# Packetbeat will not GET Kibana HTTPS

**URL:** <https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 15, 2021, 3:00am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210 "2021-03-15T03:00:05Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elks2020](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Post date:** [March 15, 2021, 3:00am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/1 "2021-03-15T03:00:05Z")

</div>

Hello everyone,  
I need help to figure-out the following problem to be fixed where the packetbeat won't start! 😫

' ' '  
` packetbeat[523584]: Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://192.168.1.10:5601/api/status fails: fail to execute`  
' ' '  
Where the  
**1- packetbeat test as follow:**  
' ' '  
[root@centos8 ~]# packetbeat test config  
Config OK  
[root@centos8 ~]#  
[root@mycentos8 ~]# packetbeat test output  
elasticsearch: [https://192.168.1.10:9200](https://192.168.1.10:9200)...  
parse url... OK  
connection...  
parse host... OK  
dns lookup... OK  
addresses: 192.168.1.10  
dial up... OK  
TLS...  
security... WARN server's certificate chain verification is disabled  
handshake... OK  
TLS version: TLSv1.3  
dial up... OK  
talk to server... OK  
version: 7.11.2  
[root@mycentos8 ~]#  
[root@mycentos8 ~]#  
' ' '

**Access the link [https://192.168.1.10:5601/api/status](https://192.168.1.10:5601/api/status)**  
' ' '  
|statusCode|401|  
|---|---|  
|error|"Unauthorized"|  
|message|"Unauthorized"|  
' ' '

**2- Packetbeat config**

**setup.kibana:**  
' ' '  
host: "[https://192.168.1.10:5601](https://192.168.1.10:5601)"  
protocol: "https"  
ssl.enabled: true  
username: "kibanauser"  
password: "password1"  
server.ssl.enabled: true  
server.ssl.certificate: /ca/packetbeatca/ca/ca.crt  
server.ssl.key: /ca/packetbeatca/ca/ca.key  
server.ssl.verification\_mode: none  
ssl.certificate\_authorities: ["/ca/packetbeatca/ca/elastic-certificate-tool-autogenerated-ca.pem"]  
' ' '

**3- Kibana.yml**  
' ' '  
server.port: 5601  
server.host: "0.0.0.0"  
' ' '  
👀

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 15, 2021, 7:34pm UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/2 "2021-03-15T19:34:09Z")

</div>

From the machine that is running Packetbeat, can you try making a `curl` request to the Kibana Status API?

```auto
curl -s -v -u kibanauser:password1 "https://192.168.1.10:5601/api/status"

```

What does this return?

Shaunak

---

<div class="post-metadata">

**Author:** ![Elks2020](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Post date:** [March 15, 2021, 11:40pm UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/3 "2021-03-15T23:40:15Z")

</div>

```
[quote="shaunak, post:2, topic:267210"]
`curl -s -v -u kibanauser:password1 "https://192.168.1.10:5601/api/status"`
[/quote]

```

Thank Shaunak  
The return output is the following:

```
    # curl -s -v -u kibanauser:password1 "https://192.168.1.10:5601/api/status"
    * Trying 192.168.1.10..
    * TCP_NODELAY set
    * Connected to 192.168.1.10 (192.168.1.10) port 5601 (#0)
    * ALPN, offering h2
    * ALPN, offering http/1.1
    * successfully set certificate verify locations:
    * CAfile: /etc/pki/tls/certs/ca-bundle.crt
      CApath: none
    * TLSv1.3 (OUT), TLS handshake, Client hello (1):
    * TLSv1.3 (IN), TLS handshake, Server hello (2):
    * TLSv1.3 (IN), TLS handshake, [no content] (0):
    * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
    * TLSv1.3 (IN), TLS handshake, [no content] (0):
    * TLSv1.3 (IN), TLS handshake, Certificate (11):
    * TLSv1.3 (OUT), TLS alert, unknown CA (560):
    * SSL certificate problem: self signed certificate
    * Closing connection 0
```

---

<div class="post-metadata">

**Author:** ![Elks2020](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Post date:** [March 18, 2021, 10:27pm UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/4 "2021-03-18T22:27:39Z")

</div>

Any luck?  
if not, do you know best documents describe step-by-step installing certificates (not the online manual) for  
1- Elastic - Kibana SSL  
2- Packetbeat - Kibana SSL  
3- XPACK  
Would shed the light on the certificate difference for each one?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 18, 2021, 11:58pm UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/5 "2021-03-18T23:58:23Z")

</div>

Maybe this blog post can help? [Configuring SSL, TLS, and HTTPS to secure Elasticsearch, Kibana, Beats, and Logstash | Elastic Blog](https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasticsearch-kibana-beats-and-logstash)

Shaunak

---

<div class="post-metadata">

**Author:** ![Elks2020](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Post date:** [March 19, 2021, 12:04am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/6 "2021-03-19T00:04:52Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![Elks2020](https://avatars.discourse-cdn.com/v4/letter/e/71e660/32.png) [@Elks2020](https://discuss.elastic.co/u/Elks2020)\
**Post date:** [March 20, 2021, 4:09am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/7 "2021-03-20T04:09:35Z")

</div>

The problem is resolved.  
The cause of the problem is the "kibana" user. The user privilege's can not run

> packetbeat setup

To solve the problem: either use a different user i.e., "kibana\_system" or add admin index privilege to the user.  
All worked no error in getting Kibana version and dashboard created successfully

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2021, 6:09am UTC](https://discuss.elastic.co/t/packetbeat-will-not-get-kibana-https/267210/8 "2021-04-17T06:09:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
