# "path: /\_security/api\_key... api keys are not enabled" while loading prebuilt detection rules

**URL:** <https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319>\
**Category:** SIEM\
**Created:** [February 14, 2020, 7:53am UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319 "2020-02-14T07:53:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Slavik\_Fursov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slavik_fursov/32/48975_2.png) [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Post date:** [February 14, 2020, 7:53am UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319/1 "2020-02-14T07:53:58Z")

</div>

I upgraded to 7.6.0 today.  
I wanted to try Detections, but I'm getting error (below) when clicking "load prebuilt detection rules".

My complete Kibana config:

```auto
---
## Default Kibana configuration from Kibana base image.
## https://github.com/elastic/kibana/blob/master/src/dev/build/tasks/os_packages/docker_generator/templates/kibana_yml.template.js
#
server.name: kibana
server.host: "0"
elasticsearch.hosts: ["http://elasticsearch:9200"]
xpack.monitoring.ui.container.elasticsearch.enabled: false

## X-Pack security credentials
#
elasticsearch.username: kibana
elasticsearch.password: ***

xpack.encryptedSavedObjects.encryptionKey: 'fhjskloppd678ehkdfdlliver123lfcr'

```

My Elastic config:

```auto
---
## Default Elasticsearch configuration from Elasticsearch base image.
## https://github.com/elastic/elasticsearch/blob/master/distribution/docker/src/docker/config/elasticsearch.yml
#
cluster.name: "docker-cluster"
network.host: 0.0.0.0

## Use single node discovery in order to disable production mode and avoid bootstrap checks
## see https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html
#
discovery.type: single-node

## X-Pack settings
## see https://www.elastic.co/guide/en/elasticsearch/reference/current/setup-xpack.html
#
xpack.license.self_generated.type: basic
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.monitoring.collection.enabled: false

```

The error in Elastic log:

> {"type": "server", "timestamp": "2020-02-14T06:48:22,835Z", "level": "WARN", "component": "r.suppressed", "cluster.name": "docker-cluster", "node.name": "eb198821dba9", "message": "path: /\_security/api\_key, params: {}", "cluster.uuid": "ikMJnjTqRYG4UlQ6SjnDBw", "node.id": "ofsLwcUiTRmAPT\_Lp8FUMg" ,  
> "stacktrace": ["java.lang.IllegalStateException: api keys are not enabled",  
> "at org.elasticsearch.xpack.security.authc.ApiKeyService.ensureEnabled(ApiKeyService.java:584) ~[?:?]",  
> "at org.elasticsearch.xpack.security.authc.ApiKeyService.createApiKey(ApiKeyService.java:194) ~[?:?]",  
> "at org.elasticsearch.xpack.security.action.TransportCreateApiKeyAction.lambda$doExecute$0(TransportCreateApiKeyAction.java:67) ~[?:?]",  
> "at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:63) [elasticsearch-7.6.0.jar:7.6.0]",  
> "at org.elasticsearch.xpack.security.authz.store.CompositeRolesStore.lambda$getRoleDescriptors$13(CompositeRolesStore.java:295) [x-pack-security-7.6.0.jar:7.6.0]",  
> "at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:63) [elasticsearch-7.6.0.jar:7.6.0]", ...

The error in Kibana log:

