# Failed to Import Metricbeat Dashboards

**URL:** <https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 4, 2019, 5:09am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896 "2019-01-04T05:09:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SSIDDIQUI](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@SSIDDIQUI](https://discuss.elastic.co/u/SSIDDIQUI)\
**Post date:** [January 4, 2019, 5:09am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/1 "2019-01-04T05:09:14Z")

</div>

Hi All,

I'm new to ELK and was not involved with the installation of ELK. The delete\_indices.yml script ended up deleting the main .kibana index file which wiped out the dashboards. Once I gave the server a reboot some of it finally appeared back but now I'm missing majority of the Metricbeat Dashboards and Visualizations especially the Host Overview.

I have tried to import the sample dashboards via .\metricbeat.exe setup --dashboards but the following error occurs below.

E:\beats\metricbeat-6.3.1-windows-x86\_64\>.\metricbeat.exe setup --dashboards  
Loading dashboards (Kibana must be running and reachable)  
Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kib  
ana: Error importing directory E:\beats\metricbeat-6.3.1-windows-x86\_64\kibana:  
Failed to import index-pattern: Failed to load directory E:\beats\metricbeat-6.3  
.1-windows-x86\_64\kibana/6/index-pattern:  
error loading E:\beats\metricbeat-6.3.1-windows-x86\_64\kibana\6\index-pattern  
metricbeat.json: no permissions for [indices:data/write/index, indices:data/writ  
e/bulk[s]] and User [name=logstash, roles=[logstash], requestedTenant=null]. Res  
ponse: {"objects":[{"id":"metricbeat-\*","type":"index-pattern","error":{"message  
":"no permissions for [indices:data/write/index, indices:data/write/bulk[s]] and  
User [name=logstash, roles=[logstash], requestedTenant=null]"}}]}

In the Elastic Search logs I'm also seeing in case this is related.

[2019-01-04T16:04:20,709][INFO][c.f.s.c.PrivilegesEvaluator] No cluster-level perm match for User [name=kibanaro, roles=[kibanauser, readall], requestedTenant=null] Resolved [aliases=, indices=, allIndices=, types=[_], isAll()=false, isEmpty()=false] [Action [indices:admin/template/get]] [RolesChecked [sg\_own\_index, sg\_kibana\_user, sg\_readall]]  
[2019-01-04T16:04:20,709][INFO][c.f.s.c.PrivilegesEvaluator] No permissions for [indices:admin/template/get]  
[2019-01-04T16:04:20,724][INFO][c.f.s.c.PrivilegesEvaluator] No index-level perm match for User [name=kibanaro, roles=[kibanauser, readall], requestedTenant=null] Resolved [aliases=[_], indices=[_], allIndices=[_], types=[_], isAll()=true, isEmpty()=false] [Action [indices:admin/mappings/get]] [RolesChecked [sg\_own\_index, sg\_kibana\_user, sg\_readall]]  
[2019-01-04T16:04:20,724][INFO][c.f.s.c.PrivilegesEvaluator] No permissions for [indices:admin/mappings/get]  
[2019-01-04T16:04:20,740][INFO][c.f.s.c.PrivilegesEvaluator] No index-level perm match for User [name=kibanaro, roles=[kibanauser, readall], requestedTenant=null] Resolved [aliases=[_], indices=[_], allIndices=[_], types=, isAll()=true, isEmpty()=false] [Action [indices:admin/get]] [RolesChecked [sg\_own\_index, sg\_kibana\_user, sg\_readall]]  
[2019-01-04T16:04:20,740][INFO][c.f.s.c.PrivilegesEvaluator] No permissions for [indices:admin/get]

Thank you all for your help! This has been driving me nuts for the past few weeks!

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [January 4, 2019, 6:33pm UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/2 "2019-01-04T18:33:45Z")

</div>

Hello @SSIDDIQUI, did you by any chance run the setup dashboard command in PowerShell as admin?

---

<div class="post-metadata">

**Author:** ![SSIDDIQUI](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@SSIDDIQUI](https://discuss.elastic.co/u/SSIDDIQUI)\
**Post date:** [January 14, 2019, 10:55pm UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/3 "2019-01-14T22:55:33Z")

</div>

> [@SSIDDIQUI](#):
>
> .\metricbeat.exe setup --dashboards

Hi,

Apologies for the late response. Yes i did try running in CMD and Powershell with Admin privileges its the same error as below.

