# Logstash error : Got response code '401' contacting Elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792>\
**Category:** Elasticsearch\
**Created:** [February 21, 2018, 9:17am UTC](https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792 "2018-02-21T09:17:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryext](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@ryext](https://discuss.elastic.co/u/ryext)\
**Post date:** [February 21, 2018, 9:17am UTC](https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792/1 "2018-02-21T09:17:24Z")

</div>

Hey,  
so here is my issue:  
I installed x-pack on elastiic kibana ana logstash  
the connection kibana elastic works fine.  
unfortunatly logstash-elasticsearch in not flowing smoothly.  
here is the error u am getting:

> :url=\>"[http://localhost:9200/](http://localhost:9200/)", :error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

i created a user and a role here are the settings

> {  
> "logstash\_writter" : {  
> "cluster" : [  
> "manage\_index\_templates",  
> "monitor"  
> ],  
> "indices" : [  
> {  
> "names" : [  
> "winlogbeat-\*"  
> ],  
> "privileges" : [  
> "write",  
> "delete",  
> "create\_index"  
> ]  
> }  
> ],  
> "run\_as" : ,  
> "metadata" : { },  
> "transient\_metadata" : {  
> "enabled" : true  
> }  
> }  
> }

and user:

> {  
> "logstash\_internal" : {  
> "username" : "logstash\_internal",  
> "roles" : [  
> "logstash\_writter"  
> ],  
> "full\_name" : "Internal Logstash User",  
> "email" : null,  
> "metadata" : { },  
> "enabled" : true  
> }  
> }

for my config file:

> input {  
> beats {  
> port =\> 5140  
> }  
> }  
> output{  
> elasticsearch{  
> hosts =\> ["localhost:9200"]  
> sniffing =\> false  
> index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
> user =\> logstash\_internal  
> password =\> logstash  
> }  
> syslog{  
> host =\> "192.168.0.5"  
> port =\> 514  
> }  
> }

and i added those lines at the end of my logstash.yml:

> xpack.monitoring.enabled: true  
> xpack.monitoring.elasticsearch.username: logsash\_system  
> xpack.monitoring.elasticsearch.password: logstash

Am i missing something?  
i'm running all that on a Centos7 latest version 6.2 of elastic.

i have been stuck on that for 3 days now i even freshly reinstalled ELK.

Thank you

---

<div class="post-metadata">

**Author:** ![ryext](https://avatars.discourse-cdn.com/v4/letter/r/a9a28c/32.png) [@ryext](https://discuss.elastic.co/u/ryext)\
**Post date:** [February 21, 2018, 10:05am UTC](https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792/2 "2018-02-21T10:05:49Z")

</div>

By the way forgot to mention i can log in to elasticsearch on browser unsig the logstash\_internal user

---

<div class="post-metadata">

**Author:** ![pereyrdi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pereyrdi/32/12480_2.png) [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Post date:** [March 13, 2018, 7:55pm UTC](https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792/3 "2018-03-13T19:55:41Z")

</div>

In logstash.yml, say  
xpack.monitoring.elasticsearch.username: **logsash\_system** , it must be logstash\_system  
maybe is that

good luck

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 7:55pm UTC](https://discuss.elastic.co/t/logstash-error-got-response-code-401-contacting-elasticsearch/120792/4 "2018-04-10T19:55:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
