# \_async\_search thowing access denieds in elasticsearch audit logs

**URL:** <https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811>\
**Category:** Elasticsearch\
**Created:** [November 9, 2020, 6:38pm UTC](https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811 "2020-11-09T18:38:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 9, 2020, 6:38pm UTC](https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811/1 "2020-11-09T18:38:28Z")

</div>

Hello,

So I made a SIEM rule which triggers on `access_denied` in `event.action` on Elastic audit logs.

And so I discovered the user `_async_search` triggers this rule.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a553c55596c36fd7acc00903e820e857e6d4d562.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/4/84057f9ac32db0b24912736708ee8d6376fa57f0.png)

I guess I can safely exclude this, but I'm curious what is causing this. Any feedback on the behaviour of `_async_search`, is the above expected?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 9, 2020, 9:51pm UTC](https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811/2 "2020-11-09T21:51:36Z")

</div>

That would relate to [https://www.elastic.co/guide/en/elasticsearch/reference/7.9/async-search.html](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/async-search.html).

You'd have to figure out what is asking that request, is there more to the event?

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [November 10, 2020, 8:38am UTC](https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811/3 "2020-11-10T08:38:36Z")

</div>

Thanks @warkolm for your answer. I already read through the documentation. There is not a lot of extra info I can give you. The access denieds alwasy seem to come from Kibana nodes and always have

```
"action":"cluster:admin/tasks/cancel"
"request.name":"CancelTasksRequest"

```

As this is a user provided by Elastic, I don't know if and what I should do with these access denieds. Imho, this seems like a bug or a questionable async search consequence. The original queries I know which were related were all executed by superusers, so at first sight I see no reason why an access denied is being thrown.

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2020, 8:38am UTC](https://discuss.elastic.co/t/async-search-thowing-access-denieds-in-elasticsearch-audit-logs/254811/4 "2020-12-08T08:38:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
