# Metricbeat password literal issue

**URL:** <https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [March 31, 2020, 12:07pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851 "2020-03-31T12:07:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenbangalore](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Post date:** [March 31, 2020, 12:07pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851/1 "2020-03-31T12:07:49Z")

</div>

Hi,  
Not sure if this issue was already reported. Found an unusual behaviour with metricbeat.  
Typically when Xpack is enabled, username and password are added in the metricbeat.yml. When the password contains the literals "$$" (consecutive $), elasticsearch fails to authorize the user.  
To replicate, try having the password of a user with literals like "P@$$XXyy"

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [March 31, 2020, 2:39pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851/2 "2020-03-31T14:39:18Z")

</div>

This is due to the template engine the metricbeat config. I would recommend using the [Beat keystore](https://www.elastic.co/guide/en/beats/metricbeat/current/keystore.html), or just substituting `$$` for `$$$$` to escape the template engine.

---

<div class="post-metadata">

**Author:** ![naveenbangalore](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Post date:** [March 31, 2020, 4:29pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851/3 "2020-03-31T16:29:17Z")

</div>

Thanks, @Alex_Kristiansen for the response. Is this info present in the documentation?

---

<div class="post-metadata">

**Author:** ![Alex\_Kristiansen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_kristiansen/32/46086_2.png) [@Alex\_Kristiansen](https://discuss.elastic.co/u/Alex_Kristiansen)\
**Post date:** [March 31, 2020, 4:56pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851/4 "2020-03-31T16:56:28Z")

</div>

Right now we are not documenting the behavior of `$$`. We should probably change that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2020, 4:56pm UTC](https://discuss.elastic.co/t/metricbeat-password-literal-issue/225851/5 "2020-04-28T16:56:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
