Elasticsearch默认凭证elastic:changeme认证失败,请求排查原因
First, let's confirm the error you're facing to ground our troubleshooting:
{ "error": { "root_cause": [ { "type": "security_exception", "reason": "failed to authenticate user [elastic]", "header": { "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\"" } } ], "type": "security_exception", "reason": "failed to authenticate user [elastic]", "header": { "WWW-Authenticate": "Basic realm=\"security\" charset=\"UTF-8\"" } }, "status": 401 }
This security_exception tells us Elasticsearch is rejecting your elastic:changeme credentials, and here are the most common fixes tailored to different Elasticsearch versions:
1. You're running Elasticsearch 8.x+ (the #1 reason this happens)
Starting with Elasticsearch 8.0, the old changeme default password was completely removed. During your first installation, Elasticsearch automatically generates a secure, random password for the elastic user and prints it directly to your console (look for a line like The password for the elastic user is: [your-unique-password]).
If you missed that password, reset it with this command from your Elasticsearch installation directory:
- Linux/macOS:
bin/elasticsearch-reset-password -u elastic - Windows:
bin\elasticsearch-reset-password.bat -u elastic
Follow the prompts, and it will generate a new valid password you can use immediately.
2. You enabled security on Elasticsearch 7.x manually
In 7.x versions, security features are disabled by default. If you turned them on by setting xpack.security.enabled: true in your elasticsearch.yml file, changeme won't work—you have to explicitly set up passwords first.
Run this tool to set passwords (choose interactive mode to pick your own, or auto for random generated ones):
bin/elasticsearch-setup-passwords interactive
Save the generated passwords somewhere safe—you'll need them for all future authenticated requests.
3. Double-check your security config
Take a quick look at your elasticsearch.yml file to rule out these edge cases:
- Ensure
xpack.security.enabledis set correctly. If it'sfalse, you shouldn't need to authenticate at all—but if it'strue, only the password you set/generated will work. - If you're on 8.x, Elasticsearch uses HTTPS by default. Make sure your client is connecting over
https://instead ofhttp://—some tools fail silently with auth errors if they use the wrong protocol.
4. Verify the elastic user exists
In rare cases, the elastic superuser might have been accidentally deleted. To check, run this command (use a valid admin password if you have one):
curl -u <admin-user>:<password> -XGET "http://localhost:9200/_security/user/elastic"
If it returns a 404, you'll need to recreate the elastic user with superuser privileges via the Elasticsearch security API.
内容的提问来源于stack exchange,提问作者Amine Maalfi

