# Nginx Kibana: Bad Gateway 502

**URL:** <https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561>\
**Category:** Kibana\
**Created:** [December 19, 2022, 1:13pm UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561 "2022-12-19T13:13:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [December 19, 2022, 1:13pm UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/1 "2022-12-19T13:13:02Z")

</div>

Hello, I use Nginx as a web server / proxy. I created the following nginx \*.conf file for Kibana.

```auto
root@dsme01:~# cat /etc/nginx/sites-available/kibana.conf
server {
    # Update this line to be your domain
    server_name kibana.intern.example.com;

    # These shouldn't need to be changed
    listen kibana.intern.example.com:80;
    return 301 https://$host$request_uri;
}

server {
    server_name kibana.intern.example.com;

    listen kibana.intern.example.com:443 ssl;

    ssl_certificate /etc/ssl/certs/kibana.intern.example.com.crt;
    ssl_certificate_key /etc/ssl/private/kibana.intern.example.com.key;
    ssl_dhparam /etc/ssl/certs/dhparams.pem;
    
    location / {

        proxy_read_timeout 300s;
        proxy_connect_timeout 75s;
        proxy_pass https://192.168.150.20:5601;
        proxy_redirect off;

        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $http_host;
        proxy_cache_bypass $http_upgrade;
        }

    access_log /var/log/nginx/access.log;
    error_log /var/log/nginx/error.log;

}

```

When calling up the FQDN via the browser, I get the above error message and the following log entry

```auto
2022/12/19 13:19:02 [error] 2740#2740: *101 upstream sent too big header while reading response header from upstream, client: 192.168.30.62, server: kibana.intern.example.com, request: "GET /kibana/login?next=%2Fkibana%2Fkibana%2Flogin%3Fnext%3D%252Fkibana%252Fkibana%252Flogin%253Fnext%253D%25252Fkibana%25252Fkibana%25252Flogin%25253Fnext%25253D%2525252Fkibana%2525252Fkibana%2525252Flogin%2525253Fnext%2525253D%252525252Fkibana%252525252Fkibana%252525252Flogin%252525253Fnext%252525253D%25252525252Fkibana%25252525252Fkibana%25252525252Flogin%25252525253Fnext%25252525253D%2525252525252Fkibana%2525252525252Fkibana%2525252525252Flogin%2525252525253Fnext%2525252525253D%252525252525252Fkibana%252525252525252Fkibana%252525252525252Flogin%252525252525253Fnext%252525252525253D%25252525252525252Fkibana%25252525252525252Fkibana%25252525252525252Flogin%25252525252525253Fnext%25252525252525253D%2525252525252525252Fkibana%2525252525252525252Fkibana%2525252525252525252Flogin%2525252525252525253Fnext%2525252525252525253D%252525252525252525252Fkibana%252525252525252525252Fkibana%252525252525252525252Flogin%252525252525252525253Fnext%252525252525252525253D%25252525252525252525252Fkibana%25252525252525252525252Fkibana%25252525252525252525252Flogin%25252525252525252525253Fnext%25252525252525252525253D%2525252525252525252525252Fkibana%2525252525252525252525252Fkibana%2525252525252525252525252Flogin%2525252525252525252525253Fnext%2525252525252525252525253D%252525252525252525252525252Fkibana%252525252525252525252525252Fkibana%252525252525252525252525252Flogin%252525252525252525252525253Fnext%252525252525252525252525253D%25252525252525252525252525252Fkibana%25252525252525252525252525252Fkibana%25252525252525252525252525252Flogin%25252525252525252525252525253Fnext%25252525252525252525252525253D%2525252525252525252525252525252Fkibana%2525252525252525252525252525252Fkibana%2525252525252525252525252525252Flogin%2525252525252525252525252525253Fnext%2525252525252525252525252525253D%252525252525252525252525252525252Fkibana%2525252525252525252525

```

Kibana I'm running

```auto
root@dsme01:~# netstat -tulpen | grep 5601
tcp 0 0 192.168.150.20:5601 0.0.0.0:* LISTEN 138 88646 1744/node     

```

What am I doing wrong?

Greetings from Stefan Harbich

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [December 19, 2022, 6:28pm UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/2 "2022-12-19T18:28:05Z")

</div>

@azasypkin can we please get some help here? Thanks!

---

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [December 19, 2022, 7:44pm UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/3 "2022-12-19T19:44:11Z")

</div>

In addition, my kibana.yml configuration

```auto
server.port: 5601
server.host: "kibana.intern.example.com" # IP 192.168.150.20
server.basePath: "/kibana"
server.name: "Kibana-Server-Harbich"
server.ssl.enabled: true
server.ssl.certificate: /etc/kibana/config/certs/kibana.intern.example.com.crt
server.ssl.key: /etc/kibana/config/certs/kibana.intern.example.com.key
elasticsearch.hosts: ["https://elasticsearch.intern.example.com:9200"]
elasticsearch.username: "kibana"
elasticsearch.password: "######"
elasticsearch.ssl.certificateAuthorities: ["/etc/kibana/config/certs/HarbichCA.cacert.pem"]
logging.appenders.file.type: file
logging.appenders.file.fileName: /var/log/kibana/kibana.log
logging.appenders.file.layout.type: json
logging.root.appenders: [default, file]
pid.file: /run/kibana/kibana.pid
xpack.fleet.outputs: [{id: fleet-default-output, name: default, is_default: true, is_default_monitoring: true, type: elasticsearch, hosts: ['https://192.168.20.10:9200'], ca_trusted_fingerprint: b973d7025b9cffae3c40d4......}]
xpack.security.encryptionKey: "###....

```

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [December 20, 2022, 7:42am UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/4 "2022-12-20T07:42:55Z")

</div>

> [@sharbich](#):
>
> `server.basePath: "/kibana"`

If I read your nginx config correctly, you serve Kibana from the root path (`/`), and not from `/kibana` sub-path. If you plan to continue serving Kibana from the root path, then you need to remove this setting from `kibana.yml` (and once you do this, try to open Kibana in a private browser tab to make sure there is no stale cookie in play).

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![sharbich](https://avatars.discourse-cdn.com/v4/letter/s/5daacb/32.png) [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Post date:** [December 20, 2022, 8:59am UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/5 "2022-12-20T08:59:49Z")

</div>

You are the best Oleg. It works. A heartfelt thank you. I wish you a Merry Christmas.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [December 20, 2022, 9:23am UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/6 "2022-12-20T09:23:09Z")

</div>

Thanks for reporting back, glad it helped!

Happy holidays @sharbich!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/nginx-kibana-bad-gateway-502/321561/7 "2023-01-17T09:23:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
