  
xpack.monitoring.enabled: true  
xpack.watcher.enabled: false  
xpack.ccr.enabled: false

My elasticsearch yml:

cluster.name: "xxxxxxxxxxxxxxxxxxxxx"  
node.name: ${HOSTNAME}  
node.master: true  
node.data: false  
cluster.routing.allocation.awareness.force.zone.values: 1A, 1B  
cluster.routing.allocation.awareness.attributes: zone  
node.attr.zone: 1A  
discovery.zen.ping.unicast.hosts: ["xxxxx", "xxxxxx", "xxxxx"]  
path.data: /esdata/data/  
path.logs: /esdata/logs/  
network.host: x.x.x.x  
discovery.zen.minimum\_master\_nodes: 2  
http.port: 9200  
gateway.recover\_after\_nodes: 1  
bootstrap.system\_call\_filter: false

xpack.security.enabled: true  
xpack.security.authc.accept\_default\_password: true  
xpack.security.transport.ssl.enabled: true  
xpack.security.transport.ssl.verification\_mode: certificate  
xpack.security.transport.ssl.keystore.path: /etc/elasticsearch/elastic-certificates.p12  
xpack.security.transport.ssl.truststore.path: /etc/elasticsearch/elastic-certificates.p12

My License details:  
{  
"license" : {  
"status" : "active",  
"uid" : "d7d4d0ce-9d8d-402d-92c4-2093691bf643",  
"type" : "basic",  
"issue\_date" : "2019-05-28T05:28:48.078Z",  
"issue\_date\_in\_millis" : 1559021328078,  
"max\_nodes" : 1000,  
"issued\_to" : "IMIConnect-Prod-Imonitor-Cluster",  
"issuer" : "elasticsearch",  
"start\_date\_in\_millis" : -1  
}  
}

My x-pack status:

{  
"build" : {  
"hash" : "65b6179",  
"date" : "2019-05-15T20:07:59.571448Z"  
},  
"license" : {  
"uid" : "d7d4d0ce-9d8d-402d-92c4-2093691bf643",  
"type" : "basic",  
"mode" : "basic",  
"status" : "active"  
},  
"features" : {  
"ccr" : {  
"description" : "Cross Cluster Replication",  
"available" : false,  
"enabled" : true  
},  
"graph" : {  
"description" : "Graph Data Exploration for the Elastic Stack",  
"available" : false,  
"enabled" : true  
},  
"ilm" : {  
"description" : "Index lifecycle management for the Elastic Stack",  
"available" : true,  
"enabled" : true  
},  
"logstash" : {  
"description" : "Logstash management component for X-Pack",  
"available" : false,  
"enabled" : true  
},  
"ml" : {  
"description" : "Machine Learning for the Elastic Stack",  
"available" : false,  
"enabled" : true,  
"native\_code\_info" : {  
"version" : "6.8.0",  
"build\_hash" : "e6cf25e2acc5ec"  
}  
},  
"monitoring" : {  
"description" : "Monitoring for the Elastic Stack",  
"available" : true,  
"enabled" : true  
},  
"rollup" : {  
"description" : "Time series pre-aggregation and rollup",  
"available" : true,  
"enabled" : true  
},  
"security" : {  
"description" : "Security for the Elastic Stack",  
"available" : true,  
"enabled" : true  
},  
"sql" : {  
"description" : "SQL access to Elasticsearch",  
"available" : true,  
"enabled" : true  
},  
"watcher" : {  
"description" : "Alerting, Notification and Automation for the Elastic Stack",  
"available" : false,  
"enabled" : true  
}  
},  
"tagline" : "You know, for X"

Can some help me on this please

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 29, 2019, 4:35am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/2 "2019-07-29T04:35:38Z")

</div>

I have moved this to the Kibana topic.

> [@flyboyacsrao](#):
>
> Error: Request Timeout after 30000ms

Your problem does not appear to have anything to do with security or licensing. Your Kibana server cannot connect to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![flyboyacsrao](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@flyboyacsrao](https://discuss.elastic.co/u/flyboyacsrao)\
**Post date:** [July 29, 2019, 4:43am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/3 "2019-07-29T04:43:57Z")

</div>

Thanks Tim,

My cluster is hosted in AWS Cloud, its a three node cluster with two nodes as data & master, while the other node is dedicated master.

i have installed the kibana server in my master only node.,  
I do see that the kibana is running when i checked the status from with in the server..

but when when i call the kibana server via browser,  
it says kibana server is not ready..

