# Authorization Exception for SuperUser

**URL:** <https://discuss.elastic.co/t/authorization-exception-for-superuser/245311>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 17, 2020, 7:36pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311 "2020-08-17T19:36:41Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![apocalypse0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apocalypse0/32/45409_2.png) [@apocalypse0](https://discuss.elastic.co/u/apocalypse0)\
**Post date:** [August 17, 2020, 7:36pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/1 "2020-08-17T19:36:41Z")

</div>

I'm running Elastic 7.8.0 on the latest Debian 10. SSL and authentication is enabled. Everything has been working fine. I've been able to connect to the ES instance using all of the stack products and using the python elasticsearch python client. I created API keys to authenticate the application I am writing, and it has been working for all sorts of queries and updates except for the 'get' request. The details are as follows

When I use the elasticsearch-py library to run the following query  
`es.get(index="filebeat-*", id=id)`  
I get the following exception:  
`elasticsearch.exceptions.AuthorizationException: AuthorizationException(403, 'security_exception', 'action [indices:data/read/get] is unauthorized for user [elastic]')`

In the above case I actually authenticated using the 'elastic' superuser just to see if I was doing anything wrong. I can't seem to figure it out.

EDIT : While debugging further I figured it was the wildcard after the index name that caused this. You can't get a document by the id across a number of indices. The exception was misleading. When I ran the same query in the 'Dev Tools' section of Kibana, the error was a bit more accurate - as such.  
`{ "error" : { "root_cause" : [{ "type" : "security_exception", "reason" : "action [indices:data/read/get] is unauthorized for user [elastic]" } ], "type" : "security_exception", "reason" : "action [indices:data/read/get] is unauthorized for user [elastic]", "caused_by" : { "type" : "illegal_state_exception", "reason" : "There are no external requests known to support wildcards that don't support replacing their indices" } }, "status" : 403 } `

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 17, 2020, 11:14pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/2 "2020-08-17T23:14:26Z")

</div>

Welcome to our community! 😃

> [@apocalypse0](#):
>
> EDIT : While debugging further I figured it was the wildcard after the index name that caused this. You can't get a document by the id across a number of indices. The exception was misleading. When I ran the same query in the 'Dev Tools' section of Kibana, the error was a bit more accurate - as such.  
> `{ "error" : { "root_cause" : [{ "type" : "security_exception", "reason" : "action [indices:data/read/get] is unauthorized for user [elastic]" } ], "type" : "security_exception", "reason" : "action [indices:data/read/get] is unauthorized for user [elastic]", "caused_by" : { "type" : "illegal_state_exception", "reason" : "There are no external requests known to support wildcards that don't support replacing their indices" } }, "status" : 403 }`

I wanted to quote this one separately so that the topic can be marked as solved 🙂

---

<div class="post-metadata">

**Author:** ![apocalypse0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apocalypse0/32/45409_2.png) [@apocalypse0](https://discuss.elastic.co/u/apocalypse0)\
**Post date:** [August 18, 2020, 4:41am UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/3 "2020-08-18T04:41:23Z")

</div>

Thank you for the warm welcome.  
Sure - it's solved. Could the `error.root_cause.reason` perhaps be amended in a future release so as to give a more accurate description (as opposed to the authorization related issue)?

Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2020, 4:42am UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/4 "2020-08-18T04:42:09Z")

</div>

It'd be worth raising a feature request for that on GitHub.

---

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [August 24, 2020, 8:02pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/5 "2020-08-24T20:02:07Z")

</div>

Hi Warkolm,  
I am having the similar issue, but i couldn't find solution in this topic,. Can you please point me to the solution for "There are no external requests known to support wildcards that don't support replacing their indices" } }, "status" : 403 }?

Thanks,  
Sankeerth.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 24, 2020, 9:07pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/6 "2020-08-24T21:07:51Z")

</div>

Please start your own topic on this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2020, 9:07pm UTC](https://discuss.elastic.co/t/authorization-exception-for-superuser/245311/7 "2020-09-21T21:07:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
