<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Prometheus can't scrape metrics in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412566#M253545</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;Thanks a lot for your help!&lt;/P&gt;&lt;P&gt;My mistake was that I specified the CN in the username as I did earlier when setting up the nifi-registry user, now I entered it without the CN exactly as it is displayed in the user-log and as you said, and this solved the problem.&amp;nbsp; Thanks again!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blackboks_0-1759419267567.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46358i0C0A058F809C8995/image-size/large?v=v2&amp;amp;px=999" role="button" title="blackboks_0-1759419267567.png" alt="blackboks_0-1759419267567.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Oct 2025 15:35:25 GMT</pubDate>
    <dc:creator>blackboks</dc:creator>
    <dc:date>2025-10-02T15:35:25Z</dc:date>
    <item>
      <title>Prometheus can't scrape metrics</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412559#M253543</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Following the advice from this post:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://community.cloudera.com/t5/Support-Questions/Accessing-NIFI-Metrics-endpoint-for-Prometheus-without/m-p/399710#M250535" target="_blank" rel="noopener"&gt;https://community.cloudera.com/t5/Support-Questions/Accessing-NIFI-Metrics-endpoint-for-Prometheus-without/m-p/399710#M250535&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm trying to set up certificate authentication/authorization from prometheus server to nifi, but getting 403 Forbidden.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Nifi user log i can see that authentication CN of certificate is successful, further&amp;nbsp; comes the 403 error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blackboks_0-1759412399877.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46351i30E3BED42B5F5785/image-size/large?v=v2&amp;amp;px=999" role="button" title="blackboks_0-1759412399877.png" alt="blackboks_0-1759412399877.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Prometheus scrape config:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blackboks_1-1759412984854.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46352i8D174C42E368BB21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="blackboks_1-1759412984854.png" alt="blackboks_1-1759412984854.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blackboks_2-1759413177931.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46353i041AB33D20E9341D/image-size/large?v=v2&amp;amp;px=999" role="button" title="blackboks_2-1759413177931.png" alt="blackboks_2-1759413177931.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please tell what is wrong here?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 13:54:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412559#M253543</guid>
      <dc:creator>blackboks</dc:creator>
      <dc:date>2025-10-02T13:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Prometheus can't scrape metrics</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412564#M253544</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/126568"&gt;@blackboks&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;All actions performed against&amp;nbsp; secured NiFi require proper authentication and authorization.&amp;nbsp; &amp;nbsp;It appears you have successful authentication via. mutualTLS exchange, but you are missing the proper authorization needed for the rest-api endpoint you are trying to access.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The shared nifi-user.log entry tells you which authorization policy is missing for the user that is needed for the request endpoint /nifi-api/flow/metrics/prometheus:&lt;BR /&gt;&lt;BR /&gt;"view the user interface" which authorizes a user to /flow NiFI resource.&lt;BR /&gt;&lt;BR /&gt;I don't know how your NIFi has been configured to for authorization, but the most common setup uses the managed-authorizer.&lt;BR /&gt;&lt;BR /&gt;From the NiFi UI you can access the global policies from the NIFi global menu in the upper right corner of UI.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_0-1759415595493.png" style="width: 347px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46354iE3F4B4C785216231/image-dimensions/347x942?v=v2" width="347" height="942" role="button" title="MattWho_0-1759415595493.png" alt="MattWho_0-1759415595493.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;"Policies" will open a new UI, where you can select "view the user interface" fomr the drop down selection:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_1-1759415685567.png" style="width: 709px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46355iED5E465AA62E79BD/image-dimensions/709x248?v=v2" width="709" height="248" role="button" title="MattWho_1-1759415685567.png" alt="MattWho_1-1759415685567.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then you can click on the person icon to the right to authorize additional user identities.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_2-1759415794142.png" style="width: 564px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46356iD07716324BE745ED/image-dimensions/564x451?v=v2" width="564" height="451" role="button" title="MattWho_2-1759415794142.png" alt="MattWho_2-1759415794142.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Your list of user will be different.&amp;nbsp; What is important to note is NiFi user and group identities are case sensitive and must match exactly.&amp;nbsp; So the exact user identity shown in the nifi-user.log is the one that needs to be added to the "view the user interface" policy.&lt;BR /&gt;&lt;BR /&gt;If this user is not in the list, you must first add that user identity and then you will be able to authorize it.&amp;nbsp; This can be done if you are using the managed-authorizer with the file-user-group-provider.&amp;nbsp; If so, you can access "Users" from the NiFi global menu to open the NiFi Users UI:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MattWho_3-1759416087894.png" style="width: 695px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46357i6F216DC9FA22122F/image-dimensions/695x323?v=v2" width="695" height="323" role="button" title="MattWho_3-1759416087894.png" alt="MattWho_3-1759416087894.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From there you can use the "+" icon to the right to add a new user identity. Remember that user identity string must match exactly case sensitive with what is shown in nifi-user.log; otherwise, it will be treated asa different user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help our community grow. If you found&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;any&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on&amp;nbsp;&lt;STRONG&gt;one or more&lt;/STRONG&gt;&amp;nbsp;of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 14:44:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412564#M253544</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2025-10-02T14:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Prometheus can't scrape metrics</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412566#M253545</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp;Thanks a lot for your help!&lt;/P&gt;&lt;P&gt;My mistake was that I specified the CN in the username as I did earlier when setting up the nifi-registry user, now I entered it without the CN exactly as it is displayed in the user-log and as you said, and this solved the problem.&amp;nbsp; Thanks again!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="blackboks_0-1759419267567.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/46358i0C0A058F809C8995/image-size/large?v=v2&amp;amp;px=999" role="button" title="blackboks_0-1759419267567.png" alt="blackboks_0-1759419267567.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 15:35:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Prometheus-can-t-scrape-metrics/m-p/412566#M253545</guid>
      <dc:creator>blackboks</dc:creator>
      <dc:date>2025-10-02T15:35:25Z</dc:date>
    </item>
  </channel>
</rss>

