# Action \[indices:admin/create\] is unauthorized for user

**URL:** <https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 27, 2023, 1:33pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990 "2023-09-27T13:33:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![brunoflament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brunoflament/32/126057_2.png) [@brunoflament](https://discuss.elastic.co/u/brunoflament)\
**Post date:** [September 27, 2023, 1:33pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/1 "2023-09-27T13:33:23Z")

</div>

Hi,  
I try to create a index but i have this error :

PUT toto-1 ( curl -k -u "logstash:password" -X PUT "[https://localhost:9200/toto-1](https://localhost:9200/toto-1))  
`{"error":{"root_cause":[{"type":"security_exception","reason":"action [indices:admin/create] is unauthorized for user [logstash] with effective roles [eck_logstash_user_role] on indices [toto-1], this action is granted by the index privileges [create_index,manage,all]"}],"type":"security_exception","reason":"action [indices:admin/create] is unauthorized for user [logstash] with effective roles [eck_logstash_user_role] on indices [toto-1], this action is granted by the index privileges [create_index,manage,all]"},"status":403}`

GET \_security/user/logstash

```auto
 "logstash" : {
    "username" : "logstash",
    "roles" : [
      "eck_logstash_user_role"
    ],
    "full_name" : null,
    "email" : null,
    "metadata" : { },
    "enabled" : true
  }
}

```

GET \_security/role/eck\_logstash\_user\_role

```auto
{
  "eck_logstash_user_role" : {
    "cluster" : [
      "all"
    ],
    "indices" : [
      {
        "names" : [
          "toto-*"
        ],
        "privileges" : [
          "all"
        ],
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

Where is the problem ? Any help is greats (edited)

Regards  
Bruno

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 27, 2023, 11:21pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/2 "2023-09-27T23:21:46Z")

</div>

Hi @brunoflament, Welcome to the community.

What Version?

What user were you logged in with when you created that role?

Ask just in case because a user can not create a role with more privileges than the user logged in.

the API will accept creating the role, but when executed, it will be the intersection of the roles (the user creating the role and the role created / used)

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 29, 2023, 6:49am UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/3 "2023-09-29T06:49:51Z")

</div>

> [@stephenb](#):
>
> Ask just in case because a user can not create a role with more privileges than the user logged in. The API will accept creating the role, but when executed, it will be the intersection of the roles (the user creating the role and the role created / used)

This is true for API keys, but not for users+roles. Users with `manage_security` can create a role that grants any access they wish, regardless of what access they themselves have.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 29, 2023, 6:52am UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/4 "2023-09-29T06:52:18Z")

</div>

> [@brunoflament](#):
>
> GET \_security/role/eck\_logstash\_user\_role

Is is possible that there is a separate definition of that role stored in the `roles.yml` file in the configuration directory of the node?

If so, the file based role will take precedence.

You can check the user's effective privileges by calling:

```auto
curl -k -u "logstash" "https://localhost:9200/_security/user/_privileges"

```

If that doesn't match your `eck_logstash_user_role` then it probably means that the node is using a different role.

---

<div class="post-metadata">

**Author:** ![brunoflament](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brunoflament/32/126057_2.png) [@brunoflament](https://discuss.elastic.co/u/brunoflament)\
**Post date:** [September 29, 2023, 8:09am UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/5 "2023-09-29T08:09:56Z")

</div>

Hello !

Yes !!

```auto
{"cluster":["cluster:admin/ingest/pipeline/get","manage_ilm","manage_index_templates","manage_logstash_pipelines","monitor","read_ilm"],"global":[],"indices":[{"names":["ecs-logstash","ecs-logstash-*","logs-*","logstash","logstash-*","metrics-*","synthetics-*","traces-*"],"privileges":["create_index","manage","read","view_index_metadata","write"],"allow_restricted_indices":false}],"applications":[],"run_as":[]}

```

The solution is 🙂 [Configuration examples | Elastic Cloud on Kubernetes [2.9] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-logstash-configuration-examples.html#k8s-logstash-configuration-custom-index)

Regards  
Bruno Flament

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 29, 2023, 12:59pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/6 "2023-09-29T12:59:06Z")

</div>

> [@TimV](#):
>
> This is true for API keys, but not for users+roles. Users with `manage_security` can create a role that grants any access they wish, regardless of what access they themselves have.

Woah I did not realize that Today I Learned!

Thanks @TimV !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2023, 1:00pm UTC](https://discuss.elastic.co/t/action-indices-admin-create-is-unauthorized-for-user/343990/7 "2023-10-27T13:00:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
