# Can not open Stack monitoring

**URL:** https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772
**Category:** Elasticsearch
**Tags:** elastic-stack-monitoring, elastic-stack-security
**Created:** [June 19, 2020, 9:21am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772 "2020-06-19T09:21:52Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [June 19, 2020, 9:21am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/1 "2020-06-19T09:21:53Z")

</div>

Hi,  
Recently I couldn't open Stack Monitoring. Then I decided to upgrade to new version 7.8.0. But after upgrading my problem still exists.  
My user has role superuser so I don't understand why I cannot have access to monitoring indices.

 ![Photo](https://us1.discourse-cdn.com/elastic/original/3X/c/e/cee90b435787f49ab159adcc8e27eac469f14432.jpeg)

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [June 23, 2020, 1:54pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/2 "2020-06-23T13:54:50Z")

</div>

Can you share the roles your user has?

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [June 23, 2020, 3:13pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/3 "2020-06-23T15:13:45Z")

</div>

The only one role superuser.

Chris Roberson via Discuss the Elastic Stack [elastic@discoursemail.com](mailto:elastic@discoursemail.com) 23 июня 2020 г. 17:05:04 написал:

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [June 29, 2020, 1:19pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/4 "2020-06-29T13:19:19Z")

</div>

That's strange. If you are using the `elastic` superuser account, there should never be permission issues.

Are you using a dedicated, separate monitoring cluster? Can you share your `kibana.yml`?

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [June 29, 2020, 5:42pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/5 "2020-06-29T17:42:07Z")

</div>

We use one cluster with all data and monitoring indices placed together.  
My kibana.yml

> server.host: "0.0.0.0"
> 
> elasticsearch.hosts:
> 
> - [http://hostname.domain.local:9200](http://hostname.domain.local:9200)
> 
> kibana.index: ".kibana"
> 
> elasticsearch.username: "kibana\_user"  
> elasticsearch.password: "\*\*\*\*\*\*\*\*\*\*\*\*\*\*"
> 
> logging.dest: /var/log/kibana/kibana.log
> 
> xpack.monitoring.enabled: true  
> xpack.monitoring.ui.enabled: true

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [June 29, 2020, 5:58pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/6 "2020-06-29T17:58:58Z")

</div>

Try creating a user with the roles defined in the error message (`kibana_admin` and `monitoring_user`) then logging in as that user. Does that fix it?

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [July 15, 2020, 12:49pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/7 "2020-07-15T12:49:17Z")

</div>

I created a new user and added 2 roles, but have the same error.

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [July 15, 2020, 2:35pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/8 "2020-07-15T14:35:06Z")

</div>

Hmm. Can you double check there aren't any errors in either the Kibana or Elasticsearch server log that might help explain this?

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [July 15, 2020, 4:52pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/9 "2020-07-15T16:52:22Z")

</div>

Well, elastic logs are clear but while I try to open stack monitoring in kibana I see many errors in kibana log