> {"type":"error","@timestamp":"2020-02-14T08:14:02Z","tags":,"pid":6,"level":"error","error":{"message":"[illegal\_state\_exception] api keys are not enabled","name":"Error","stack":"Error: [illegal\_state\_exception] api keys are not enabled\n at transformError (/usr/share/kibana/x-pack/legacy/plugins/siem/server/lib/detection\_engine/routes/utils.js:24:14)\n at handler (/usr/share/kibana/x-pack/legacy/plugins/siem/server/lib/detection\_engine/routes/rules/add\_prepackaged\_rules\_route.js:84:16)\n at process.\_tickCallback (internal/process/next\_tick.js:68:7)"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":null,"query":{},"pathname":"/api/detection\_engine/rules/prepackaged","path":"/api/detection\_engine/rules/prepackaged","href":"/api/detection\_engine/rules/prepackaged"},"message":"[illegal\_state\_exception] api keys are not enabled"}  
> {"type":"response","@timestamp":"2020-02-14T08:14:02Z","tags":["access:siem"],"pid":6,"method":"put","statusCode":500,"req":{"url":"/api/detection\_engine/rules/prepackaged","method":"put","headers":{"host":"xxx:9100","connection":"keep-alive","content-length":"0","kbn-xsrf":"true","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36","content-type":"application/json","accept":"_/_","origin":"[http://xxx:9100](http://xxx:9100)","referer":"[http://xxx:9100/app/siem","accept-encoding":"gzip](http://xxx:9100/app/siem%22,%22accept-encoding%22:%22gzip), deflate","accept-language":"en-GB,en-US;q=0.9,en;q=0.8,ru;q=0.7"},"remoteAddress":"172.22.0.1","userAgent":"172.22.0.1","referer":"[http://xxx:9100/app/siem"},"res":{"statusCode":500,"responseTime":1412,"contentLength":9},"message":"PUT](http://xxx:9100/app/siem%22%7D,%22res%22:%7B%22statusCode%22:500,%22responseTime%22:1412,%22contentLength%22:9%7D,%22message%22:%22PUT) /api/detection\_engine/rules/prepackaged 500 1412ms - 9.0B"}  
> {"type":"log","@timestamp":"2020-02-14T08:14:03Z","tags":["error","plugins","security","api-key"],"pid":6,"message":"Failed to create API key: [illegal\_state\_exception] api keys are not enabled"}

Any idea how to fix the issue?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [February 14, 2020, 4:53pm UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319/2 "2020-02-14T16:53:09Z")

</div>

Hi Slavik\_Fursov,

It looks like your Kibana instance is connecting to your Elastic through `http` and not `https` by looking at your configuration?

```auto
elasticsearch.hosts: ["http://elasticsearch:9200"]

```

If you have security and certificates setup you should be able to begin to use `https`:

```auto
elasticsearch.hosts: ["https://elasticsearch:9200"]

```

If you have self signed certificates without a local CA you might just need to add one additional Kibana setting of:

```auto
  ssl:
    verificationMode: 'certificate'

```

which would skip the hostname validation, but I would always recommend maintaining your own certificates root certificates and doing verification full even when on local intranets. On public reachable areas, of course, regular certificate CA is what I would always recommended.

After this your API keys should begin to working for you and then in turn the detection signals.

The system is trying to ensure you don't send out API keys in plain clear text when you have `http` is why it is stopping you from moving forward.

More details about these settings and permissioning:

[https://www.elastic.co/guide/en/kibana/current/settings.html](https://www.elastic.co/guide/en/kibana/current/settings.html)  
[https://www.elastic.co/guide/en/elasticsearch/reference/master/security-api-create-api-key.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-api-create-api-key.html)  
[https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions)

---

<div class="post-metadata">

**Author:** ![Slavik\_Fursov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/slavik_fursov/32/48975_2.png) [@Slavik\_Fursov](https://discuss.elastic.co/u/Slavik_Fursov)\
**Post date:** [February 14, 2020, 6:42pm UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319/3 "2020-02-14T18:42:11Z")

</div>

yes, I'm running everything via HTTP,  
no HTTPS.

One reason for that is because I set up my system via Docker, so all communications are internal.

Thank you for pointing me to that. I'll go and configure my system to enable HTTPS.

Perhaps, that recent blog post about enabling Detections should have HTTPS prerequisite noted down, too:  
[https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html)

---

<div class="post-metadata">

**Author:** ![Ben\_Skelker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_skelker/32/46274_2.png) [@Ben\_Skelker](https://discuss.elastic.co/u/Ben_Skelker)\
**Post date:** [February 16, 2020, 10:33am UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319/4 "2020-02-16T10:33:59Z")

</div>

Thanks for the suggestion @Slavik_Fursov. I've opened a PR for improving the Detections requirements: [https://github.com/elastic/stack-docs/pull/882](https://github.com/elastic/stack-docs/pull/882)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2020, 10:34am UTC](https://discuss.elastic.co/t/path-security-api-key-api-keys-are-not-enabled-while-loading-prebuilt-detection-rules/219319/5 "2020-03-15T10:34:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
