# Vega - Request must contain a kbn-xsrf header

**URL:** https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890
**Category:** Kibana
**Tags:** vega
**Created:** [August 5, 2020, 3:09pm UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890 "2020-08-05T15:09:59Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![TVxJVOV](https://avatars.discourse-cdn.com/v4/letter/t/9de053/32.png) [@TVxJVOV](https://discuss.elastic.co/u/TVxJVOV)
#### Post date: [August 5, 2020, 3:10pm UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/1 "2020-08-05T15:10:00Z")

</div>

Hi!  
I am new to Kibana. I hope I am using all the terminology in the right way.  
I am currently working on a Vega viz and I am getting a weird error message.  
It comes when I do a search query to elastic API. It says:

```auto
    statusCode	400
    error	"Bad Request"
    message	"Request must contain a kbn-xsrf header."

```

The above message is the response from Elasticsearch.  
I tried adding a kbn-xsrf header in the API-query:

```auto
    url: {
        %context%: true 
        %timefield%: ts 
        index: fra2020
        header:{
          kbn-xsrf: true
        }
        body: {
          size: 87000,
          _source: ['ip']
        }
    }

```

I found in the documentation that the kbn-xsrf must be set to true. But it didn’t do the trick.  
Any help or pointer in the right direction would be greatly appreciated.

Cheers

---

<div class="post-metadata">

### Author: ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)
#### Post date: [August 5, 2020, 8:20pm UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/2 "2020-08-05T20:20:47Z")

</div>

Hello,

Where are you seeing this message please? And are your other kibana visualizations working fine?

Thanks,  
Bhavya

---

<div class="post-metadata">

### Author: ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)
#### Post date: [August 5, 2020, 9:22pm UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/3 "2020-08-05T21:22:25Z")

</div>

I've had to add that header when making custom plugins and sending data to ES but never in Vega.

What version of Kibana is this?

What do you get if you do the below?

```auto
    url: {
        index: fra2020
    }

```

---

<div class="post-metadata">

### Author: ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)
#### Post date: [August 5, 2020, 9:31pm UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/4 "2020-08-05T21:31:25Z")

</div>

Just looked at the request headers from a Vega Viz Elastic API call and it doesn't pass kbn-xsrf in.

```auto
:authority:
:method: POST
:path: /elasticsearch/kibana_sample_data_logs/_search
:scheme: https
accept: */*
accept-encoding: gzip, deflate, br
accept-language: en-US,en;q=0.9
content-length: 269
content-type: application/json
cookie: sid=
kbn-version: 7.8.0
origin: 
referer: 
sec-fetch-dest: empty
sec-fetch-mode: cors
sec-fetch-site: same-origin
user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36

```

Where are you seeing this error? Do you know how to see the request in your browser dev tools?

---

<div class="post-metadata">

### Author: ![TVxJVOV](https://avatars.discourse-cdn.com/v4/letter/t/9de053/32.png) [@TVxJVOV](https://discuss.elastic.co/u/TVxJVOV)
#### Post date: [August 6, 2020, 5:50am UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/5 "2020-08-06T05:50:24Z")

</div>

Hi!

I see the error when I open the web developer inspector in Firefox.  
I hope I do as described in the [docs](https://www.elastic.co/guide/en/kibana/current/vega-debugging.html).

I use the "networking tab" to see the JSON file that localhost is sending back to me.  
The screenshot below shows how I go about debugging:

 ![Skärmavbild 2020-08-06 kl. 07.54.27](https://us1.discourse-cdn.com/elastic/original/3X/4/3/4338b32839daed202ae9aacf6fff33fd589a2f97.png)

When I double-click on the file "\_search" i get the following response from Firefox:

![Skärmavbild 2020-08-06 kl. 07.57.18](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b69fc3f7587669489421db450a6e5379e480a07.png)

I believe that the file "\_search" is where my data should be stored.

My other visualizations that don't rely on Vega are working.  
Just to make matters even weirder i noticed the following:  
I have a Vega-lite visualization that worked and suddenly stopped working.  
I get the same error.

Kibana version: 7.8.1  
Elasticsearch version: 7.8.1

Thanks

---

<div class="post-metadata">

### Author: ![TVxJVOV](https://avatars.discourse-cdn.com/v4/letter/t/9de053/32.png) [@TVxJVOV](https://discuss.elastic.co/u/TVxJVOV)
#### Post date: [August 6, 2020, 6:12am UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/6 "2020-08-06T06:12:10Z")

</div>

Now I see the error of my ways.  
When I click the "Reponse" tab I see the actual JSON response.  
And there I see the result that I am looking for. My API-request is working fine.

Thank you bhavyarm and aaron\_nimocks for pointing me in the right direction.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 3, 2020, 6:12am UTC](https://discuss.elastic.co/t/vega-request-must-contain-a-kbn-xsrf-header/243890/7 "2020-09-03T06:12:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