E:\beats\metricbeat-6.3.1-windows-x86\_64\>.\metricbeat.exe setup --dashboards  
Loading dashboards (Kibana must be running and reachable)  
Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kib  
ana: Error importing directory E:\beats\metricbeat-6.3.1-windows-x86\_64\kibana:  
Failed to import index-pattern: Failed to load directory E:\beats\metricbeat-6.3  
.1-windows-x86\_64\kibana/6/index-pattern:  
error loading E:\beats\metricbeat-6.3.1-windows-x86\_64\kibana\6\index-pattern  
metricbeat.json: no permissions for [indices:data/write/index, indices:data/writ  
e/bulk[s]] and User [name=logstash, roles=[logstash], requestedTenant=null]. Res  
ponse: {"objects":[{"id":"metricbeat-\*","type":"index-pattern","error":{"message  
":"no permissions for [indices:data/write/index, indices:data/write/bulk[s]] and  
User [name=logstash, roles=[logstash], requestedTenant=null]"}}]}

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 16, 2019, 10:26am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/4 "2019-01-16T10:26:34Z")

</div>

This looks like a permission error. I assume you have x-pack security enabled?

Interestingly in the error it shows the user logstash with the role logstash which I assume does not have permissions to load the dashobards.

---

<div class="post-metadata">

**Author:** ![SSIDDIQUI](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@SSIDDIQUI](https://discuss.elastic.co/u/SSIDDIQUI)\
**Post date:** [January 17, 2019, 1:31am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/5 "2019-01-17T01:31:04Z")

</div>

Hi Ruffin,

From checking the elasticsearch.yml file it seems to be disabled.

# SearchGuard Security Area

xpack.security.enabled: false  
searchguard.ssl.transport.pemcert\_filepath: esnode.pem  
searchguard.ssl.transport.pemkey\_filepath: esnode-key.pem  
searchguard.ssl.transport.pemtrustedcas\_filepath: root-ca.pem  
searchguard.ssl.transport.enforce\_hostname\_verification: false  
searchguard.ssl.http.enabled: true  
searchguard.ssl.http.pemcert\_filepath: esnode.pem  
searchguard.ssl.http.pemkey\_filepath: esnode-key.pem  
searchguard.ssl.http.pemtrustedcas\_filepath: root-ca.pem  
searchguard.allow\_unsafe\_democertificates: true  
searchguard.allow\_default\_init\_sgindex: true  
searchguard.authcz.admin\_dn:

- CN=kirk,OU=client,O=client,L=test,C=de

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 18, 2019, 12:13pm UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/6 "2019-01-18T12:13:16Z")

</div>

You are running search guard? I assume this is causing it. You need to adjust the permissions.

---

<div class="post-metadata">

**Author:** ![SSIDDIQUI](https://avatars.discourse-cdn.com/v4/letter/s/2bfe46/32.png) [@SSIDDIQUI](https://discuss.elastic.co/u/SSIDDIQUI)\
**Post date:** [January 22, 2019, 4:17am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/7 "2019-01-22T04:17:23Z")

</div>

Thanks. I'll have a look at the sg\_roles and sg\_config.yml files and see what is missing.

sg\_logstash is mapped to user logstash

What permissions would i need to give in this sg\_roles.yml file for these dashboards to install using user logstash?

# For logstash and beats

sg\_logstash:  
cluster:  
- CLUSTER\_MONITOR  
- CLUSTER\_COMPOSITE\_OPS  
- indices:admin/template/get  
- indices:admin/template/put  
indices:  
'logstash-_':  
'_':  
- CRUD  
- CREATE\_INDEX  
- indices:data/write/index  
- indices:data/write/bulk[s]]  
- indices:data/write/bulk

```
'*beat*':
  '*':
    - CRUD
    - CREATE_INDEX
    - indices:data/write/index
    - indices:data/write/bulk[s]]
    - indices:data/write/bulk
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2019, 4:17am UTC](https://discuss.elastic.co/t/failed-to-import-metricbeat-dashboards/162896/8 "2019-02-19T04:17:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
