# Packetbeat error connecting to elasticsearch

**URL:** <https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 1, 2024, 10:54am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545 "2024-04-01T10:54:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Syphax](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Syphax](https://discuss.elastic.co/u/Syphax)\
**Post date:** [April 1, 2024, 10:54am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545/1 "2024-04-01T10:54:20Z")

</div>

hi everyone,

my elasticsearch server receives IPs dynamically from a DHCP server. my elastic server had an address of 192.168.100.116 when I installed it, the next day the address was changed to 192.168.100.126 and when I installed packetbeat on another server.  
the problem started when I ran the command "./packetbeat.exe setup -e" and it showed me this error  
error: [error connecting to elasticsearch at https: // 192.168. 100.126: 9200: Get "https:// 192. 168. 100. 126: 9200" x509: certificate is valid fr 192.168.100.116 \*\*\*\*not 192.168.100.126]

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 1, 2024, 6:05pm UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545/2 "2024-04-01T18:05:19Z")

</div>

Hi @Syphax, Welcome to the community

> [@Syphax](#):
>
> error  
> error: [error connecting to elasticsearch at https: // 192.168. 100.126: 9200: Get "https:// 192. 168. 100. 126: 9200" x509: certificate is valid fr 192.168.100.116 \*\*\*\*not 192.168.100.126]

The error is pretty clear .. .the cert for elasticsearch no longer matches its IP.

Whoever changed the elasticsearch IP address should have updated the certificate to match the IP.

A workaround in the packetbeat.yml in the elasticsearch.output section set the [verification\_mode](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-ssl.html#client-verification-mode)

```auto
elasticsearch.output:
  ssl.verification_mode: none

```

This is a temp / slightly less secure the right thing to do is have your admin fix the elasticsearcbh cert, the mismatching IP is probably going to break other things as well.

---

<div class="post-metadata">

**Author:** ![Syphax](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Syphax](https://discuss.elastic.co/u/Syphax)\
**Post date:** [April 2, 2024, 9:48am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545/3 "2024-04-02T09:48:01Z")

</div>

Thank you @stephenb for your answer ,  
the problem with the address is resolved but I do not receive information on the kibana dashboards, the dashboards are empty, yet the command below works without error.

 ![image_2024-04-02_114134344](https://us1.discourse-cdn.com/elastic/original/3X/0/7/078c92846600a5d7b96077525d70967b4d84146a.png)

I don't know if it's because of the config of the packetbeat.yml file :

_ **packetbeat.interfaces.device: default\_route** _

---

<div class="post-metadata">

**Author:** ![Syphax](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Syphax](https://discuss.elastic.co/u/Syphax)\
**Post date:** [April 2, 2024, 11:12am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545/4 "2024-04-02T11:12:10Z")

</div>

Hi,  
Finally, I forgot to launch the service, that's why I don't get any results from Kibana.  
the problem is solved,

thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2024, 11:13am UTC](https://discuss.elastic.co/t/packetbeat-error-connecting-to-elasticsearch/356545/5 "2024-04-30T11:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