"Kibana server is not ready yet"

but my cluster is green and indices are good and i can do a curl from the master node to other nodes..

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 29, 2019, 5:48am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/4 "2019-07-29T05:48:28Z")

</div>

From what you've written above, this is expected behaviour.

Kibana cannot connect to Elasticsearch, so it is not possible to access Kibana.

What we need to diagnose is why you are getting timeouts from Kibana to Elasticsearch when curl is working.

I would start by double checking that you can run curl from the kibana user, using exactly the same settings as in your `kibana.yml` (same url, same username, same password).

---

<div class="post-metadata">

**Author:** ![flyboyacsrao](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@flyboyacsrao](https://discuss.elastic.co/u/flyboyacsrao)\
**Post date:** [July 29, 2019, 6:11am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/5 "2019-07-29T06:11:48Z")

</div>

Hi Tim

I Tried, and its working fine..

[root@ip-172-16-190-20 ~]# curl -XGET "[http://kibana:xxxxxx@x.x.x.x:9200/\_cluster/health](http://kibana:xxxxxx@x.x.x.x:9200/_cluster/health)"?pretty  
{  
"cluster\_name" : "xxxxxxxxxxxxxxxxxxxxxxxxxx",  
"status" : "green",  
"timed\_out" : false,  
"number\_of\_nodes" : 3,  
"number\_of\_data\_nodes" : 2,  
"active\_primary\_shards" : 299,  
"active\_shards" : 594,  
"relocating\_shards" : 0,  
"initializing\_shards" : 0,  
"unassigned\_shards" : 0,  
"delayed\_unassigned\_shards" : 0,  
"number\_of\_pending\_tasks" : 0,  
"number\_of\_in\_flight\_fetch" : 0,  
"task\_max\_waiting\_in\_queue\_millis" : 0,  
"active\_shards\_percent\_as\_number" : 100.0

We are using a load balancer over the data nodes..,  
but when i try to connect curl through load balancer..

[root@ip-172-16-190-20 ~]# curl -XGET "[http://kibana](http://kibana):xxxxxxx  
@imonitor-datanode.imiconnect.net:9200/\_cluster/health"?pretty  
curl: (7) Failed to connect to [imonitor-datanode.imiconnect.net](http://imonitor-datanode.imiconnect.net) port 9200: Connection timed out

Now i removed calling via load balancer and used the data node ip as URL..

when i restarted kibana...i get this error:

