# Add resiliency on .security-7 index

**URL:** https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121
**Category:** Elasticsearch
**Created:** [July 11, 2023, 2:51pm UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121 "2023-07-11T14:51:57Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Josselin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josselin/32/142659_2.png) [@Josselin](https://discuss.elastic.co/u/Josselin)
#### Post date: [July 11, 2023, 2:51pm UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121/1 "2023-07-11T14:51:57Z")

</div>

Hi,

During multiple incident with cluster restart we lost the nodes where the index .security-7 was stored. It had a huge impact and we want to avoid as much as possible this situation to occur again.

We have seen on the index the setting : `index.auto_expand_replicas` which we would want to edit and tune to our needs.  
We tried to update the settings using informations found on old thread / internet with no result.

In our last attempts we had a role with rights like :

```auto
{
  "indices": [
    {
      "names": ["*",".*"],
      "privileges": ["manage", "all"],
      "allow_restricted_indices": true
    }
  ]
}

```

but we got this issue when trying to update the settings :

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "illegal_state_exception",
        "reason": "Cannot override settings on system indices: [.security-[0-9]+*] -> [index.auto_expand_replicas]"
      }
    ],
    "type": "illegal_state_exception",
    "reason": "Cannot override settings on system indices: [.security-[0-9]+*] -> [index.auto_expand_replicas]"
  },
  "status": 500
}

```

If someone has information to share about this topic we would be glad 🙂

Thank you !

---

<div class="post-metadata">

### Author: ![vincenbr](https://avatars.discourse-cdn.com/v4/letter/v/8edcca/32.png) [@vincenbr](https://discuss.elastic.co/u/vincenbr)
#### Post date: [July 11, 2023, 4:41pm UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121/2 "2023-07-11T16:41:43Z")

</div>

Changing number of replica has been forbidden on system indices (including .security) . This might change in the future, you can refer to [Productize a way to change index.auto\_expand\_replicas and index.number\_of\_replicas settings on the .security index · Issue #92992 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/92992)

Tip: for cluster outages due to `.security` index being unavailable, you can set a "file realm" in order to mitigate the situation. See [File-based user authentication | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.8/file-realm.html#file-realm)

---

<div class="post-metadata">

### Author: ![Josselin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josselin/32/142659_2.png) [@Josselin](https://discuss.elastic.co/u/Josselin)
#### Post date: [July 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121/3 "2023-07-17T09:23:39Z")

</div>

Thank you very much Vincent for your time and answer.

We will monitor the issue in hope this change in the future 🙂

We already have a file realm for some accounts but would expect all dynamic accounts not using a file realm to keep working 😕

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 14, 2023, 9:24am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121/4 "2023-08-14T09:24:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
