# Error after OS upgrade

**URL:** <https://discuss.elastic.co/t/error-after-os-upgrade/286966>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 18, 2021, 9:05am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966 "2021-10-18T09:05:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zincometal](https://avatars.discourse-cdn.com/v4/letter/z/b5ac83/32.png) [@Zincometal](https://discuss.elastic.co/u/Zincometal)\
**Post date:** [October 18, 2021, 9:05am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/1 "2021-10-18T09:05:54Z")

</div>

Hello all,  
I'm a newbie to ELK and after many search I've not found a solution.  
After an OS upgrade Devuan 3 =\> Devuan 4 my filebeat doesn't work.  
The error in /var/log/filebeat.log is this:

`Preformatted text`2021-10-18T10:00:03.386+0200 ERROR [publisher\_pipeline\_output] pipeline/output.go:154 Failed to connect to backoff(elasticsearch([http://192.168.2.252:9200](http://192.168.2.252:9200))): Connection marked as failed because the onConnect callback failed: failed to create alias: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/aliases] is unauthorized for user [filebeat\_writer] with roles [filebeat\_writer], this action is granted by the index privileges [manage,all]"}],"type":"security\_exception","reason":"action [indices:admin/aliases] is unauthorized for user [filebeat\_writer] with roles [filebeat\_writer], this action is granted by the index privileges [manage,all]"},"status":403}: 403 Forbidden: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/aliases] is unauthorized for user [filebeat\_writer] with roles [filebeat\_writer], this action is granted by the index privileges [manage,all]"}],"type":"security\_exception","reason":"action [indices:admin/aliases] is unauthorized for user [filebeat\_writer] with roles [filebeat\_writer], this action is granted by the index privileges [manage,all]"},"status":403}`

In devuan 3 it works properly  
I have created a role filebeat\_writer with cluster privileges

`monitor  
read\_ilm  
cluster:admin/ingest/pipeline/get  
cluster:admin/ingest/pipeline/put  
cluster:admin/ilm/put

indices filebeat-\*

privileges  
create\_doc  
view\_index\_metadata  
create index`

after I have created a user filebeat\_writer  
roles  
filebeat\_writer

my /etc/filebeat/filebeat.yml say:

`filebeat.inputs:

- type: log

- type: filestream

filebeat.config.modules:

path: ${path.config}/modules.d/\*.yml

reload.enabled: false

setup.template.settings:  
index.number\_of\_shards: 1

```
setup.kibana:
 host: "192.168.2.252:5601"
 output.elasticsearch:

```

# Array of hosts to connect to.

```
hosts: ["192.168.2.252:9200"]
username: "filebeat_writer"
password: "mypass"

processors:

```

- add\_host\_metadata:  
when.not.contains.tags: forwarded
- add\_cloud\_metadata: ~
- add\_docker\_metadata: ~
- add\_kubernetes\_metadata: ~`

Version of filebeat is everywhere 7.15.1.  
kernel version on Devuan 3 is 5.10.0-0.bpo.8-amd64 #1 SMP Debian 5.10.46-4~bpo10+1  
kernel version on Devuan 4 is 5.10.0-9-amd64 #1 SMP Debian 5.10.70-1

Can someone please give me an idea of how to fix this malfunction?  
Thank you in advance

---

<div class="post-metadata">

**Author:** ![Zincometal](https://avatars.discourse-cdn.com/v4/letter/z/b5ac83/32.png) [@Zincometal](https://discuss.elastic.co/u/Zincometal)\
**Post date:** [October 18, 2021, 2:53pm UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/2 "2021-10-18T14:53:52Z")

</div>

I answer myself  
adding manage, all to the role of filebeat in the index privileges section works  
thanks anyway

---

<div class="post-metadata">

**Author:** ![joao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joao/32/83447_2.png) [@joao](https://discuss.elastic.co/u/joao)\
**Post date:** [October 18, 2021, 8:10pm UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/3 "2021-10-18T20:10:12Z")

</div>

Hi,

You need to review the roles of the user "filebeat\_writer".

**Log info**

**Error:** Connect callback failed: failed to create alias: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/aliases] **is unauthorized for user [filebeat\_writer] with roles [filebeat\_writer]**

**Suggestion:** this action is granted by the index privileges [manage,all]

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 18, 2021, 10:26pm UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/4 "2021-10-18T22:26:52Z")

</div>

Welcome to our community! 😃

In future it's super helpful if you format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![Zincometal](https://avatars.discourse-cdn.com/v4/letter/z/b5ac83/32.png) [@Zincometal](https://discuss.elastic.co/u/Zincometal)\
**Post date:** [October 19, 2021, 8:03am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/5 "2021-10-19T08:03:52Z")

</div>

@joao  
Thanks, I got there with difficulty yesterday afternoon 🙂

---

<div class="post-metadata">

**Author:** ![Zincometal](https://avatars.discourse-cdn.com/v4/letter/z/b5ac83/32.png) [@Zincometal](https://discuss.elastic.co/u/Zincometal)\
**Post date:** [October 19, 2021, 8:05am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/6 "2021-10-19T08:05:22Z")

</div>

@warkolm  
Thanks I'll try to figure out how to do it, unfortunately I'm a command line man, and if I don't use vim I'm lost 😃

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 19, 2021, 9:04am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/7 "2021-10-19T09:04:23Z")

</div>

Yep I understand that!  
If your `filebeat.yml` was code formatted though, we could more easily read it and pick out indentation issues. That's more what I was getting at.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2021, 11:04am UTC](https://discuss.elastic.co/t/error-after-os-upgrade/286966/8 "2021-11-16T11:04:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
