Elasticsearch Transport Errors Unauthorized

Solution Unverified - Updated -

Issue

  • Fluentd dropping logs and getting the 401 error message:
2018-07-24 07:45:44 -0400 [warn]: temporarily failed to flush the buffer. next_retry=2018-07-24 07:45:45 -0400 error_class="Elasticsearch::Transport::Transport::Errors::Unauthorized" error="[401] " plugin_id="object:14f34e4"
  • Message in Elasticsearch with corresponding timestamp:
[2018-07-24 07:45:36,488][WARN ][rest.suppressed          ] path: /_bulk, params: {}
java.util.ConcurrentModificationException
  • Also seeing in Elasticsearch could not authenticate user messages:
[2018-07-24 16:28:35,715][INFO ][io.fabric8.elasticsearch.plugin.acl.DynamicACLFilter] Could not authenticate user
[2018-07-24 16:28:47,723][INFO ][io.fabric8.elasticsearch.plugin.acl.DynamicACLFilter] Could not authenticate user
[2018-07-24 16:28:59,711][INFO ][io.fabric8.elasticsearch.plugin.acl.DynamicACLFilter] Could not authenticate user
[2018-07-24 16:29:11,713][INFO ][io.fabric8.elasticsearch.plugin.acl.DynamicACLFilter] Could not authenticate user

Environment

  • Red Hat OpenShift Container Platform
    • 3.7
  • Logging-es image
    • 3.7.46

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content