# Curator delete indices shield permissions

**URL:** <https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 16, 2015, 1:31am UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354 "2015-09-16T01:31:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Doug\_Nelson](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@Doug\_Nelson](https://discuss.elastic.co/u/Doug_Nelson)\
**Post date:** [September 16, 2015, 1:31am UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/1 "2015-09-16T01:31:23Z")

</div>

I have a working curator delete script that works when I run it from my very privileged admin account. I am trying to get it to work with a curator role and I want to limit the actions to exactly what is required.

this is how the role is defined  
curator:  
cluster: montior  
indices:  
'.-shield\_audit\_log-\*':  
-indices:admin/delete, indices:admin/exists, indices:admin/get

When I run the curator script as the curator account I get a message saying no indices found. I am looking to remove indices that are more than 7 days old. Again when I run the curator account in my full admin role, it does find and remove the indices.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 16, 2015, 11:40am UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/2 "2015-09-16T11:40:00Z")

</div>

Hi Doug,

If this role is for the Shield Index Audit output, I believe that you have an extra `-` in the index name:

`'.-shield_audit_log-*'` should be `'.shield_audit_log-*'`

Jay

---

<div class="post-metadata">

**Author:** ![Doug\_Nelson](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@Doug\_Nelson](https://discuss.elastic.co/u/Doug_Nelson)\
**Post date:** [September 16, 2015, 12:58pm UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/3 "2015-09-16T12:58:32Z")

</div>

Sorry, that was a typo when I was entering the post. I do not have the  
.-shield but rather .shield. Like I said, when I use my credentials it  
works, but not with the credentials I have set up for the curator roles.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 16, 2015, 2:05pm UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/4 "2015-09-16T14:05:14Z")

</div>

Can you try updating the role to:

```auto
curator:
  cluster: monitor
  indices:
    '.shield_audit_log-*':
      - indices:monitor/settings/get
      - indices:admin/delete
      - indices:admin/exists
      - indices:admin/get 

```

I believe curator gets the list of indices through the get settings API.

A side note, one way to determine the necessary privileges would be to look at the `access_granted` entries in the audit log from your administrative user when curator is interacting with Shield.

---

<div class="post-metadata">

**Author:** ![Doug\_Nelson](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@Doug\_Nelson](https://discuss.elastic.co/u/Doug_Nelson)\
**Post date:** [September 17, 2015, 2:54am UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/5 "2015-09-17T02:54:51Z")

</div>

Figured out the issue. I needed to put the indices on the single line with log name

'.shield\_audit\_log-\*' : indices:admin/get, indices:admin/delete

These are the methods that are called. I don't really understand why the list option did not work. Also, when using the list format,. I did not get entries in the security log, once I switched to the single line option as shown above I could see the entries in the log.

Thanks for the help, really appresciated

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/curator-delete-indices-shield-permissions/29354/6 "2017-07-06T13:48:23Z")

</div>


