# Graylog first installation - You cannot access this resource, missing authorization header!

**URL:** <https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328>\
**Category:** Graylog Central (peer support)\
**Created:** [January 25, 2024, 1:38pm UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328 "2024-01-25T13:38:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 25, 2024, 1:38pm UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/1 "2024-01-25T13:38:16Z")

</div>

Hello everyone, i’m asking for your support, i am not able to resolve the following issue :

\*\*1. Unable to access webadmin  
The installation went wel, all service are up and ready, but when i try to access Graylog Webadmin i get the following popup :  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/8/a/8a6cfc65d1969c0e487f686b16e0b2d11092d283.png)  
Just like an .htaccess secure prompt  
When i close that prompt i got the following :  
“You cannot access this resource, missing authorization header!”

I’ve tried to run Graylog server behing an apache or a nginx proxy (classic or ssl).  
I got always the same issue.  
I think something is wrong in my graylog server.conf  
I have modified http bind address according to my current setup.  
For example, now, direct access to graylog from another network (without proxy) so http\_bind\_address = 0.0.0.0:9000  
I d’on’t really understand graylog security features, so i might be missing something.

**2. Environment:**

- OS Information: Debian 11

- Package Version: Graylog 5.2, opensearch v2.11.1, mongoDB v7.0.5

Any help would be really appreciated

Thank you

Regards

---

<div class="post-metadata">

**Author:** ![drewmiranda-gl](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/drewmiranda-gl/32/13376_2.png) [@drewmiranda-gl](https://community.graylog.org/u/drewmiranda-gl)\
**Post date:** [January 29, 2024, 9:33pm UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/2 "2024-01-29T21:33:59Z")

</div>

Do you have `elasticsearch_hosts` configured in `server.conf`?

My guess is this is related to the datanode feature recently added, see [Prerequisites](https://go2docs.graylog.org/5-2/setting_up_graylog/graylog_data_node_getting_started.htm?TocPath=Graylog+Data+Node%7CGetting+Started+with+the+Graylog+Data+Node%7C _____ 0)

The username/password is in the log file of the graylog node. However, if you are not using datanode that setup process won’t be very helpful.

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 30, 2024, 10:46am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/3 "2024-01-30T10:46:44Z")

</div>

Hello and thank you,

That is the exact problem, good gess.

My graylog server don’t see any data node even if Opensearch is installed and well configured (hope so).  
Any advices for graylog-server.conf for opensearch (named elasticsearch in the conf file)?  
curl 127.0.0.1:9200 works well, but my graylog server doesn’t seem to see the opensearch instance…

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 30, 2024, 10:47am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/4 "2024-01-30T10:47:49Z")

</div>

“Do you have `elasticsearch_hosts` configured in `server.conf` ?”

I let default parameters

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 30, 2024, 10:54am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/5 "2024-01-30T10:54:05Z")

</div>

elasticsearch\_hosts = [http://127.0.0.1:9200](http://127.0.0.1:9200)  
Correction, i have uncommented this, maybe too late. (After preflight i think)  
I wanted to reinstall everything.  
Do i have to set others parameters for opensearch in server.conf?  
What do you think?

Thank you

---

<div class="post-metadata">

**Author:** ![valhaim](https://avatars.discourse-cdn.com/v4/letter/v/67e7ee/32.png) [@valhaim](https://community.graylog.org/u/valhaim)\
**Post date:** [January 30, 2024, 1:36pm UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/6 "2024-01-30T13:36:58Z")

</div>

Is this the first login after installation? If so, the access data is in the log: /var/log/graylog-server/server.log

It seems to be a similar problem like in this thread: [Webinterface login refused!](https://community.graylog.org/t/webinterface-login-refused/31290)

---

<div class="post-metadata">

**Author:** ![drewmiranda-gl](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/drewmiranda-gl/32/13376_2.png) [@drewmiranda-gl](https://community.graylog.org/u/drewmiranda-gl)\
**Post date:** [January 30, 2024, 6:59pm UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/7 "2024-01-30T18:59:34Z")

</div>

Settings `elasticsearch_hosts` should be sufficient. This is no longer an optional configuration parameter if you are maintaining opensearch (as opposed to using datanode).

I believe you can update that setting to point to your OpenSearch cluster. If this does not work though you may need to:

1. stop graylog-server
2. remove the graylog mongodb database
3. update `server.conf` to configure `elasticsearch\_hosts1
4. start graylog-server

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 31, 2024, 7:51am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/8 "2024-01-31T07:51:59Z")

</div>

Good morning Valhaim, and thank you,

Yes i found those credential, i’ve done preflight but my graylogserver was unable to find the datanode (in my case opensearch). I kindda ignore that. But then i access to the normal UI, made an input, saw log arriving on the server, but no data collection because of missing datanode

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/5/9/593cd6e8b756cbb2e26a42358caa2ad1a54a487e.png)

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 31, 2024, 7:55am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/9 "2024-01-31T07:55:05Z")

</div>

Morning Drew,  
Do you think i have to completely remove mongoDB? Are only the base that contain Graylog parameters?

---

<div class="post-metadata">

**Author:** ![brinch](https://avatars.discourse-cdn.com/v4/letter/b/9dc877/32.png) [@brinch](https://community.graylog.org/u/brinch)\
**Post date:** [January 31, 2024, 8:15am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/10 "2024-01-31T08:15:39Z")

</div>

THank you Drew,  
I’ve just tried your recommandations

1. stop graylog-server
2. remove the graylog mongodb database
3. update `server.conf` to configure `elasticsearch\_hosts1
4. start graylog-server  
Unfortunately, it didn’t work… Still node datanode found. I will try to reinstall the whole thing.  
Have a good day.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 14, 2024, 8:16am UTC](https://community.graylog.org/t/graylog-first-installation-you-cannot-access-this-resource-missing-authorization-header/31328/11 "2024-02-14T08:16:32Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
