# Elasticsearch permissions required by Filebeat

**URL:** <https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 2, 2018, 2:42pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185 "2018-11-02T14:42:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [November 2, 2018, 2:42pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/1 "2018-11-02T14:42:57Z")

</div>

I'm looking to secure my Elastic Cloud deployment by creating additional users (and roles where necessary) on the system. I'm not comfortable using the root `elastic` username and password for writing logs from Filebeat, and so I'd like to create a new user specifically for Filebeat ingestion. What permissions does Filebeat need in Elasticsearch to function correctly? I haven't been able to find this information via Google or in the Filebeat docs.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [November 2, 2018, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/2 "2018-11-02T15:47:24Z")

</div>

Hi,

Have a look at [Securing Filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/securing-beats.html) section of the docs.

---

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [November 2, 2018, 5:04pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/3 "2018-11-02T17:04:56Z")

</div>

Thanks @adrisr. Please can you confirm whether this works with Cloud authentication (in conjunction with the cloud ID) also? It seems as though it should, but I'm seeing authentication failures as a result of changing this.

Additionally, from [step 4](https://www.elastic.co/guide/en/beats/filebeat/current/beats-system-user.html) of that page of the documentation, I don't see a `beats_system` user in my deployment, so I guess there's nothing to do there. Perhaps the docs need updating for Elastic Cloud?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [November 2, 2018, 5:27pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/4 "2018-11-02T17:27:21Z")

</div>

It worked for me, leaving `cloud.id` as is, and changing `cloud.auth` to the new user:

```auto
cloud.auth: filebeat_internal:YOUR_PASSWORD

```

About step 4 you are right, I don't see any `beats_system` user either, I will raise the issue

---

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [November 2, 2018, 6:14pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/5 "2018-11-02T18:14:19Z")

</div>

Great, thanks. I tried with a different password (no symbols) and it worked fine. Not sure which symbol caused the problem there, but I assume there are some forbidden ones of which I fell foul.

I'm seeing a lot of these messages in my filebeat logs now:

```auto
2018-11-02T18:03:21.874Z ERROR pipeline/output.go:121 Failed to publish 
events: 403 Forbidden: {"error":{"root_cause":[{"type":"security_exception",
"reason":"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user
 [filebeat]"}],"type":"security_exception","reason":"action 
[cluster:admin/xpack/monitoring/bulk] is unauthorized for user [filebeat]"},
"status":403}

```

I can't see to which permission this action maps; any ideas which I've missed, or indeed what's causing it? I'm using Kubernetes autodiscover, and these are the modules I have enabled:

```auto
Enabled modules/filesets: apache2 (access), traefik (access), redis (log, slowlog), (), system (auth, syslog)

```

Not sure where that blank one has come from 🤔

---

<div class="post-metadata">

**Author:** ![alastairs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alastairs/32/38136_2.png) [@alastairs](https://discuss.elastic.co/u/alastairs)\
**Post date:** [November 2, 2018, 6:55pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/6 "2018-11-02T18:55:24Z")

</div>

Aha, it's the `beats_system` role it needs. Found that in the [Monitoring Filebeat](https://www.elastic.co/guide/en/beats/filebeat/6.4/monitoring.html) docs 👍

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [November 2, 2018, 8:08pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/7 "2018-11-02T20:08:42Z")

</div>

Thanks for your feedback! I'm glad you sorted it out.

I've created [an issue](https://github.com/elastic/beats/issues/8913) to improve the documentation on this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 8:08pm UTC](https://discuss.elastic.co/t/elasticsearch-permissions-required-by-filebeat/155185/8 "2018-11-30T20:08:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
