# Unable to authenticate user for REST request

**URL:** <https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 18, 2020, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118 "2020-09-18T14:27:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhavikdhoot](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bhavikdhoot](https://discuss.elastic.co/u/bhavikdhoot)\
**Post date:** [September 18, 2020, 2:27pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/1 "2020-09-18T14:27:46Z")

</div>

Hi,

I'm trying to connect to Elasticsearch through FileBeats using the following config in my filebeat.yml.

output.elasticsearch:

# Array of hosts to connect to.

#hosts: ["localhost:9200"]  
hosts: ["server1:9600","server2:9600","server3:9600"]  
username: "4399xxxx"  
password: "abcdefgh"  
protocol: "https"  
ssl.certificate\_authorities: "/goldeneye-ca.crt"  
ssl.certificate: "/goldeneye.uk.hsbc-elk.crt"  
ssl.key: "/goldeneye.uk.hsbc-elk.key"  
index: "engg-%{+yyyy.MM.dd}"

But, while running FileBeat, getting the following error -

2020-09-18T19:54:29.972+0530 ERROR [publisher\_pipeline\_output] pipeline/output.go:155 Failed to connect to backoff(elasticsearch([https://server1:9600](https://server1:9600))): 401 Unauthorized: {"error":{"root\_cause":[{"type":"security\_exception","reason":"**unable to authenticate user [4399xxxx] for REST request [/]**","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}}],"type":"security\_exception","reason":"unable to authenticate user [4399xxxx] for REST request [/]","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}},"status":401}  
2020-09-18T19:54:29.972+0530 INFO [publisher\_pipeline\_output] pipeline/output.go:146 Attempting to reconnect to backoff(elasticsearch([https://server1:9600](https://server1:9600))) with 1 reconnect attempt(s)  
2020-09-18T19:54:29.972+0530 INFO [publisher] pipeline/retry.go:221 retryer: send unwait signal to consumer  
2020-09-18T19:54:29.974+0530 INFO [publisher] pipeline/retry.go:225 done

Appreciate any help regarding this.

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 20, 2020, 9:30pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/2 "2020-09-20T21:30:55Z")

</div>

Welcome to our community! 😃

Can you confirm that the username and password work?

---

<div class="post-metadata">

**Author:** ![bhavikdhoot](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bhavikdhoot](https://discuss.elastic.co/u/bhavikdhoot)\
**Post date:** [September 21, 2020, 3:39am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/3 "2020-09-21T03:39:50Z")

</div>

Hello,

Yes, the username/pwd works fine while using the same with 'curl' command or else through web browser too.

---

<div class="post-metadata">

**Author:** ![bhavikdhoot](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bhavikdhoot](https://discuss.elastic.co/u/bhavikdhoot)\
**Post date:** [September 22, 2020, 4:00am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/4 "2020-09-22T04:00:25Z")

</div>

Please let me know if anyone has any clue regarding this issue.

---

<div class="post-metadata">

**Author:** ![bhavikdhoot](https://avatars.discourse-cdn.com/v4/letter/b/c57346/32.png) [@bhavikdhoot](https://discuss.elastic.co/u/bhavikdhoot)\
**Post date:** [September 24, 2020, 5:56am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/5 "2020-09-24T05:56:15Z")

</div>

I was able to solve this error. In the Elasticsearch logs, it was throwing invalid credentials error where as in the filebeat output it shows the above error.  
Digging further, we found out that there is a bug in Elasticsearch wherein if there is one or more '$' in ur password then it will throw 'invalid credentials' error in Elasticsearch.

I changed my password without any '$' and it progressed further. I hope ELK team will take a note of it and fix this bug in next releases.  
Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 7:56am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-for-rest-request/249118/6 "2020-10-22T07:56:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
