# Monitoring User for Logstash

**URL:** <https://discuss.elastic.co/t/monitoring-user-for-logstash/142290>\
**Category:** Logstash\
**Created:** [July 31, 2018, 6:49am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290 "2018-07-31T06:49:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![toni](https://avatars.discourse-cdn.com/v4/letter/t/8797f3/32.png) [@toni](https://discuss.elastic.co/u/toni)\
**Post date:** [July 31, 2018, 6:49am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/1 "2018-07-31T06:49:20Z")

</div>

Hi guys,

I took over an elastic cluster with 3 nodes. All of the nodes have x-pack installed. What I'm trying to do is enable pipelines and monitoring for logstash through kibana.

The pipeline configuration in logstash.yml is working.

Unfortunately I can't get the monitoring feature to work:

> `2018-07-30T13:38:04.25+0200 [APP/PROC/WEB/0] OUT [2018-07-30T11:38:04,258][WARN][logstash.outputs.elasticsearch] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"https://mynewuser:xxxxxx@https://myelasticsearch.cs.example.com:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :error=>"Got response code '401' contacting Elasticsearch at URL 'https://myelasticsearch.cs.example.com:9200/'"}`

My question is, do I have to use the logstash\_system user for the monitoring or is it ok to create a new native user? Weirdly the error persists even if the new user has the superuser role (login to kibana works fine).

Further question, if I need the logstash\_system User, how would I create it? There seems to be no logstash\_system-User on my Cluster (there is an "elastic"-User):

> curl -XPUT \_xpack/security/user/logstash\_system/\_enable'  
> {"error":{"root\_cause":[{"type":"validation\_exception","reason":"Validation Failed: 1: only \> existing users can be enabled;"}],"type":"validation\_exception","reason":"Validation \> Failed: 1: only existing users can be enabled;"},"status":400}

logstash.yml:

> xpack.monitoring.enabled: "true"  
> xpack.monitoring.elasticsearch.url: "[https://myelasticsearch.cs.example.com:9200](https://myelasticsearch.cs.example.com:9200)"  
> xpack.monitoring.elasticsearch.username: "mynewuser"  
> xpack.monitoring.elasticsearch.password: "randompassword"

Thank you!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 31, 2018, 7:46am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/2 "2018-07-31T07:46:18Z")

</div>

What versions of Elasticsearch and Logstash are you running?

---

<div class="post-metadata">

**Author:** ![toni](https://avatars.discourse-cdn.com/v4/letter/t/8797f3/32.png) [@toni](https://discuss.elastic.co/u/toni)\
**Post date:** [July 31, 2018, 8:43am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/3 "2018-07-31T08:43:12Z")

</div>

I'm running 6.1.3, sorry for the missing information.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 31, 2018, 10:35am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/4 "2018-07-31T10:35:21Z")

</div>

> [@toni](#):
>
> curl -XPUT \_xpack/security/user/logstash\_system/\_enable'  
> {"error":{"root\_cause":[{"type":"validation\_exception","reason":"Validation Failed: 1: only \> existing users can be enabled;"}],"type":"validation\_exception","reason":"Validation \> Failed: 1: only existing users can be enabled;"},"status":400}

Did you copy this exactly from your cluster?  
As best I can tell that error message has not existed in any recent version of X-Pack/Elasticsearch (I checked from 6.0.0 to 6.2.0)

What do you get for:

```auto
GET /_xpack/security/user/

```

and

```auto
GET /_xpack/

```

---

<div class="post-metadata">

**Author:** ![toni](https://avatars.discourse-cdn.com/v4/letter/t/8797f3/32.png) [@toni](https://discuss.elastic.co/u/toni)\
**Post date:** [July 31, 2018, 11:54am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/5 "2018-07-31T11:54:33Z")

</div>

```
Did you copy this exactly from your cluster?

```

Yes (logstash and elasticsearch version 6.1.3)

```
GET /_xpack/security/user/

```

List of native users, comparable to the management/user section in kibana (no built-in users)

```
GET /_xpack/

```

> {"build":{"hash":"9b1be50","date":"2018-01-26T19:20:38.715Z"},"license":{"uid":"f943086f-xxxx-xxxx-xxxx-b2b691dec9b7","type":"platinum","mode":"platinum","status":"active","expiry\_date\_in\_millis":1535759999999},"features":{"graph":{"description":"Graph Data Exploration for the Elastic Stack","available":true,"enabled":true},"logstash":{"description":"Logstash management component for X-Pack","available":true,"enabled":true},"ml":{"description":"Machine Learning for the Elastic Stack","available":true,"enabled":false,"native\_code\_info":{"version":"N/A","build\_hash":"N/A"}},"monitoring":{"description":"Monitoring for the Elastic Stack","available":true,"enabled":true},"security":{"description":"Security for the Elastic Stack","available":true,"enabled":true},"watcher":{"description":"Alerting, Notification and Automation for the Elastic Stack","available":true,"enabled":true}},"tagline":"You know, for X"}

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 1, 2018, 6:14am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/6 "2018-08-01T06:14:08Z")

</div>

I've worked out where that validation error is coming from.  
Is your cluster running under Elastic Cloud Enterprise?

If so, unfortunately you can't use the `logstash_system` user, and will need to create your own custom user.

So, back to your original questions:

> [@toni](#):
>
> do I have to use the logstash\_system user for the monitoring or is it ok to create a new native user

A native user will be fine. Just create `logstash_monitoring` user, and give it the `logstash_system` role.

> [@toni](#):
>
> Weirdly the error persists even if the new user has the superuser role

I don't understand why that would be the case.  
Are you sure the password is correct, and doesn't contain any unusual characters that might get incorrectly interpretted in the config file?

---

<div class="post-metadata">

**Author:** ![toni](https://avatars.discourse-cdn.com/v4/letter/t/8797f3/32.png) [@toni](https://discuss.elastic.co/u/toni)\
**Post date:** [August 13, 2018, 8:36am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/7 "2018-08-13T08:36:33Z")

</div>

Thx for your comments Tim.

As it turns out there is a logstash\_system user after all, the monitoring works when I use that one.

Sorry for the troubles.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2018, 8:36am UTC](https://discuss.elastic.co/t/monitoring-user-for-logstash/142290/8 "2018-09-10T08:36:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
