# Randomly getting Error: Failed to decrypt report job data. with Kibana

**URL:** <https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135>\
**Category:** Kibana\
**Created:** [April 30, 2019, 6:42pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135 "2019-04-30T18:42:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![javadevmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javadevmtl/32/45613_2.png) [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Post date:** [April 30, 2019, 6:42pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/1 "2019-04-30T18:42:16Z")

</div>

Hi, I have two instances of `Kibana 6.4.2` running in Docker container on DC/OS and I randomly get: `Error: Failed to decrypt report job data.` with Kibana.

Sometimes the reports work, sometimes not.

I have set `xpack.reporting.encryptionKey` as an `environment variable`. NOT in the kibana.yml

If it's an environment var should it be: XPACK\_REPORTING\_ENCRYPTIONKEY?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [April 30, 2019, 11:19pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/2 "2019-04-30T23:19:04Z")

</div>

If this error is intermittent then you might be running into a problem in which the amount of data used to generate the report is too large. Here's a [similar issue](https://discuss.elastic.co/t/error-in-reporting/147595) in which the user solved the problem by using a smaller time interval. Can you see if this works, to confirm that this is the problem?

---

<div class="post-metadata">

**Author:** ![javadevmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javadevmtl/32/45613_2.png) [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Post date:** [May 1, 2019, 2:50pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/3 "2019-05-01T14:50:31Z")

</div>

The intermittent also happens on the same report.

The data range is 1 month and produces about 900 documents. On the discover page it seems to take 3 seconds max.

---

<div class="post-metadata">

**Author:** ![javadevmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javadevmtl/32/45613_2.png) [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Post date:** [May 2, 2019, 8:31pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/4 "2019-05-02T20:31:50Z")

</div>

So, I dunno how much smaller I can do it. Or should I reduce the month to a day type of thing?

---

<div class="post-metadata">

**Author:** ![joelgriffith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joelgriffith/32/53738_2.png) [@joelgriffith](https://discuss.elastic.co/u/joelgriffith)\
**Post date:** [May 6, 2019, 7:15pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/5 "2019-05-06T19:15:45Z")

</div>

Hey @javadevmtl, do your Kibana instances have the same `kibana.index` set? There's a known issue (really mis-configuration) where having the different `kibana.index`'s, but the same `xpack.reporting.index`, will cause Kibana to claim jobs it cannot fulfill.

With different `kibana.index` settings across Kibana instances connected to the same Elasticsearch cluster, you _must_ also configure a different `xpack.reporting.index` setting per each unique `kibana.index`.

Let me know if that helps!

---

<div class="post-metadata">

**Author:** ![javadevmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javadevmtl/32/45613_2.png) [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Post date:** [May 6, 2019, 8:16pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/6 "2019-05-06T20:16:47Z")

</div>

Hi, no I do not set a different index per Kibana instance and both configs are default.

These are the only ENVIRONMENT var I set...  
"NODE\_OPTIONS": "xxxxxx",  
"ELASTICSEARCH\_URL": "xxxxxx",  
"XPACK\_MONITORING\_UI\_CONTAINER\_ELASTICSEARCH\_ENABLED": "false",  
"xpack.reporting.encryptionKey": "xxxxxx"

1- So it seems I don't need to do anything?  
2- Should xpack.reporting.encryptionKey be in caps and underscores just like the other environment vars?

---

<div class="post-metadata">

**Author:** ![javadevmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javadevmtl/32/45613_2.png) [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Post date:** [May 7, 2019, 4:02pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/7 "2019-05-07T16:02:47Z")

</div>

@joelgriffith Hi, basically I run Kibana in DC/OS and all I do is scale up or down. So in essence each instance is running the exact same Docker/Marathon/config, I do not inject any special kibana.yaml in the docker container and use mostly default values except for the above mentioned config.

And then access Kibana through Haproxy.

The only thing I'm not sure is that "xpack.reporting.encryptionKey": "xxxxxx" if it's configurable by environment variable and if it should be XPACK\_REPORTING\_ENCRYPTION\_KEY instead?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2019, 4:02pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/8 "2019-06-04T16:02:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 8, 2019, 6:51pm UTC](https://discuss.elastic.co/t/randomly-getting-error-failed-to-decrypt-report-job-data-with-kibana/179135/9 "2019-07-08T18:51:32Z")

</div>

Hi, the answer to your question is that environment variables used for a config setting DO need to be uppercased. The documentation about this can be found in Docker configuration: [https://www.elastic.co/guide/en/kibana/current/docker.html#environment-variable-config](https://www.elastic.co/guide/en/kibana/current/docker.html#environment-variable-config) as environment variables are often used to run customized Docker containers.

If the environment variable with your encryption key can't be found by Kibana, it will generate a random one, which means other Kibana instances have different encryption keys, and they'll only be allowed to decrypt the reports they created... until they restart.

If Kibana is generating a random encryption key, a warning log about this will be printed in the Kibana console at startup.
