# Latest Graylog-datanode not secure url and Authentication finally failed

**URL:** <https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220>\
**Category:** Graylog Central (peer support)\
**Created:** [March 14, 2025, 8:55am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220 "2025-03-14T08:55:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![wil](https://avatars.discourse-cdn.com/v4/letter/w/59ef9b/32.png) [@wil](https://community.graylog.org/u/wil)\
**Post date:** [March 14, 2025, 8:55am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/1 "2025-03-14T08:55:42Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
I have graylog-enterprise running using nginx proxy but its graylog-datanode in port 9200 has appearing not secure url and Authentication finally failed in web ui

**2. Describe your environment:**

- OS Information: CentOS

- Package Version: Stream 9

- Service logs, configurations, and environment variables:  
Authentication finally failed for null from [IP host]

**3. What steps have you already taken to try and solve the problem?**  
modify opensearch in config file location of datanode = unsolved  
modify datanode config related to certificate and authentication = unsolved

**4. How can the community help?**  
Please help to assist me on what file path needs to modify/fix the authenticated finally failed and its not secured url ? or is that a normal running gui of graylog-datanode integrated opensearch?

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/e/e/ee945bf5984a95a54b0f269b72a15061528e9e4e.png)

---

<div class="post-metadata">

**Author:** ![Joel\_Duffield](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Joel\_Duffield](https://community.graylog.org/u/Joel_Duffield)\
**Post date:** [March 14, 2025, 12:05pm UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/2 "2025-03-14T12:05:32Z")

</div>

What are you trying to do, because you arent supposed to be accessing datanode via the web, only thr main graylog server talks to it?

---

<div class="post-metadata">

**Author:** ![wil](https://avatars.discourse-cdn.com/v4/letter/w/59ef9b/32.png) [@wil](https://community.graylog.org/u/wil)\
**Post date:** [March 17, 2025, 2:27am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/3 "2025-03-17T02:27:30Z")

</div>

Hi @Joel_Duffield  
Appreciate your response,  
I’m trying to secure the web of datanode or do i need to secure it? Addionally, it appears Authentication finally failed its that a normal web interface of datanode? Please help thanks in advance 😇

---

<div class="post-metadata">

**Author:** ![Joel\_Duffield](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Joel\_Duffield](https://community.graylog.org/u/Joel_Duffield)\
**Post date:** [March 17, 2025, 10:09am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/4 "2025-03-17T10:09:35Z")

</div>

There is no web interface of datanode just some api endpoints that only the graylog server talks to. As long as you went through preflight then that connection is already secured.

---

<div class="post-metadata">

**Author:** ![wil](https://avatars.discourse-cdn.com/v4/letter/w/59ef9b/32.png) [@wil](https://community.graylog.org/u/wil)\
**Post date:** [March 18, 2025, 12:20am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/5 "2025-03-18T00:20:16Z")

</div>

Hi @Joel_Duffield

Noted on this I have running graylog-server but how about the message on port 9200? it says authentication finally failed do I need to do something to be authenticated when I access the port?  
Thanks in advanced 😇  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/3/0/3077fa5140b94e11e25111cb61b27da28898f6c6.png)

---

<div class="post-metadata">

**Author:** ![Joel\_Duffield](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Joel\_Duffield](https://community.graylog.org/u/Joel_Duffield)\
**Post date:** [March 18, 2025, 1:13am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/6 "2025-03-18T01:13:11Z")

</div>

When datanode is setup during preflight, it is setup to use certificates it generates as authentication, so the only way to access it is to generate a certificate for 3rd part access whixh yiu can do in the graylog UI

---

<div class="post-metadata">

**Author:** ![wil](https://avatars.discourse-cdn.com/v4/letter/w/59ef9b/32.png) [@wil](https://community.graylog.org/u/wil)\
**Post date:** [March 19, 2025, 1:38am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/7 "2025-03-19T01:38:50Z")

</div>

Hi @Joel_Duffield  
Thank you for the info I think there’s nothing I can do on graylog-datanode web since it already managed by graylog-server

Have a nice day.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [April 2, 2025, 1:39am UTC](https://community.graylog.org/t/latest-graylog-datanode-not-secure-url-and-authentication-finally-failed/35220/8 "2025-04-02T01:39:30Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
