# Elastic does not respond with many security index patterns

**URL:** <https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 16, 2020, 6:59pm UTC](https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376 "2020-01-16T18:59:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jpozorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpozorio/32/60974_2.png) [@jpozorio](https://discuss.elastic.co/u/jpozorio)\
**Post date:** [January 16, 2020, 6:59pm UTC](https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376/1 "2020-01-16T18:59:59Z")

</div>

Hi,

My custer has 770 index and when I try to open a Kibana dashboard with one user who can access more then 10 patterns (each pattern usually "point" to 9 index), the elasticsearch throws the below message.

I google a litte, but don't find anything about it.

> {"error":{"root\_cause":[{"type":"security\_exception","reason":"The set of permitted index patterns [_612199_,_396341_,_191200_,_396455_,_461388_,_65064_,_39813_,_40109_,_229972_,.k...] is too complex to evaluate"}],"type":"security\_exception","reason":"The set of permitted index patterns [_612199_,_396341_,_191200_,_396455_,_461388_,_65064_,_39813_,_40109_,_229972_,.k...] is too complex to evaluate","caused\_by":{"type":"too\_complex\_to\_determinize\_exception","reason":"Determinizing automaton with 93 states and 126 transitions would result in more than 100000 states."}},"status":500}

Thanks in advance

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [January 17, 2020, 6:06am UTC](https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376/2 "2020-01-17T06:06:44Z")

</div>

Hi Joao,

What version are you on ?

You can start by setting `xpack.security.automata.max_determinized_states` to something bigger than 100000 and see if that gets you a quick win for your issue. Don't set it _too_ high though as this does have an effect on memory consumption on your nodes.

The most important step is to go through your role definitions and try to optimize the indices name patterns that you are using. There is no generic guidance I could offer offhand without knowing what your role definitions look like but feel free to share some examples here so that we can make some suggestions. Alternatively, you can reach your support engineer and get some assistance from them too!

---

<div class="post-metadata">

**Author:** ![jpozorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpozorio/32/60974_2.png) [@jpozorio](https://discuss.elastic.co/u/jpozorio)\
**Post date:** [January 17, 2020, 2:41pm UTC](https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376/3 "2020-01-17T14:41:44Z")

</div>

Thanks for the quickly reply.

I update recently from 6.3.2 to 6.8.5, to use the security stack... So all of those security features are new for me.

I'll try to change this setting today e share the results.

I was thinking about to use a alias to group my index and use this alias in my patterns to reduce this hudge number of patterns.

I have one type for each entity in my domain and each tenant has your own list of index.  
I create one rule for each tenant and the pattern "point" to them.  
And my user could access a list of those tenants.

Let me give you a short example to clearly this confusion.

2 Entities in my domain:

> E1, E2

And I have 3 tenants

> T1, T2, T3

In elasticsearch I'll have 6 index

> T1\_E1, T1\_E2, T2\_E1, T2\_E2, T3\_E1, T3\_E2

I create one role for each tenant, each of them with a pattern matching tenants

> R1 -\> T1\*  
> R2 -\> T2\*  
> R3 -\> T3\*

For each user, I set a list of roles, based on what tenants he could access.

> U1 -\> R1  
> U2 -\> R1, R3  
> U3 -\> R1, R2, R3

Thanks again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2020, 2:41pm UTC](https://discuss.elastic.co/t/elastic-does-not-respond-with-many-security-index-patterns/215376/4 "2020-02-14T14:41:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
