# Logstash elasticsearch filter plugin 401 error

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328>\
**Category:** Logstash\
**Created:** [October 13, 2019, 2:38am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328 "2019-10-13T02:38:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [October 13, 2019, 2:38am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328/1 "2019-10-13T02:38:17Z")

</div>

Hello Team,

We are trying to use elasticsearch filter plugin,But we are getting 401 unauthorised error.  
Since our elasticsearch is secured , In elasticsearch output section we have configured SSL, cacert, keystore, and keystore pasdeord, However, we couldn't find the keystore, keystore password options in filter. We don't have Basic Auth so we cannot use user and password paraters.

Could you please help us understand how can we authenticate and use elasticsearch filter plugin,with security enabled for elasticsearch.

Thank you for your help and support.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 13, 2019, 4:27am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328/2 "2019-10-13T04:27:04Z")

</div>

How have you secured the cluster if you do not have basic auth? As far as I know the Elasticsearch filter only supports basic auth although you might be able to use a proxy.

---

<div class="post-metadata">

**Author:** ![adityaPsl](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Post date:** [October 15, 2019, 12:58pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328/3 "2019-10-15T12:58:55Z")

</div>

Hello Christian,  
Thank you for your reply.

ELK version : 7.2.0

We tried to create new user with all privileges and Tried setting user and password I. Logstash. However we are getting 403 forbidden error.

Found similar issue : [Logstash - Elasticsearch filter plugin with basic authentication](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473)

Any pointers to resolve the issue are really appreciated.

Thank you for your help and support.

Thank you,  
Aditya

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2019, 12:59pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-401-error/203328/4 "2019-11-12T12:59:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
