# Fleet API account missing security settings

**URL:** <https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [February 15, 2023, 3:45pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643 "2023-02-15T15:45:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsaeks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsaeks/32/5068_2.png) [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Post date:** [February 15, 2023, 3:45pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643/1 "2023-02-15T15:45:10Z")

</div>

Hi all,

I'm on v8.6 of the ELK stack and working on some new custom log parsing. It looks like the configuration is reading our initial test data properly, however it appears the built-in Fleet API account is missing some permissions and is unable to create the index:

```auto
{"type":"security_exception","reason":"action [indices:admin/auto_create] is unauthorized for API key id [KEYID] of user [elastic/fleet-server] on indices [logs-connectedclients-default], this action is granted by the index privileges [auto_configure,create_index,manage,all]"}, dropping event!

```

Since this was automatically setup when configuring Fleet, I don't have a way to adjust the permissions since the accounts / roles are all built-in.

Is there a way to adjust these some other way?

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [February 16, 2023, 9:20am UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643/2 "2023-02-16T09:20:55Z")

</div>

Hi, it might be due to the API keys are not regenerated with the new data stream permissions.  
Have you installed a new version of the integration? It could help to upgrade or re-add the integration policy, that should trigger the API key regeneration.  
Here is a related public issue: [[Fleet] API Keys are not updated after adding data streams to package · Issue #148524 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/148524)

---

<div class="post-metadata">

**Author:** ![rsaeks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsaeks/32/5068_2.png) [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Post date:** [February 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643/3 "2023-02-28T18:32:11Z")

</div>

Thank you for the info, Julia!

As I was working through this a bit since I saw the data stream was deprecated I moved over to filestream and was able to get that working!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643/4 "2023-03-28T18:32:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
