# Xpack defaults, beats\_system authentication error

**URL:** <https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870>\
**Category:** Elasticsearch\
**Created:** [August 31, 2018, 1:40pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870 "2018-08-31T13:40:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [August 31, 2018, 1:40pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870/1 "2018-08-31T13:40:37Z")

</div>

We are running Elasticsearch 6.3.2 on our system and xpack.security.enabled is set to true on only the elastic nodes within our system. I have also ran the bin/elasticsearch-setup-passwords interactive setup on all three of our nodes so we have changed all of the passwords for elastic, kibana, logstash\_system and beats\_system. If you need any other info please let me know, first time poster here.

So a really basic question here but after reading the documentation for Elastic, Kibana and Logstash its stated that in Kibana that xpack.security.enabled is set to true by default. However when I go into our kibana.yml files there is nothing within the text that is set to xpack.security.enabled: true. Does this mean that I actually have to input xpack.security.enabled: true in order to turn xpack on in kibana?

Also, our system is getting an; elasticsearch: [2018-08-31T08:33:50,289][INFO][o.e.x.s.a.AuthenticationService] [dch1090ql5app] Authentication of [beats\_system] was terminated by realm [reserved] - failed to authenticate user [beats\_system] error message and if I took a guess it has something to do with the fact that I ran the bin/elasticsearch-setup-passwords interactive command and changed the passwords. It seems to me that I'm missing a few steps in here and some help would be appreciated. If you could point me to what changes need to be made so that things can communicate again that would be appreciated. Thank you elastic community and enjoy your day!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 31, 2018, 2:01pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870/2 "2018-08-31T14:01:23Z")

</div>

Hi Ryan,

Security [is enabled by default in kibana](https://www.elastic.co/guide/en/kibana/6.3/security-settings-kb.html#general-security-settings), you don't need to set

```auto
xpack.security.enabled: true

```

explicitly.

> [@Ryan\_Downey](#):
>
> I have also ran the bin/elasticsearch-setup-passwords interactive setup on all three of our nodes

You don't need to run this in all your nodes, you should only need to run it once in your cluster.

> [@Ryan\_Downey](#):
>
> Also, our system is getting an; elasticsearch: [2018-08-31T08:33:50,289][INFO][o.e.x.s.a.AuthenticationService] [dch1090ql5app] Authentication of [beats\_system] was terminated by realm [reserved] - failed to authenticate user [beats\_system] error message

This is your beats instance trying to communicate to Elasticsearch and failing. You need to go and [set the newly configured beats\_system password](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/built-in-users.html#add-built-in-user-passwords) in each one of your beats.

---

<div class="post-metadata">

**Author:** ![Ryan\_Downey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_downey/32/35987_2.png) [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Post date:** [August 31, 2018, 6:17pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870/3 "2018-08-31T18:17:39Z")

</div>

> [@ikakavas](#):
>
> Authentication of [beats\_system] was terminated by realm [reserved]

Does this need to go in the elasticsearch, logstash or kibana yml file?  
xpack.monitoring.elasticsearch.username: beats\_system  
xpack.monitoring.elasticsearch.password: beatspassword

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 31, 2018, 6:54pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870/4 "2018-08-31T18:54:01Z")

</div>

Please see [the docs on how to set up your beats for security](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/beats.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2018, 7:07pm UTC](https://discuss.elastic.co/t/xpack-defaults-beats-system-authentication-error/146870/5 "2018-09-28T19:07:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
