# Logstash 401 Error

**URL:** <https://discuss.elastic.co/t/logstash-401-error/234029>\
**Category:** Logstash\
**Created:** [May 24, 2020, 6:24am UTC](https://discuss.elastic.co/t/logstash-401-error/234029 "2020-05-24T06:24:43Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 24, 2020, 6:24am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/1 "2020-05-24T06:24:43Z")

</div>

Hello,

I have followed the steps in the below doc to enable security ;

> **[Secure Elasticsearch with TLS encryption and role-based access control](https://www.elastic.co/blog/getting-started-with-elasticsearch-security)**
>
> Secure your Elasticsearch clusters -- and the other components of the Elastic Stack -- with node-to-node TLS and role-based access control (RBAC). These features and more are now available free with the default distribution of Elasticsearch and...

Everything seems to have worked. HOwever, when I start logstash, i get the below error :

[2020-05-24T02:16:15,655][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

[2020-05-24T02:16:15,669][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

[2020-05-24T02:16:15,683][WARN][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

I have not made any changes to logstash.yml file.

Could you please let me know what am I missing here ?

When I try to connect directly, it seems to be working.

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/3274e6bc19216de13a4ee5b6933876e14e0c0161.png)

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 24, 2020, 8:13am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/2 "2020-05-24T08:13:50Z")

</div>

I configured the logstash\_internal user and now I see the below error during the start up of logstash :

[2020-05-24T03:48:58,345][INFO][logstash.outputs.elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1, "index.lifecycle.name"=\>"logstash-policy", "index.lifecycle.rollover\_alias"=\>"logstash"}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
warning: thread "Ruby-0-Thread-12: :1" terminated with exception (report\_on\_exception is true):  
LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError: Got response code '403' contacting Elasticsearch at URL '[http://localhost:9200/logstash](http://localhost:9200/logstash)'  
perform\_request at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/manticore\_adapter.rb:80  
perform\_request\_to\_url at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:332  
perform\_request at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:319  
with\_connection at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:414  
perform\_request at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:318  
Pool at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:326  
exists? at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client.rb:341  
rollover\_alias\_exists? at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http\_client.rb:359  
maybe\_create\_rollover\_alias at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/ilm.rb:91  
setup\_ilm at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/ilm.rb:10  
setup\_after\_successful\_connection at /elk/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/common.rb:54

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 24, 2020, 8:40am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/3 "2020-05-24T08:40:01Z")

</div>

> [@vikramaddagulla](#):
>
> r: Got response code '403' contacting Elasticsearch at URL '[http://localhost:9200/logstash](http://localhost:9200/logstash)'

Same issue was reported in : [LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError: Got response code '403' contacting Elasticsearch at URL 'http://localhost:9200/logstash'](https://discuss.elastic.co/t/logstash-got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200-logstash/194951)

That post got auto closed,,,

Any suggestions please ?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 24, 2020, 9:50am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/4 "2020-05-24T09:50:40Z")

</div>

401 is authentication error, while 403 is authorization error

> [@vikramaddagulla](#):
>
> logstash.outputs.elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash- _", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1, "index.lifecycle.name"=\>"logstash-policy", "index.lifecycle.rollover\_alias"=\>"logstash"}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_ ", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
> warning: thread "Ruby-0-Thread-12: :1" terminated with exception (report\_on\_exception is true):  
> LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError: Got response code '403' contacting

your logstash\_user is trying to install template in elasticsearch but it doesn’t seem to have privileges to do so. what’s your logstash\_user privileges that you configure ? you will need manage\_index\_templates on cluster level to manage index templates.

further info on securing logstash - ES [here](https://www.elastic.co/guide/en/logstash/current/ls-security.html)

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 25, 2020, 6:46am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/5 "2020-05-25T06:46:58Z")

</div>

Hello

Thanks for your reply.

I have actually followed the same document.

I had created the user logstash\_internal and configured that in the output section of the logstash conf file as below :

elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> "logstash\_internal"  
password =\> "PASSWORD"  
index =\> "adminaccesslogsindex"  
}  
stdout { codec =\> rubydebug }  
}

With the above settings, I was receiving the 403 error.

However, i changed the above setting to elastic user ( which is a super user ) and then everything was working fine.

With this, I am under an assumption that the user logstash\_internal is missing some privileges to create connections to elasticsearch.

How can I know what is missing??

I had followed the steps provided at : [https://www.elastic.co/guide/en/logstash/current/ls-security.html](https://www.elastic.co/guide/en/logstash/current/ls-security.html)

Created the role : `logstash_writer`  
For **cluster** privileges, i have added `manage_index_templates` and `monitor` .  
For **indices** privileges, I have added `write` , `create` , `delete` , and `create_index`

Created logstash\_internal user and assigned the role logstash\_writer to that user.

Then created a role logstash\_reader  
The role has access to : `read` and `view_index_metadata` privileges for the Logstash indices

Assigned that role to logstash\_internal

Yet I get 403 error.

Any comments on what could be wrong ??

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 25, 2020, 7:15am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/6 "2020-05-25T07:15:12Z")

</div>

From the Logstash error, it seems you're getting a 403 error because Logstash tries to install an index template.

Did you grant the permissions to install index templates?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 25, 2020, 7:17am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/7 "2020-05-25T07:17:39Z")

</div>

> [@vikramaddagulla](#):
>
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> user =\> "logstash\_internal"  
> password =\> "PASSWORD"  
> index =\> "adminaccesslogsindex"  
> }

you defined the index name as “adminaccesslogindex”. does logstash\_writer has privileges to that index?

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 25, 2020, 7:40am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/8 "2020-05-25T07:40:11Z")

</div>

I have assigned logstash\_reader and logstash\_writer role to the user logstash\_internal

Below are the screenshot of the roles configured.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3df8e1d0604f5871fb8272b62d540a8d49fd5114.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1d238857b1021593efc23248f0c7e7a1aea957d6.png)

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 25, 2020, 7:41am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/9 "2020-05-25T07:41:00Z")

</div>

I have uploaded the screenshot of the roles which are assigned to the logstash\_internal user.

Can you please check that and let me know if I am missing it ?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 25, 2020, 8:02am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/10 "2020-05-25T08:02:46Z")

</div>

can you add the logstash\* to the list of indices the logstash writer role has privileges to?

---

<div class="post-metadata">

**Author:** ![vikramaddagulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikramaddagulla/32/139858_2.png) [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Post date:** [May 29, 2020, 2:15am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/11 "2020-05-29T02:15:40Z")

</div>

I will try it out during the weekend and let you know...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2020, 2:15am UTC](https://discuss.elastic.co/t/logstash-401-error/234029/12 "2020-06-26T02:15:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
