# Prevent inclusion of Authorization header

**URL:** <https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 20, 2019, 1:33am UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917 "2019-01-20T01:33:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Daly](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@Michael\_Daly](https://discuss.elastic.co/u/Michael_Daly)\
**Post date:** [January 20, 2019, 1:33am UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917/1 "2019-01-20T01:33:37Z")

</div>

To get FileBeat working with AWS ES, the `Authorization` http header must not be included in the http request.

How can I prevent FileBeat sending a basic auth header?

Setting `-E output.elasticsearch.username="" -E output.elasticsearch.password=""` in the docker command does not work.

Example Docker Command

```
    docker run \
        docker.elastic.co/beats/filebeat-oss:6.5.4 \
        setup -E setup.kibana.host="https://*.eu-west-1.es.amazonaws.com:443" \
        -E output.elasticsearch.hosts=["https://*.eu-west-1.es.amazonaws.com:443"]

```

Output from FileBeat:

> Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: [Error connection to Elasticsearch https://\*.eu-west-1.es.amazonaws.com:443: 403 Forbidden: {"message":"Authorization header requires 'Credential' parameter. Authorization header requires 'Signature' parameter. Authorization header requires 'SignedHeaders' parameter. Authorization header requires existence of either a 'X-Amz-Date' or a 'Date' header. Authorization=Basic ZWxhc3RpYzpjaGFuZ2VtZQ=="}]

Another user also had the same issue, but didn't ask about the Authorization header.

> [@Failed to perform any bulk index operations: 403 Forbidden](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-403-forbidden/153207/4):
>
> What does your config look like?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 22, 2019, 11:34am UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917/2 "2019-01-22T11:34:48Z")

</div>

The error message seems to suggest that AWS ES requires you to have an Authorization header in a special format include credentials and signature. Beats are not tested with AWS IAM, and I don't think that Beats support AWS IAM functionality.

---

<div class="post-metadata">

**Author:** ![Michael\_Daly](https://avatars.discourse-cdn.com/v4/letter/m/a698b9/32.png) [@Michael\_Daly](https://discuss.elastic.co/u/Michael_Daly)\
**Post date:** [January 22, 2019, 12:07pm UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917/3 "2019-01-22T12:07:01Z")

</div>

AWS ES requires credentials and signature **only if** an `Authorization` header is present. If the header is not present, requests do not need to be signed.

I have tested removal the `Authorization` header with an nginx container proxying requests, but this is quite a bit of additional complexity for deployment.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [January 22, 2019, 3:51pm UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917/4 "2019-01-22T15:51:14Z")

</div>

Hm... I don't think filebeat will send create an Authorization header if no username or password is configured. You can try to add `-E 'output.elasticsearch={user: "", password: ""}` to overwrite the settings with empty strings in the containers config file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2019, 3:51pm UTC](https://discuss.elastic.co/t/prevent-inclusion-of-authorization-header/164917/5 "2019-02-19T15:51:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