> {"type":"log","@timestamp":"2020-07-15T16:43:32Z","tags":["error","plugins","monitoring","monitoring"],"pid":9192,"message":"{ Error: [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user]\n at respond (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:349:15)\n at checkRespForFailure (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:306:7)\n at HttpConnector. (/usr/share/kibana/node\_modules/elasticsearch/src/lib/connectors/http.js:173:7)\n at IncomingMessage.wrapper (/usr/share/kibana/node\_modules/elasticsearch/node\_modules/lodash/lodash.js:4929:19)\n at IncomingMessage.emit (events.js:203:15)\n at endReadableNT (\_stream\_readable.js:1145:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19)\n status: 403,\n displayName: 'AuthorizationException',\n message:\n '[security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user] (and) [security\_exception] action [indices:data/read/search[can\_match]] is unauthorized for user [user]',\n path:\n '/_%3A.monitoring-es-6-_%2C\*%3A.monitoring-es-7-_%2C.monitoring-es-6-_%2C.monitoring-es-7-\*/\_search',\n query:\n { size: 10000,\n ignore\_unavailable: true,\n filter\_path:\n 'hits.hits.\_index,hits.hits.\_source.cluster\_uuid,hits.hits.\_source.cluster\_name,hits.hits.\_source.version,hits.hits.\_source.license.status,hits.hits.\_source.license.type,hits.hits.\_source.license.issue\_date,hits.hits.\_source.license.expiry\_date,hits.hits.\_source.license.expiry\_date\_in\_millis,hits.hits.\_source.cluster\_stats,hits.hits.\_source.cluster\_state,hits.hits.\_source.cluster\_settings.cluster.metadata.display\_name' },\n body:\n { error:\n { root\_cause: [Array],\n type: 'search\_phase\_execution\_exception',\n reason: 'all shards failed',\n phase: 'can\_match',\n grouped: true,\n failed\_shards: [Array] },\n status: 403 },\n statusCode: 403,\n response:\n '{"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"},{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]"}],"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"can\_match","grouped":true,"failed\_shards":[{"shard":0,"index":".monitoring-es-7-2020.07.09","node":"Zy4jPFsyR\_S6mvlUQJOxDg","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.10","node":"0HC5iE8ITcqRY7kFPem6rQ","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.11","node":"0HC5iE8ITcqRY7kFPem6rQ","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.12","node":"9FcVASLhQaecOi41I6Nu0g","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.13","node":"Zy4jPFsyR\_S6mvlUQJOxDg","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.14","node":"0HC5iE8ITcqRY7kFPem6rQ","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}},{"shard":0,"index":".monitoring-es-7-2020.07.15","node":"0HC5iE8ITcqRY7kFPem6rQ","reason":{"type":"security\_exception","reason":"action [indices:data/read/search[can\_match]] is unauthorized for user [user]","caused\_by":{"type":"illegal\_state\_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}}]},"status":403}',\n toString: [Function],\n toJSON: [Function] }"}  
> {"type":"response","@timestamp":"2020-07-15T16:43:32Z","tags":,"pid":9192,"method":"post","statusCode":403,"req":{"url":"/api/monitoring/v1/clusters","method":"post","headers":{"connection":"upgrade","host":"kibana.domain.local","content-length":"101","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0","accept":"application/json, text/plain, _/_","accept-language":"ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3","accept-encoding":"gzip, deflate, br","content-type":"application/json;charset=utf-8","kbn-version":"7.8.0","origin":"[https://kibana.domain.local](https://kibana.domain.local)","referer":"[https://kibana.domain.local/app/monitoring"},"remoteAddress":"127.0.0.1","userAgent":"127.0.0.1","referer":"https://kibana.domain.local/app/monitoring"},"res":{"statusCode":403,"responseTime":76,"contentLength":9},"message":"POST](https://kibana.domain.local/app/monitoring%22%7D,%22remoteAddress%22:%22127.0.0.1%22,%22userAgent%22:%22127.0.0.1%22,%22referer%22:%22https://kibana.domain.local/app/monitoring%22%7D,%22res%22:%7B%22statusCode%22:403,%22responseTime%22:76,%22contentLength%22:9%7D,%22message%22:%22POST) /api/monitoring/v1/clusters 403 76ms - 9.0B"}  
> {"type":"response","@timestamp":"2020-07-15T16:43:32Z","tags":,"pid":9192,"method":"get","statusCode":200,"req":{"url":"/api/monitoring/v1/check\_access","method":"get","headers":{"connection":"upgrade","host":"kibana.domain.local","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:78.0) Gecko/20100101 Firefox/78.0","accept":"application/json, text/plain, _/_","accept-language":"ru-RU,ru;q=0.8,en-US;q=0.5,en;q=0.3","accept-encoding":"gzip, deflate, br","kbn-version":"7.8.0","referer":"[https://kibana.domain.local/app/monitoring"},"remoteAddress":"127.0.0.1","userAgent":"127.0.0.1","referer":"https://kibana.domain.local/app/monitoring"},"res":{"statusCode":200,"responseTime":59,"contentLength":9},"message":"GET](https://kibana.domain.local/app/monitoring%22%7D,%22remoteAddress%22:%22127.0.0.1%22,%22userAgent%22:%22127.0.0.1%22,%22referer%22:%22https://kibana.domain.local/app/monitoring%22%7D,%22res%22:%7B%22statusCode%22:200,%22responseTime%22:59,%22contentLength%22:9%7D,%22message%22:%22GET) /api/monitoring/v1/check\_access 200 59ms - 9.0B"}

I replaced real host name and user login.

