# Logstash with x-pack authentication problems without Authentication Header

**URL:** <https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692>\
**Category:** Logstash\
**Created:** [September 7, 2017, 8:54am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692 "2017-09-07T08:54:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Metehan\_Selvi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metehan_selvi/32/21869_2.png) [@Metehan\_Selvi](https://discuss.elastic.co/u/Metehan_Selvi)\
**Post date:** [September 7, 2017, 8:54am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692/1 "2017-09-07T08:54:10Z")

</div>

Hello,  
as stated in [Logstash with x-pack authentication problems](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897)  
I have the same problems after I have updated ELK-Stack with x-pack.

```
[2017-09-07T08:44:37,664][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>401, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}}],\"type\":\"security_exception\",\"reason\":\"missing authentication token for REST request [/_bulk]\",\"header\":{\"WWW-Authenticate\":\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\"}},\"status\":401}"}

```

Logstash **does not** include BASIC Authorisations Headers.  
I tried to tcpdump the communication and it is true:

```
POST /_bulk HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json
Content-Length: 94879 
Host: localhost:9200
User-Agent: Manticore 0.6.1
Accept-Encoding: gzip,deflate

{"index":{"_id":null,"_index":"metricbeat-2017.09.07","_type":"metricsets","_routing":null}}
. ....

HTTP/1.1 401 Unauthorized
WWW-Authenticate: Basic realm="security" charset="UTF-8"
content-type: application/json; charset=UTF-8
content-encoding: gzip
transfer-encoding: chunked

ba
............K
 .@.D.2.:.....P...!.DB;.fH.hw..B.

```

I tried the official docu and created roles and users, add the  
xpack.monitoring.elasticsearch.username: "elastic"  
xpack.monitoring.elasticsearch.password: "changeme"

in the logstash.yml file etc.

Also a basic curl works

```
 curl -v -u elastic:changeme http://localhost:9200

```

Is it a bug??????

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 8:56am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692/2 "2017-09-07T08:56:02Z")

</div>

What does your Logstash configuration look like?

---

<div class="post-metadata">

**Author:** ![Metehan\_Selvi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/metehan_selvi/32/21869_2.png) [@Metehan\_Selvi](https://discuss.elastic.co/u/Metehan_Selvi)\
**Post date:** [September 7, 2017, 9:13am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692/3 "2017-09-07T09:13:22Z")

</div>

Thank you for the quick reply.  
Yes, I found the mistake.  
THANK YOU very Much!!

In the logstash.yml I had a reference to

```
  path.config: /etc/logstash/conf.d 

```

which inside there was beats.conf file where I have not noticed that there also must be  
the user and password inserted. Current output is:

```
output {
   if [@metadata][beat] {
     elasticsearch {
         hosts => ["http://localhost:9200"]
         index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
        document_type => "%{[@metadata][type]}"
        user => "elastic"
        password => "changeme"
      }
   }
     else {
         elasticsearch {
               hosts => ["127.0.0.1:9200"]
               user => "elastic"
               password => "changeme"
         }
     }
 }

```

But why do I register the user both on beats.conf and the logstash,yml ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 9:17am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692/4 "2017-09-07T09:17:53Z")

</div>

The entry in logstash.yml specifies where Logstash will send monitoring data. Configuration in the config determines where data go.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2017, 9:17am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems-without-authentication-header/99692/5 "2017-10-05T09:17:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