{"type":"log","@timestamp":"2019-07-29T06:07:53Z","tags":["error","task\_manager"],"pid":10914,"message":"Failed to poll for work: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)]; :: {"path":"/.kibana\_task\_manager/\_doc/oss\_telemetry-vis\_telemetry/\_update","query":{"if\_seq\_no":84,"if\_primary\_term":6,"refresh":"true"},"body":"{\"doc\":{\"type\":\"task\",\"task\":{\"taskType\":\"vis\_telemetry\",\"state\":\"{\\\"runs\\\":9,\\\"stats\\\":{\\\"markdown\\\":{\\\"total\\\":1,\\\"spaces\_min\\\":1,\\\"spaces\_max\\\":1,\\\"spaces\_avg\\\":1},\\\"table\\\":{\\\"total\\\":10,\\\"spaces\_min\\\":10,\\\"spaces\_max\\\":10,\\\"spaces\_avg\\\":10},\\\"metric\\\":{\\\"total\\\":7,\\\"spaces\_min\\\":7,\\\"spaces\_max\\\":7,\\\"spaces\_avg\\\":7},\\\"histogram\\\":{\\\"total\\\":3,\\\"spaces\_min\\\":3,\\\"spaces\_max\\\":3,\\\"spaces\_avg\\\":3}}}\",\"params\":\"{}\",\"attempts\":0,\"scheduledAt\":\"2019-07-16T03:14:57.700Z\",\"runAt\":\"2019-07-29T06:12:53.760Z\",\"status\":\"running\"},\"kibana\":{\"uuid\":\"e7d14ee1-da18-4a35-8603-e088a5e7f45c\",\"version\":6080099,\"apiVersion\":1}}}","statusCode":403,"response":"{\"error\":{\"root\_cause\":[{\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"}],\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"},\"status\":403}"}"}  
{"type":"log","@timestamp":"2019-07-29T06:07:55Z","tags":["security","error"],"pid":10914,"message":"Error registering Kibana Privileges with Elasticsearch for kibana-.kibana: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];, with { suppressed={ 0={ type="cluster\_block\_exception" & reason="blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];" } & 1={ type="cluster\_block\_exception" & reason="blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];" } & 2={ type="cluster\_block\_exception" & reason="blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];" } } }"}  
{"type":"log","@timestamp":"2019-07-29T06:07:56Z","tags":["error","task\_manager"],"pid":10914,"message":"Failed to poll for work: [cluster\_block\_exception] blocked by: [FORBIDDEN/12/index read-only / allow delete (api)]; :: {"path":"/.kibana\_task\_manager/\_doc/oss\_telemetry-vis\_telemetry/\_update","query":{"if\_seq\_no":84,"if\_primary\_term":6,"refresh":"true"},"body":"{\"doc\":{\"type\":\"task\",\"task\":{\"taskType\":\"vis\_telemetry\",\"state\":\"{\\\"runs\\\":9,\\\"stats\\\":{\\\"markdown\\\":{\\\"total\\\":1,\\\"spaces\_min\\\":1,\\\"spaces\_max\\\":1,\\\"spaces\_avg\\\":1},\\\"table\\\":{\\\"total\\\":10,\\\"spaces\_min\\\":10,\\\"spaces\_max\\\":10,\\\"spaces\_avg\\\":10},\\\"metric\\\":{\\\"total\\\":7,\\\"spaces\_min\\\":7,\\\"spaces\_max\\\":7,\\\"spaces\_avg\\\":7},\\\"histogram\\\":{\\\"total\\\":3,\\\"spaces\_min\\\":3,\\\"spaces\_max\\\":3,\\\"spaces\_avg\\\":3}}}\",\"params\":\"{}\",\"attempts\":0,\"scheduledAt\":\"2019-07-16T03:14:57.700Z\",\"runAt\":\"2019-07-29T06:12:56.801Z\",\"status\":\"running\"},\"kibana\":{\"uuid\":\"e7d14ee1-da18-4a35-8603-e088a5e7f45c\",\"version\":6080099,\"apiVersion\":1}}}","statusCode":403,"response":"{\"error\":{\"root\_cause\":[{\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"}],\"type\":\"cluster\_block\_exception\",\"reason\":\"blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];\"},\"status\":403}"}"}

My node allocation is  
[root@ip-172-16-190-20 ~]# curl -XGET "[http://kibana:xxxxxxxxx@172.16.190.20:9200/\_cat/allocation](http://kibana:xxxxxxxxx@172.16.190.20:9200/_cat/allocation)"?v  
shards disk.indices disk.used disk.avail disk.total disk.percent host ip node  
298 146.8gb 164.9gb 334.8gb 499.7gb 32 172.16.190.89 172.16.190.89 ip-172-16-190-89.eu-west-1.compute.internal  
298 146.5gb 164.9gb 334.7gb 499.7gb 33 172.16.190.23 172.16.190.23 ip-172-16-190-23.eu-west-1.compute.internal

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 29, 2019, 7:57am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/6 "2019-07-29T07:57:31Z")

</div>

Are you running out of disk space for Elasticsearch?

---

<div class="post-metadata">

**Author:** ![flyboyacsrao](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@flyboyacsrao](https://discuss.elastic.co/u/flyboyacsrao)\
**Post date:** [July 29, 2019, 9:09am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/7 "2019-07-29T09:09:44Z")

</div>

Hi Christian

We ran out of disk but than i cleaned up data via curl and as given in the earlier reply i do see that my disks are only 35% used.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 29, 2019, 9:30am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/8 "2019-07-29T09:30:55Z")

</div>

Then you need to remove the index block. Search for watermark in the docs for an example.

---

<div class="post-metadata">

**Author:** ![flyboyacsrao](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@flyboyacsrao](https://discuss.elastic.co/u/flyboyacsrao)\
**Post date:** [July 29, 2019, 11:11am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/9 "2019-07-29T11:11:49Z")

</div>

Thanks Christian and Tim

There seemed to be an issue with the aws load balancer, when we changed the Elasticsearch url to data node IP and set the curl -XPUT '[http://kibana:xxxxxxxx@x.x.x.x:9200/\_settings](http://kibana:xxxxxxxx@x.x.x.x:9200/_settings) {"index": { "blocks": { "read\_only\_allow\_delete": "false" }}}'

then restarted Kibana., this solved the problem

Thanks for the wounderful guidance from Tim and Christian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2019, 11:11am UTC](https://discuss.elastic.co/t/license-warning-xpack/192600/10 "2019-08-26T11:11:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
