# Alerting throws "node \[es-client1\] does not have the \[remote\_cluster\_client\] role"

**URL:** <https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073>\
**Category:** Kibana\
**Created:** [March 12, 2021, 10:01am UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073 "2021-03-12T10:01:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hrak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hrak/32/34222_2.png) [@hrak](https://discuss.elastic.co/u/hrak)\
**Post date:** [March 12, 2021, 10:01am UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073/1 "2021-03-12T10:01:36Z")

</div>

Hi all,

My cluster consists of the following nodes:

2x coordinating node (empty `node.roles`)  
3x master (node.roles = ['master'])  
5x data (node.roles = ['data', 'ingest', 'ml', 'transform'])

I have recently upgraded from 6.8.14 to 7.11.2, which went fairly smooth. The only issue is that Kibana alerting keeps throwing the following errors in the log:

```auto
{"type":"log","@timestamp":"2021-03-12T09:46:49+00:00","tags":["error","plugins","alerts","plugins","alerting"],"pid":18141,"message":"Executing Alert \"b0177aa0-8316-11eb-a876-59c2aec22f7c\" has resulted in Error: [illegal_argument_exception] node [es-client1] does not have the [remote_cluster_client] role"}
{"type":"log","@timestamp":"2021-03-12T09:46:49+00:00","tags":["error","plugins","alerts","plugins","alerting"],"pid":18141,"message":"Executing Alert \"b011fc60-8316-11eb-a876-59c2aec22f7c\" has resulted in Error: [illegal_argument_exception] node [es-client2] does not have the [remote_cluster_client] role"}

```

I am not using CCR so i was under the impression that none of my nodes required the `remote_cluster_client` role. Is this something that is required for Kibana monitoring/alerting to function?

Google was not really helpful, so i hope someone here can advise. Thanks!

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 17, 2021, 5:00pm UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073/2 "2021-03-17T17:00:12Z")

</div>

This could be related to cross cluster search, and not cross cluster replication.

Is there an alert defined that attempts to search to a remote cluster?

---

<div class="post-metadata">

**Author:** ![hrak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hrak/32/34222_2.png) [@hrak](https://discuss.elastic.co/u/hrak)\
**Post date:** [March 18, 2021, 12:07pm UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073/3 "2021-03-18T12:07:05Z")

</div>

As far as i can see there isn't, its a fairly stock installation after an upgrade from 6.8.14 to 7.11.2.

These are the alerts it came with:

 ![Screenshot 2021-03-18 at 13.06.00](https://us1.discourse-cdn.com/elastic/original/3X/c/4/c42be916d27bffc5174d85dc727bfe32aab78bfc.png)

---

<div class="post-metadata">

**Author:** ![belwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/belwood/32/77183_2.png) [@belwood](https://discuss.elastic.co/u/belwood)\
**Post date:** [April 6, 2021, 1:15pm UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073/4 "2021-04-06T13:15:34Z")

</div>

Any updates on this? I'm seeing the same behavior; also not using any remote cluster settings or CCR.

Also, it looks like I have 14 different 'stock' alerts that are producing the error:

CCR read exceptions  
CPU usage  
Cluster health  
Disk Usage  
Elasticsearch version mismatch  
Kibana version mismatch  
License expiration  
Logstash version mismatch  
Memory Usage (JVM)  
Missing monitoring data  
Nodes changed  
Shard size  
Thread pool search rejections  
Thread pool write rejections

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2021, 1:16pm UTC](https://discuss.elastic.co/t/alerting-throws-node-es-client1-does-not-have-the-remote-cluster-client-role/267073/5 "2021-05-04T13:16:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
