# Logstash with x-pack authentication problems

**URL:** <https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897>\
**Category:** Logstash\
**Created:** [March 8, 2017, 9:42pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897 "2017-03-08T21:42:11Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [March 8, 2017, 9:42pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/1 "2017-03-08T21:42:11Z")

</div>

I have x-pack installed and I keep getting errors in the logstash log

> WARN ][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>#\<URI::HTTP:0xa3a53ec URL:[http://logstash\_system:xxxxxx@localhost:9200/\_xpack/monitoring/?system\_id=logstash&system\_api\_version=2&interval=1s](http://logstash_system:xxxxxx@localhost:9200/_xpack/monitoring/?system_id=logstash&system_api_version=2&interval=1s)\>, :error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

> [ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=\>401, :response\_body=\>"{"error":{"root\_cause":[{"type":"security\_exception","reason":"failed to authenticate user [logstash\_system]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}}],"type":"security\_exception","reason":"failed to authenticate user [logstash\_system]","header":{"WWW-Authenticate":"Basic realm=\"security\" charset=\"UTF-8\""}},"status":401}"}

I'm not even using the "logstash\_system" account in my output config for elasticsearch.  
I'm using the "elastic" account

What is it looking for ?

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [March 27, 2017, 10:39am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/2 "2017-03-27T10:39:33Z")

</div>

I am also facing the same issue. Now the changes what i am doing in logstash.conf file not reflecting in kibana.

Could you please someone help on this.

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 27, 2017, 2:52pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/3 "2017-03-27T14:52:51Z")

</div>

Could you please put your Logstash output settings? Or are you using logstash\_system anywhere on your settings?

For what I understand, logstash\_system is needed for monitoring purposes on X-Pack. But still, it would be also recommended to use that user for output settings from Logstash to Elasticsearch

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [March 28, 2017, 1:45am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/4 "2017-03-28T01:45:52Z")

</div>

Hi,

Following property i have added after added xpack plugin into logstash.

xpack.monitoring.elasticsearch.username: "logstash\_system"  
xpack.monitoring.elasticsearch.password: "demopwd"

Following is the output of logstash conf file.

output  
{

elasticsearch { hosts =\> ["localhost:9200"]}  
stdout{codec=\> rubydebug}

}

I am not seeing anything about logstash in Kibana monitoring page. Please help me to resolve this issue.

Regards  
Raja

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 28, 2017, 3:04pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/5 "2017-03-28T15:04:17Z")

</div>

Alright, if you are not using SSL settings, you're close! Check this page [https://www.elastic.co/guide/en/x-pack/current/logstash.html](https://www.elastic.co/guide/en/x-pack/current/logstash.html). This will help how to configure logstash output settings. For testing purposes, I had assigned the logstash\_internal user the two roles created on the example (logstash\_writer and logstash\_reader), just to check if the connection between Logstash and Elasticsearch was running fine. The output conf file shold look like this:

output  
{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> "logstash\_internal"  
password =\> "\<logstash\_internal\_password\>"  
...  
}  
stdout{codec=\> rubydebug}

}

The logstash.yaml file is okay for now. Just check if the password is the correct.

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [March 29, 2017, 1:53am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/6 "2017-03-29T01:53:26Z")

</div>

Hi,

Thanks for your reply.  
I tried this but still same issue.

Regards  
Raja

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 29, 2017, 1:47pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/7 "2017-03-29T13:47:52Z")

</div>

Can you show me your logs?

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [March 30, 2017, 1:41am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/8 "2017-03-30T01:41:42Z")

</div>

Hi,

Please find the log below. This is the same log displaying continuously.

[2017-03-30T01:36:22,955][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>#\<URI::HTTP:0x79bb1764 URL:[http://localhost:9200/](http://localhost:9200/)\>, :error\_type=\>Logstash::outputs::Elasticsearch::HttpClient::Pool::badResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch at URL '[http://localhost:9200/](http://localhost:9200/)'"}

Regards  
Raja

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 30, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/9 "2017-03-30T14:11:05Z")

</div>

If you are getting a 401 (Unauthorized), there could be something wrong with your credentials. And this is from Logstash-Elasticsearch connection

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [March 31, 2017, 1:44am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/10 "2017-03-31T01:44:14Z")

</div>

Hello,

I know something went wrong some where but i followed exactly the elastic document. Nothing has changed.

Tried to reset the password even though same errors.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2017, 1:44am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897/11 "2017-04-28T01:44:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
