# Action \[cluster:monitor/main\] is unauthorized for user

**URL:** <https://discuss.elastic.co/t/action-cluster-monitor-main-is-unauthorized-for-user/119074>\
**Category:** Elasticsearch\
**Created:** [February 8, 2018, 2:52pm UTC](https://discuss.elastic.co/t/action-cluster-monitor-main-is-unauthorized-for-user/119074 "2018-02-08T14:52:38Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Turbo\_Fredriksson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/turbo_fredriksson/32/27696_2.png) [@Turbo\_Fredriksson](https://discuss.elastic.co/u/Turbo_Fredriksson)\
**Post date:** [February 8, 2018, 10:44pm UTC](https://discuss.elastic.co/t/action-cluster-monitor-main-is-unauthorized-for-user/119074/2 "2018-02-08T22:44:45Z")

</div>

Well, several hours later, it seems that my `roles.yml` was WAY wrong!

This seems to work better:

```auto
admins:
  cluster:
    - all
  indices:
    - names:
        - "*"
      privileges:
        - all
devs:
  cluster:
    - manage
  indices:
    - names:
        - "20*"
      privileges:
        - write
        - delete
        - create_index
lbchk:
  cluster:
    - monitor
    - transport_client
  indices:
    - names:
        - ".marvel-es-*"
        - ".monitoring-*"
      privileges:
        - all

```

I took the opportunity to rename my 'LB check user' (kept getting `Username [something] is reserved and may not be used.`. But seems that no matter what username I use, I still get that..

---

_[View the full topic](https://discuss.elastic.co/t/action-cluster-monitor-main-is-unauthorized-for-user/119074)._
