# \[Shield\] Kibana error on startup

**URL:** <https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 20, 2015, 4:15pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591 "2015-10-20T16:15:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pierre\_Jacquot](https://avatars.discourse-cdn.com/v4/letter/p/e274bd/32.png) [@Pierre\_Jacquot](https://discuss.elastic.co/u/Pierre_Jacquot)\
**Post date:** [October 20, 2015, 4:15pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/1 "2015-10-20T16:15:33Z")

</div>

Hello,

I'm trying to use Shield with elasticSearch and kibana, but I get the following error when I launch kibana

"level":50,"err":{"message":"AuthorizationException[action [cluster:monitor/health] is unauthorized for user [XXXXX]]","name":"Error","stack":"Error: AuthorizationException[action [cluster:monitor/health] is unauthorized for user [XXXXX]]

I have follow the instruction describe is the topic bellow without any success :

> [@Using Kibana 4 with Shield: Auth problem](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841):
>
> Hi All, I refer to 'using kibana 4 with shield steps ([https://www.elastic.co/guide/en/shield/current/kibana.html#kibana4-user-role](https://www.elastic.co/guide/en/shield/current/kibana.html#kibana4-user-role))' to practice kibana with shield, but got some error log after I restart Kibana MY ENV (Elasticsearch Cluster: 1 master (140.92.25.126) 1 node (140.92.25.161) ; (Kibana 140.92.25.95) {"name":"Kibana","hostname":"kibana","pid":53218,"level":60,"err":{"message":"RemoteTransportException[[enode1][inet[/140.92.25.161:9301]][cluster:monitor/health]]; nested: Authoriz…

Here is the elasticSearch configuration related to shield :  
shield.authc.realms.default.type: esusers  
shield.authc.realms.default.order: 0  
shield.authc.realms.default.files.users: /etc/elasticsearch/shield/user  
shield.authc.realms.default.files.users\_roles: /etc/elasticsearch/shield/users\_roles  
shield.authc.realms.default.files.roles: /etc/elasticsearch/shield/roles

and the content of /etc/elasticsearch/shield/user file  
toto:$2a$10$ZMwDYq/U7jJOHkgdE77Z7uUS4qPhqDRhtwBJlXt0TE.verOva5eWe  
kibana:$2a$10$wgi9556p286bUeNSYBE34.1wVl6gT8/a56kesRUEt3Ugmnv8CWDfe

here is the content of users\_roles file :  
admin:es\_admin,kibana,ng36cb1  
kibana4\_server:toto

roles files have not been updated, and I have try multiple test with admin and kibana4 roles without success.  
Anyone have an idea of the origin of this issue ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 21, 2015, 1:23pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/2 "2015-10-21T13:23:13Z")

</div>

Hi Pierre,

I am sorry that you have not had success getting Kibana to work with Shield, lets work on resolving that. What did you configure in your kibana.yml? What versions of Kibana, Elasticsearch, and Shield are you using?

Are you able to issue curl commands to the elasticsearch node protected by shield with success?

-Jay

---

<div class="post-metadata">

**Author:** ![Pierre\_Jacquot](https://avatars.discourse-cdn.com/v4/letter/p/e274bd/32.png) [@Pierre\_Jacquot](https://discuss.elastic.co/u/Pierre_Jacquot)\
**Post date:** [October 22, 2015, 9:10am UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/3 "2015-10-22T09:10:27Z")

</div>

Hello,

I'm sorry for the missing information.  
Here is a quick view of the product versions :

Elastic search : Version: 1.7.0, Build: 929b973/2015-07-16T14:31:07Z, JVM: 1.8.0\_40  
Kibana : Version : 4.1.1  
Shield : Version 1.3.2

Here is the content of my kybana.yml file

```
port: 5601
host: "0.0.0.0"
elasticsearch_url: "http://localhost:9200"
elasticsearch_preserve_host: true
kibana_index: ".kibana"
kibana_elasticsearch_username: toto
kibana_elasticsearch_password: aaaaaa
default_app_id: "discover"
request_timeout: 300000
shard_timeout: 0
verify_ssl: true
bundled_plugin_ids:
 - plugins/dashboard/index
 - plugins/discover/index
 - plugins/doc/index
 - plugins/kibana/index
 - plugins/markdown_vis/index
 - plugins/metric_vis/index
 - plugins/settings/index
 - plugins/table_vis/index
 - plugins/vis_types/index
 - plugins/visualize/index

```

I have tested connection use the folllowing url and it's works

curl -u toto:aaaaaa [http://localhost:9200](http://localhost:9200)  
{  
"status" : 200,  
"name" : "ELK INT",  
"cluster\_name" : "elasticsearch",  
"version" : {  
"number" : "1.7.0",  
"build\_hash" : "929b9739cae115e73c346cb5f9a6f24ba735a743",  
"build\_timestamp" : "2015-07-16T14:31:07Z",  
"build\_snapshot" : false,  
"lucene\_version" : "4.10.4"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 22, 2015, 12:15pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/4 "2015-10-22T12:15:10Z")

</div>

Can you try to curl `http://localhost:9200/_cluster/health` instead? The root URL only requires authentication and not authorization.

---

<div class="post-metadata">

**Author:** ![Pierre\_Jacquot](https://avatars.discourse-cdn.com/v4/letter/p/e274bd/32.png) [@Pierre\_Jacquot](https://discuss.elastic.co/u/Pierre_Jacquot)\
**Post date:** [October 22, 2015, 7:15pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/5 "2015-10-22T19:15:25Z")

</div>

Hello,

I have test it, and I get an error of authorization also.  
I have checked the following parameters

```
> shield.authc.realms.default.files.roles: /etc/elasticsearch/shield/roles

```

and correct it with

```
shield.authc.realms.default.files.roles: /etc/elasticsearch/shield/roles.yml

```

but I still have an issue.

😕

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 22, 2015, 7:33pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/6 "2015-10-22T19:33:00Z")

</div>

Ah, I think the issue is that setting should be:

```auto
shield.authz.store.file.roles: /etc/elasticsearch/shield/roles.yml

```

---

<div class="post-metadata">

**Author:** ![Pierre\_Jacquot](https://avatars.discourse-cdn.com/v4/letter/p/e274bd/32.png) [@Pierre\_Jacquot](https://discuss.elastic.co/u/Pierre_Jacquot)\
**Post date:** [October 23, 2015, 7:19am UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/7 "2015-10-23T07:19:53Z")

</div>

Hello Jaymode,

I have updated the line as you tell me to do and it's works as expected !  
Thanks for your help !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/shield-kibana-error-on-startup/32591/8 "2017-07-06T13:48:10Z")

</div>


