# Elastic/fleet-server cannot create/write to index - insufficient permissions

**URL:** <https://discuss.elastic.co/t/elastic-fleet-server-cannot-create-write-to-index-insufficient-permissions/294181>\
**Category:** Elasticsearch\
**Created:** [January 12, 2022, 3:31pm UTC](https://discuss.elastic.co/t/elastic-fleet-server-cannot-create-write-to-index-insufficient-permissions/294181 "2022-01-12T15:31:28Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 13, 2022, 2:50am UTC](https://discuss.elastic.co/t/elastic-fleet-server-cannot-create-write-to-index-insufficient-permissions/294181/2 "2022-01-13T02:50:01Z")

</div>

> [@mark8](#):
>
> Is there a way to allow that user to create/write to these indices?

No, it is not possible. The fleet-server service account is only able to write to indices that are managed by fleet, and there is no way to change that.

> [@mark8](#):
>
> Am I going about this correctly? Is there a more straighforward way to achieve my goal?

You're definitely fighting against what Fleet/Agent tries to do.  
It is designed to ingest into curated index names, and not be a universal data router in the way that Logstash is often used.  
I don't understand _why_ you want to have your logs routed like that, but it's not really a scenario fleet & agent are designed for.

The best suggestion I can make is to change your pipeline to something like:

```auto
    "set": {
      "field": "_index",
      "value": "logs-{{{name}}}",
      "media_type": "text/plain"
    }

```

It's still likely to violate some of the assumptions fleet makes, but it's going to get you closer.

---

_[View the full topic](https://discuss.elastic.co/t/elastic-fleet-server-cannot-create-write-to-index-insufficient-permissions/294181)._
