# Receive Authorization Header Logstash Http Input Plugin

**URL:** <https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407>\
**Category:** Logstash\
**Created:** [December 2, 2020, 6:19pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407 "2020-12-02T18:19:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sai\_kiran1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_kiran1/32/44118_2.png) [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Post date:** [December 2, 2020, 6:19pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/1 "2020-12-02T18:19:06Z")

</div>

Hi,

I am using the HTTP input plugin to receive data from the postman with Basic Auth enabled, "Authorization" header is available in the postman response but when I print the data in logstash I don't see the Authorization header available.

Can someone help so I can receive the Authorization field in the headers list to my logstash?

Thanks,  
Sai

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 2, 2020, 7:31pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/2 "2020-12-02T19:31:47Z")

</div>

```auto
input {
  http_poller {
    urls => {
      postman => {
        method => get
        url => "https://postman-echo.com/basic-auth"
        headers => {
            "Authorization" => "Basic cG9zdG1hbjpwYXNzd29yZA=="
            "Content-Type" => "application/json"
        }
     }
    }
    schedule => { cron => "* * * * * UTC"}
    codec => "json"
  }
}
output {
        stdout { codec => rubydebug }
}

```

returns

```auto
{
    "authenticated" => true,
         "@version" => "1",
       "@timestamp" => 2020-12-02T19:26:00.891Z
}

```

If you are talking about the same postman basic authentication it only returns the `authenticated` field. Are you able to share your config and what you anticipate the return to be?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 2, 2020, 7:53pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/3 "2020-12-02T19:53:30Z")

</div>

I have a very vague recollection that the Authorization header is special, and gets consumed by the http server. There is another [forum post](https://discuss.elastic.co/t/sending-authorization-header-to-http-input-plugin/231999) that suggests this is true, however, I have poked around in github and cannot find anything in logstash or netty that consumes it.

Sadly I cannot find the thread I recall from a couple of years ago on this subject.

---

<div class="post-metadata">

**Author:** ![sai\_kiran1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_kiran1/32/44118_2.png) [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Post date:** [December 3, 2020, 7:18am UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/4 "2020-12-03T07:18:25Z")

</div>

Hi Aaron

My HTTP Post and header fields in postman look like this :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e561983db11c714a0a9ff6134aa089ef4da9de46.png)

Below Logstash config receives data from the postman and displays it

```auto
input {
        http {
                port => 7030
                user => "user"
                password => "password"
        }
}

output {
        stdout{codec => rubydebug}
}

```

Output Displayed on logsatsh console where I don't see Authorization field:

```auto
{
      "headers" => {
           "http_accept" => "*/*",
         "cache_control" => "no-cache",
       "http_user_agent" => "PostmanRuntime/7.24.1",
             "http_host" => "lostash_dns:7030",
       "accept_encoding" => "gzip, deflate, br",
          "http_version" => "HTTP/1.1",
            "connection" => "keep-alive",
         "postman_token" => "e430b354-e60c-478f-81ee-761ea0339590",
        "content_length" => "0",
          "request_path" => "/",
        "request_method" => "POST"
   },
         "host" => "192.xxx.xxx.xx",
     "@version" => "1",
   "@timestamp" => 2020-12-03T07:01:00.211Z,
      "message" => ""
}

```

Expected Output for me is the field Authorization available in Postman should be received at logstash.

Thanks in advance 🙂

Regadrs,  
Sai

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 3, 2020, 2:18pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/5 "2020-12-03T14:18:43Z")

</div>

Got it.

I would not expect the authorization field to be returned in Logstash. I couldn't find anything to verify this but I'd think it would be a security concern logging your authorization credentials.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 2:18pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407/6 "2020-12-31T14:18:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
