# Logstash error 403 with a remote elasticsearch instance

**URL:** <https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161>\
**Category:** Logstash\
**Created:** [October 7, 2021, 8:35pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161 "2021-10-07T20:35:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [October 7, 2021, 8:35pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161/1 "2021-10-07T20:35:27Z")

</div>

Hi,

I have a logstash config which works fine with my local Elasticsearch instance but when i try to push to a remote instance config gives error at startup as follows:

Using default mapping template  
[2021-10-07T13:17:25,981][INFO][logstash.outputs.Elasticsearch][main] Attempting to install template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}  
[2021-10-07T13:17:26,028][WARN][org.logstash.instrument.metrics.gauge.LazyDelegatingGauge][main] A gauge metric of an unknown type (org.jruby.specialized.RubyArrayOneObject) has been created for key: cluster\_uuids. This may result in invalid serialization. It is recommended to log an issue to the responsible developer/development team.  
[2021-10-07T13:17:26,028][INFO][logstash.javapipeline][main] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>12, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50, "pipeline.max\_inflight"=\>1500, "pipeline.sources"=\>["C:/logstash-7.6.2/config/logstash-grok.conf"], :thread=\>"#\<Thread:0x59254081 run\>"}  
**[2021-10-07T13:17:26,075][ERROR][logstash.outputs.Elasticsearch][main] Failed to install template. {:message=\>"Got response code '403' contacting Elasticsearch at URL '[https://mysite.com:443/\_template/logstash](https://mysite.com:443/_template/logstash)'",** :class=\>"LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError", :backtrace=\>["C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-Elasticsearch-10.3.3-java/lib/logstash/outputs/Elasticsearch/http\_client/manticore\_adapter.rb:80:in `perform_request'", "C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:332:in `perform\_request\_to\_url'", "C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-Elasticsearch-10.3.3-java/lib/logstash/outputs/Elasticsearch/http\_client/pool.rb:319:in `block in perform_request'", "C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:414:in `with\_connection'", "C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-Elasticsearch-10.3.3-java/lib/logstash/outputs/Elasticsearch/http\_client/pool.rb:318:in `perform_request'", "C:/logstash-7.6.2/vendor/bundle/jruby/2.5.0/gems/logstash-output-elasticsearch-10.3.3-java/lib/logstash/outputs/elasticsearch/http_client/pool.rb:326:in `block in Pool'",

I have default template settings.

My input looks like this

```auto
input { 
	beats {
		port => 5044
	}
}

filter {
### I have tried with the simplest filter too
}

output {
   elasticsearch {
         hosts => ["https://mysite.com:443"]
         user => "logstash_user"
         password => "myp@ssword"
         index => "offline-%{[name]}-%{[logtype]}-%{+YYYY.MM.dd}"
		 document_id => "%{[@metadata][fingerprint]}"
      }
}

```

Please share what is wrong here?

Thanks

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 7, 2021, 10:17pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161/2 "2021-10-07T22:17:27Z")

</div>

> [@Indigo\_Star](#):
>
> [2021-10-07T13:17:26,075][ERROR][logstash.outputs.Elasticsearch][main] Failed to install template. {:message=\>"Got response code '403' contacting Elasticsearch at URL '[https://mysite.com:443/\_template/logstash](https://mysite.com:443/_template/logstash)'",

Usually means access to a resource is being denied.... is the user allowed to create, edit the template if it exists ?

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [October 7, 2021, 10:37pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161/3 "2021-10-07T22:37:59Z")

</div>

> [@zx8086](#):
>
> Usually means access to a resource is being denied.... is the user allowed to create, edit the template if it exists ?

Thanks @zx8086, for your response, Can you please tell how can i find it out?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 7, 2021, 10:42pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161/4 "2021-10-07T22:42:13Z")

</div>

> [@Indigo\_Star](#):
>
> ```auto
> user => "logstash_user"
> password => "myp@ssword"
> index => "offline-%{[name]}-%{[logtype]}-%{+YYYY.MM.dd}"
> 
> ```

Does the specified User & Password have permission to write to the index specified.

> **[Secure your connection to Elasticsearch | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/ls-security.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2021, 10:42pm UTC](https://discuss.elastic.co/t/logstash-error-403-with-a-remote-elasticsearch-instance/286161/5 "2021-11-04T22:42:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
