# Logstash security\_exception, can't write to ES after installing X-pack

**URL:** <https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973>\
**Category:** Logstash\
**Created:** [June 12, 2017, 4:23am UTC](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973 "2017-06-12T04:23:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [June 12, 2017, 4:23am UTC](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973/1 "2017-06-12T04:23:48Z")

</div>

As the title says, after installing X-pack logstash can't seem to authenticate with ES.

`[2017-06-12T13:08:28,307][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>401, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}"}
[2017-06-12T13:08:31,009][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>401, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}"}
[2017-06-12T13:08:31,055][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>401, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}"}
[2017-06-12T13:08:33,161][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://localhost:9200/, :path=>"/"}
[2017-06-12T13:08:33,167][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>#<URI::HTTP:0x35355450 URL:http://localhost:9200/>, :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://localhost:9200/'"}
[2017-06-12T13:08:33,182][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://localhost:9200/, :path=>"/"}`

localhost:9200 is working but it requires me to log in where as previously this obviously was not necessary.

I've followed the steps in the installation guide.  
[https://www.elastic.co/guide/en/x-pack/current/installing-xpack.html](https://www.elastic.co/guide/en/x-pack/current/installing-xpack.html)

ES & Kibana 5.4.1  
Logstash 5.4.0

ES & Kibana appear to be working fine.

PS. Upgrading logstash to 5.4.0 is not a option.

---

<div class="post-metadata">

**Author:** ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Post date:** [June 12, 2017, 5:17am UTC](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973/2 "2017-06-12T05:17:45Z")

</div>

Okay I created the logstash\_internal user as described in the documentation. Logstash requiring configuration changes after installing x-pack should be mentioned on the installation page, not hidden away.  
[https://www.elastic.co/guide/en/x-pack/current/logstash.html](https://www.elastic.co/guide/en/x-pack/current/logstash.html)

This appears to be working but logstash is still producing some authentication/check errors. Why?

`[2017-06-12T14:13:38,624][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-06-12T14:13:38,767][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://localhost:9200/, :path=>"/"}
[2017-06-12T14:13:38,770][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>#<URI::HTTP:0x2ad7b9ff URL:http://localhost:9200/>, :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'http://localhost:9200/'"}`

---

<div class="post-metadata">

**Author:** ![vinod\_hy](https://avatars.discourse-cdn.com/v4/letter/v/c4cdca/32.png) [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Post date:** [June 12, 2017, 10:30am UTC](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973/3 "2017-06-12T10:30:15Z")

</div>

Hi,

In logstash.conf, did u add credentials for elasticsearch as below,  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> "elastic"  
password =\> "changeme"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2017, 10:30am UTC](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973/4 "2017-07-10T10:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