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [July 15, 2020, 5:21pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/10 "2020-07-15T17:21:52Z")

</div>

Hmm okay. So for the user you created, can you please run these commands and return all the results?

`GET _security/user/{THE_USER_YOU_CREATED}`

Use the `roles` list from the above response to run the next command:

`GET _security/role/{THE_ROLE_FROM_ABOVE_AS_COMMA_SEPARATED_LIST}`

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [July 15, 2020, 5:31pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/11 "2020-07-15T17:31:47Z")

</div>

Maybe my problem is wider.  
I tried to open monitoring many times and opened. I see

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4aa5c5241da5aaf019113da59414a45666c6c388.png)

What concerns your question:  
{  
"user" : {  
"username" : "user",  
"roles" : [  
"superuser",  
"wazuh\_admin"  
],  
"full\_name" : "User",  
"email" : "",  
"metadata" : { },  
"enabled" : true  
}  
}

```
{
  "superuser" : {
    "cluster" : [
      "all"
    ],
    "indices" : [
      {
        "names" : [
          "*"
        ],
        "privileges" : [
          "all"
        ],
        "allow_restricted_indices" : true
      }
    ],
    "applications" : [
      {
        "application" : "*",
        "privileges" : [
          "*"
        ],
        "resources" : [
          "*"
        ]
      }
    ],
    "run_as" : [
      "*"
    ],
    "metadata" : {
      "_reserved" : true
    },
    "transient_metadata" : { }
  }
}

{
  "wazuh_admin" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "wazuh-*"
        ],
        "privileges" : [
          "all"
        ],
        "field_security" : {
          "grant" : [
            "*"
          ],
          "except" : []
        },
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}
```

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [July 16, 2020, 11:15am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/12 "2020-07-16T11:15:59Z")

</div>

Maybe this info helps  
`"action [indices:data/read/search[can_match]] is unauthorized for user [user]"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"can_match","grouped":true,"failed_shards":[{"shard":0,"index":".monitoring-es-7-2020.07.09","node":"0HC5iE8ITcqRY7kFPem6rQ","reason":{"type":"security_exception","reason":"action [indices:data/read/search[can_match]] is unauthorized for user [user]","caused_by":{"type":"illegal_state_exception","reason":"There are no external requests known to support wildcards that don\'t support replacing their indices"}}}`  
All monitoring indices are accessible

 ![изображение](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb40736426b9dc6b732216669a707aca811c7984.png)

---

<div class="post-metadata">

### Author: ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)
#### Post date: [July 20, 2020, 2:53pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/13 "2020-07-20T14:53:12Z")

</div>

I honestly don't know.

Can you try recreating your environment to see if the error still happens? I'm going to tag the Elasticsearch team on this as well as they might be able to help more.

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [July 21, 2020, 7:23am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/14 "2020-07-21T07:23:54Z")

</div>

It's a cluster from 6 servers so it's not simple to recreate it.  
I have another one standalone server with Elasticsearch stack the same version and this error is not reproduced there.

---

<div class="post-metadata">

### Author: ![Sebastian\_Treu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_treu/32/27013_2.png) [@Sebastian\_Treu](https://discuss.elastic.co/u/Sebastian_Treu)
#### Post date: [August 11, 2020, 11:41pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/15 "2020-08-11T23:41:38Z")

</div>

I'm having exactly the same issue. For what I've been able understand, the problem is not the user role or permission but instead the error in the search API request:

For instance, this API request method from the log:

`/%3A.monitoring-es-6-%2C*%3A.monitoring-es-7-%2C.monitoring-es-6-%2C.monitoring-es-7-*/_search`

is the problematic request. I crafted multiple requests based on the one above to find out where the problem is by removing part of it. Basically, the request above is doing a multiple index search be separating index patterns with `,` (`%2C`) and `:` (`%3A`)

In my particular case, this is the path:

