# Action \[cluster:monitor/health\] is unauthorized for user

**URL:** <https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 9, 2019, 7:54am UTC](https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624 "2019-09-09T07:54:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Pillai](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@Nikhil\_Pillai](https://discuss.elastic.co/u/Nikhil_Pillai)\
**Post date:** [September 9, 2019, 7:54am UTC](https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624/1 "2019-09-09T07:54:41Z")

</div>

Hi,

I have configured LDAP with my single ELK node running locally. I have a user created on LDAP but that user is facing "unauthorized error" when I try to login to kibana UI or check the cluster health using curl command.

```auto
xpack.security.enabled: true
xpack.monitoring.collection.enabled: true
xpack:
  security:
    authc:
      realms:
        ldap1:
          type: ldap
          order: 0
          url: "ldap://172.16.16.63:10389"
          bind_dn: "cn=Nikhil Pillai, ou=people, o=sevenseas"
          user_search:
            base_dn: "ou=people,o=sevenseas"
            filter: "(cn={0})"
          group_search:
            base_dn: "ou=people,o=sevenseas"
          files:
            role_mapping: "role_mapping.yml"
          unmapped_groups_as_roles: false

```

I have assigned user to superuser role.  
GET /\_xpack/security/role\_mapping/admins?pretty

```auto
{
  "admins" : {
    "enabled" : true,
    "roles" : [
      "superuser"
    ],
    "rules" : {
      "field" : {
        "groups" : "cn=Nikhil Pillai,ou=people,o=sevenseas"
      }
    },
    "metadata" : { }
  }
}

```

Elasticsearch and Kibana version is 6.5.4.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [September 9, 2019, 3:23pm UTC](https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624/2 "2019-09-09T15:23:51Z")

</div>

> [@Nikhil\_Pillai](#):
>
> "field" : { "groups" : "cn=Nikhil Pillai,ou=people,o=sevenseas" }

This is not a group, this is the DN of your user. If you want to give the superuser role to your user only, you need to modify the role mapping to

```auto
POST /_xpack/security/role_mapping/admins
{
  "roles": ["superuser"],
  "enabled": true,
  "rules": {
    "field" : { "dn" : "cn=Nikhil Pillai,ou=people,o=sevenseas" }
  }
}

```

See our documentation also : [Role mapping resources | Elasticsearch Guide [6.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/role-mapping-resources.html)

---

<div class="post-metadata">

**Author:** ![Nikhil\_Pillai](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@Nikhil\_Pillai](https://discuss.elastic.co/u/Nikhil_Pillai)\
**Post date:** [September 10, 2019, 6:52am UTC](https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624/3 "2019-09-10T06:52:00Z")

</div>

Thank You. This worked..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2019, 6:52am UTC](https://discuss.elastic.co/t/action-cluster-monitor-health-is-unauthorized-for-user/198624/4 "2019-10-08T06:52:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
