# 'create' vs. 'create\_doc' privilege for beats\_system

**URL:** <https://discuss.elastic.co/t/create-vs-create-doc-privilege-for-beats-system/315752>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 4, 2022, 8:59am UTC](https://discuss.elastic.co/t/create-vs-create-doc-privilege-for-beats-system/315752 "2022-10-04T08:59:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![NominaSumpta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nominasumpta/32/52412_2.png) [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Post date:** [October 4, 2022, 8:59am UTC](https://discuss.elastic.co/t/create-vs-create-doc-privilege-for-beats-system/315752/1 "2022-10-04T08:59:45Z")

</div>

On my Elasticsearch 7.x cluster, the `beats_system` role has the index privileges `create_index` and `create`.

According to [Security privileges | Elasticsearch Guide [7.17] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/security-privileges.html), roles with the the index `create` privilege may:

> index documents, allowing overwriting any existing document, but not permitting updating one.

According to that same document, the index `create_doc` privilege does NOT allow for overwriting:

> Privilege to index new documents, without allowing overwriting or updating existing ones.

According to [Grant privileges and roles needed for monitoring | Filebeat Reference [7.17] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.17/privileges-to-publish-monitoring.html), a user-made role (as an alternative to using the built-in `beats_system` role) should have the index `create_index` and `create_doc` privileges.

Questions:

- Why does the built-in `beats_system` role have the index `create` privilege instead of the index `create_doc` privilege?
- How could I replace the index `create` privilege with the index `create_doc` privilege for the `beats_system` role? I am unable to update it because it's built in.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [October 6, 2022, 1:16am UTC](https://discuss.elastic.co/t/create-vs-create-doc-privilege-for-beats-system/315752/2 "2022-10-06T01:16:12Z")

</div>

> - Why does the built-in `beats_system` role have the index `create` privilege instead of the index `create_doc` privilege?

Because `beats_system` came before we had the `create_doc`. Because of backward compatibility, it is not simpel to change it to use `create_doc` afterwards.

> - How could I replace the index `create` privilege with the index `create_doc` privilege for the `beats_system` role? I am unable to update it because it's built in.

You cannot. You'll want to create and use your own role.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2022, 1:16am UTC](https://discuss.elastic.co/t/create-vs-create-doc-privilege-for-beats-system/315752/3 "2022-11-03T01:16:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