`/*%3A.monitoring-es-6-*%2C*%3A.monitoring-es-7-*%2C.monitoring-es-6-*%2C.monitoring-es-7-*/_search`

removing url encoded string:

`/*:.monitoring-es-6-*,*:.monitoring-es-7-*,.monitoring-es-6-*,.monitoring-es-7-*/_search`

> **Resulting in an error**
>
> ```auto
> {
> "error" : {
> "root_cause" : [
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> },
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> },
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> },
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> },
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> },
> {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]"
> }
> ],
> "type" : "search_phase_execution_exception",
> "reason" : "all shards failed",
> "phase" : "query",
> "grouped" : true,
> "failed_shards" : [
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.06",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> },
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.07",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> },
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.08",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> },
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.09",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> },
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.10",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> },
> {
> "shard" : 0,
> "index" : ".monitoring-es-7-2020.08.11",
> "reason" : {
> "type" : "security_exception",
> "reason" : "action [indices:data/read/search[phase/query]] is unauthorized for user [elastic]",
> "caused_by" : {
> "type" : "illegal_state_exception",
> "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
> }
> }
> }
> ]
> },
> "status" : 403
> }
> 
> ```

If I manually remove `:` from the path request and try that again in dev tools it works:

```auto
POST /*.monitoring-es-6-*,.monitoring-es-7-*,.monitoring-es-6-*,.monitoring-es-7-*/_search

```

Anyways, that's the cause of the error but I'm not sure why it's happening, where is `*:` being appended and if it's a correct path syntax or not.

`POST /*:/_search` doesn't looks OK to me, but I honestly don't know.

@chrisronline Any clues?

---

<div class="post-metadata">

### Author: ![Sebastian\_Treu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_treu/32/27013_2.png) [@Sebastian\_Treu](https://discuss.elastic.co/u/Sebastian_Treu)
#### Post date: [August 12, 2020, 12:02am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/16 "2020-08-12T00:02:07Z")

</div>

Further debugging:

Looks that:

```auto
POST /*:.monitoring*

```

works OK, but this fails:

```auto
POST /*:.monitoring-es-7-*,.monitoring-es-7-*/_search

```

And both individually works ok:

```auto
POST /*:.monitoring-es-7-*/_search
POST /.monitoring-es-7-*/_search

```

I'm really puzzled about this.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [August 12, 2020, 1:07am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/17 "2020-08-12T01:07:07Z")

</div>

> [@v.n](#):
>
> here are no external requests known to support wildcards that don't support replacing their indices"

If you are seeing this message, then it's definitely a bug.

Are you able to [capture a HAR](https://gist.github.com/legrego/7154b71096a09876423e2bd61d6a3e0f) from your browser when this error occurs?

If it has sensitive information in it (it probably will), then you can send it to me via a private message.  
Or, if you are a paid customer you can open a ticket on our [support portal](https://support.elastic.co/) and provide the details there.

---

<div class="post-metadata">

### Author: ![Sebastian\_Treu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sebastian_treu/32/27013_2.png) [@Sebastian\_Treu](https://discuss.elastic.co/u/Sebastian_Treu)
#### Post date: [August 12, 2020, 2:28am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/18 "2020-08-12T02:28:13Z")

</div>

hi @TimV

just to clarify, is this request valid?

```auto
POST /*:.monitoring-es-7-*,.monitoring-es-7-*/_search

```

Because that looks like the request is being made by kibana.

If you split that request in two, i.e.:

```auto
POST /*:.monitoring-es-7-*/_search
POST /.monitoring-es-7-*/_search

```

it looks fine.

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [August 12, 2020, 8:36am UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/19 "2020-08-12T08:36:07Z")

</div>

I sent you a private message with link to HAR.

---

<div class="post-metadata">

### Author: ![v.n](https://avatars.discourse-cdn.com/v4/letter/v/5daacb/32.png) [@v.n](https://discuss.elastic.co/u/v.n)
#### Post date: [August 31, 2020, 2:16pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772/20 "2020-08-31T14:16:40Z")

</div>

Hi!  
Any news on this issue?

[Next page](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772.md?page=2)
