# Missing authentication credentials for REST request

**URL:** <https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588>\
**Category:** Beats\
**Tags:** elastic-stack-security, filebeat\
**Created:** [September 3, 2022, 7:58am UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588 "2022-09-03T07:58:01Z")\
**Posts on this page:** 11\
**Page:** 2

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 9, 2022, 5:47pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/21 "2022-09-09T17:47:21Z")

</div>

`https://github.com/frosky/ELK-Installation/blob/main/SIEM.md`  
Can you go through this link and tell me whether the steps mentioned in this tutorial are correct or not?

---

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 9, 2022, 5:54pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/22 "2022-09-09T17:54:41Z")

</div>

Stephen I did what you told me, but now I am getting this error

```auto
</>
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at http://localhost:9200: Get "http://localhost:9200": dial tcp 127.0.0.1:9200: connect: connection refused]
</>

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2022, 5:56pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/23 "2022-09-09T17:56:58Z")

</div>

> [@Sher\_Khan](#):
>
> `https://github.com/frosky/ELK-Installation/blob/main/SIEM.md`  
> Can you go through this link and tell me whether the steps mentioned in this tutorial are correct or not?

No sorry I can not... the problem is there are 100s of these types of helps... they often are not kept up to date... or are not correct.

But quick glance those instructions are for 7.x and you are using 8.x ...

There is no mention of setup ... now I told you how to do that... and the logstash is wrong because it is 7.x version not 8.x version

so the logastash should look like

```auto
input {
  beats {
    port => 5044
  }
}

output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "https://061ab24010a2482e9d64729fdb0fd93a.us-east-1.aws.found.io:9243"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create" 
      pipeline => "%{[@metadata][pipeline]}" 
      user => "elastic"
      password => "secret"
    }
  } else {
    elasticsearch {
      hosts => "https://061ab24010a2482e9d64729fdb0fd93a.us-east-1.aws.found.io:9243"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}" 
      action => "create"
      user => "elastic"
      password => "secret"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 9, 2022, 6:00pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/24 "2022-09-09T18:00:31Z")

</div>

I have to add the commands you mention above in these two files right?

```auto
sudo nano /etc/logstash/conf.d/2-beats-input.conf

```

```auto
sudo nano /etc/logstash/conf.d/2-elasticsearch-output.conf

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2022, 6:22pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/25 "2022-09-09T18:22:37Z")

</div>

> [@Sher\_Khan](#):
>
> Stephen I did what you told me, but now I am getting this error
> 
> ```auto
> </>
> Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at http://localhost:9200: Get "http://localhost:9200": dial tcp 127.0.0.1:9200: connect: connection refused]
> </>
> 
> ```

First your tutorial assume 7.x which does not setup SSL and Authentication by Default, If you used 8.4 then did you understand that SSL and authentication is set up be default? Did you notice?

There are big changes between 7.x and 8.x ... your tutorial is missing many configs for 8.x it will not work for 8.x.

Have you trying to curl elasticsearch?

`curl -k -u elastic https://localhost:9200`

You need to choose to either use 7.x (which you probably should) or 8.x then you will need to properly config to work with the certs and SSL etc... non of that is in that tutorial.

I would clean up and try 7.17.6

---

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 9, 2022, 6:28pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/26 "2022-09-09T18:28:28Z")

</div>

Can you post a link of any tutorial for 8.x

---

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 9, 2022, 6:30pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/27 "2022-09-09T18:30:45Z")

</div>

When I try to curl elasticsearch I get this error

```auto
curl: (35) error:0A00010B:SSL routines::wrong version number

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2022, 7:16pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/28 "2022-09-09T19:16:02Z")

</div>

> [@Sher\_Khan](#):
>
> Can you post a link of any tutorial for 8.x

When you don't show the actual command you ran the result is basically useless.

> [@Sher\_Khan](#):
>
> Can you post a link of any tutorial for 8.x

No I recommend our docs / quckstarts etc...

Our docs show you how to setup Default 8.x elasticsearch and kibana out of the box...

You literally install them making no changes and follow the prompts...

> **[Securing your Elastic Stack is now simpler than ever](https://www.elastic.co/blog/introducing-simplified-elastic-stack-security)**
>
> In Elastic 8.0, Elastic Stack security is on by default for self-managed clusters. To get started, simply spin up Elasticsearch and Kibana, connect them using the new web UI, and they work together securely, out of the box.

Elasticsearch

> **[Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.4/deb.html)**

Kiabana

> **[Install Kibana with Debian package | Kibana Guide \[8.4\] | Elastic](https://www.elastic.co/guide/en/kibana/8.4/deb.html)**

But if you just want it to work and not learn about the components and don't need the stack secured just use 7.17

Good Luck!

---

<div class="post-metadata">

**Author:** ![Sher\_Khan](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Post date:** [September 11, 2022, 4:37pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/30 "2022-09-11T16:37:17Z")

</div>

![Screenshot from 2022-09-10 15-00-21](https://us1.discourse-cdn.com/elastic/original/3X/a/e/ae155408b7860d2e64cad77747c7b759c7a609b5.png)

Any idea how to resolve this issue?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 11, 2022, 6:19pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/31 "2022-09-11T18:19:34Z")

</div>

You should open a separate / new thread on that.  
Looks like Kibana does not have access to the internet.  
This will be a non-trivial fix if you are on a closed network.

Did you click on the link

> your own registry

> **[Air-gapped environments | Fleet and Elastic Agent Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/fleet/current/air-gapped.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 9, 2022, 6:20pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588/32 "2022-10-09T18:20:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588.md?page=1)
