# User not found in cache for realm

**URL:** <https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428>\
**Category:** Elasticsearch\
**Created:** [October 26, 2017, 1:14pm UTC](https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428 "2017-10-26T13:14:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [October 26, 2017, 1:14pm UTC](https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428/1 "2017-10-26T13:14:20Z")

</div>

I am trying to figure out why a native user is getting a 401 from a remote server. I have configured Filebeat to authenticate via native (the only realm I have set up), and I've created the user with a custom role (as shown below). When I try to run Filebeat on the remote server, it returns a 401 with the following errors logged in Elasticsearch:

```
[2017-10-26T07:54:19,831][DEBUG][o.e.x.s.a.e.ReservedRealm] [EMCTS499] user [cpe_filebeat] not found in cache for realm [reserved], proceeding with normal authentication
[2017-10-26T07:54:19,831][DEBUG][o.e.x.s.a.e.NativeRealm] [EMCTS499] user [cpe_filebeat] not found in cache for realm [native1], proceeding with normal authentication
[2017-10-26T07:54:19,837][DEBUG][r.suppressed] path: /, params: {}
org.elasticsearch.ElasticsearchSecurityException: unable to authenticate user [cpe_filebeat] for REST request [/]

```

However, if I make a call to the API from the host, it works without any errors. This is what I used to create the role (I use Postman, since it's hosted on a Windows box):

```
POST {{ES}}/_xpack/security/role/cpe_filebeat_writer
{
	"cluster": ["manage_index_templates", "monitor"],
	"indices": [
		{
			"names": ["httpderrorlog-test-*", "httplog-test-*"],
			"privileges": ["read", "write", "create_index"]
		}
	]
}

```

And this is the user I created:

```
POST {{ES}}/_xpack/security/user/cpe-filebeat
{
	"password" : "redacted",
	"roles" : "cpe_filebeat_writer",
	"full_name" : "Indexing Test Account",
	"enabled" : true
}

```

Here's the x-pack config from elasticsearch.yml

```
xpack.security.enabled: true
xpack.security.http.filter.enabled: true
xpack.security.http.filter.allow: ["IP ranges go here"]
xpack.security.http.filter.deny: _all
xpack.security.transport.filter.enabled: true
xpack.security.transport.filter.allow: "IP range goes here"
xpack.security.transport.filter.deny: _all
xpack.security.authc.realms:
  native1:
    type: native
    order: 0

```

And here's the filebeat.yml config that's running on the remote server:

```
filebeat.prospectors:

- input_type: log
  paths:
    - /var/log/httpd/error_log

- input_type: log
  paths:
    - /usr/local/redacted/logs/HttpLog
  include_lines: ["Response"]

output.elasticsearch:
  hosts: ["IP with HTTP port goes here"]

  protocol: "http"
  username: "cpe_filebeat"
  password: "redacted"

  index: "httpderrorlog-test-%{+yyyy.MM.dd}"
  indices:
    - index: "httplog-test-%{+yyyy.MM.dd}"
      when.contains:
        message: "Response"

```

What am I missing?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [October 26, 2017, 4:09pm UTC](https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428/2 "2017-10-26T16:09:11Z")

</div>

Hmm in one place you use a `-` and a `_` in the other. Is it `cpe-filebeat` or `cpe_filebeat`?

---

<div class="post-metadata">

**Author:** ![Speedman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/speedman/32/37066_2.png) [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Post date:** [October 26, 2017, 4:56pm UTC](https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428/3 "2017-10-26T16:56:15Z")

</div>

It's always a typo :-/ Thanks for catching that. It's definitely supposed to be a hyphen, not an underscore. As soon as I fixed that, everything started to flow.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2017, 4:56pm UTC](https://discuss.elastic.co/t/user-not-found-in-cache-for-realm/105428/4 "2017-11-23T16:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
