# Getting "stats\[n\] does not support wildcards" for \_stats ES API

**URL:** <https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** elastic-stack-security\
**Created:** [December 12, 2023, 10:50am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135 "2023-12-12T10:50:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shweta.c](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@shweta.c](https://discuss.elastic.co/u/shweta.c)\
**Post date:** [December 12, 2023, 10:50am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/1 "2023-12-12T10:50:38Z")

</div>

We have setup an ES cluster(version 8.11.0) using ECK with _xpack.security_ **enabled** and are getting the following error while trying to hit the **"/\_stats"** API -

Sample curl request -

```auto
curl --location 'http://localhost:9200/_stats'

```

Error response -

```auto
{
    "_shards": {
        "total": 10,
        "successful": 0,
        "failed": 10,
        "failures": [
            {
                "shard": 0,
                "index": "test_index",
                "status": "INTERNAL_SERVER_ERROR",
                "reason": {
                    "type": "failed_node_exception",
                    "reason": "Failed node [5-i-JJzsR6OPmdlr4Pc0ag]",
                    "node_id": "5-i-JJzsR6OPmdlr4Pc0ag",
                    "caused_by": {
                        "type": "illegal_argument_exception",
                        "reason": "the action indices:monitor/stats[n] does not support wildcards; the provided index expression(s) [*] are not allowed"
                    }
                }
            }
        ]
    },
    "_all": {
        "primaries": {},
        "total": {}
    },
    "indices": {}
}

```

When we try to get a specific index's stats, that works fine -

Sample curl request -

```auto
curl --location 'http://localhost:9200/test_index/_stats'

```

Snippet of the successful response -

```auto
{
    "_shards": {
        "total": 5,
        "successful": 5,
        "failed": 0
    },
    "_all": {
        "primaries": {
            "docs": {
                "count": 14097379,
                "deleted": 1151323
            },
            ...
        },
        "total": {
            "docs": {
                "count": 14097379,
                "deleted": 1151323
            },
            ...
        }
    },
    "indices": {
        "test_index": {
            "uuid": "NhyCjP_QQLC8TZE24GpvcQ",
            "health": "green",
            "status": "open",
            "primaries": {
                "docs": {
                    "count": 14097379,
                    "deleted": 1151323
                },
                ...
            },
            "total": {
                "docs": {
                    "count": 14097379,
                    "deleted": 1151323
                },
                ...
            }
        }
    }
}

```

We have an existing ES cluster(version 7.16.3) with _xpack.security_ **disabled** and the aforementioned "/\_stats" request works fine there.

Can someone from the Elastic team please help confirm if we need to explicitly enable support for wildcards if xpack.security is enabled; and if yes, how can we achieve that since we could not find any supporting documentation.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 13, 2023, 2:35am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/2 "2023-12-13T02:35:46Z")

</div>

Perhaps per [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html#privileges-list-indices)

> If the Elasticsearch security features are enabled, you must have the monitor or manage index privilege for the target data stream, index, or alias.

Perhaps your user does not have those permissions

---

<div class="post-metadata">

**Author:** ![shweta.c](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@shweta.c](https://discuss.elastic.co/u/shweta.c)\
**Post date:** [December 13, 2023, 8:11am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/3 "2023-12-13T08:11:36Z")

</div>

Thanks, @stephenb .

Yes, the permissions should not be a problem since the following APIs are returning a valid response -

```auto
GET /<target>/_stats/<index-metric>

GET /<target>/_stats

```

The only one where we are seeing the "Internal server error" specifically related to wildcard usage is -

```auto
GET /_stats

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 13, 2023, 4:25pm UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/4 "2023-12-13T16:25:34Z")

</div>

Hmm, weird.... It works for me as expected, same version both with security enabled and without security enabled.

So on a cluster with no security at all, it works...

```auto
hyperion:~ sbrown$ curl http://localhost:9200/
{
  "name" : "ebcb74a532a0",
  "cluster_name" : "docker-cluster",
  "cluster_uuid" : "LiJpuuoJR2WiOzyi796HrA",
  "version" : {
    "number" : "8.11.0",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "d9ec3fa628c7b0ba3d25692e277ba26814820b20",
    "build_date" : "2023-11-04T10:04:57.184859352Z",
    "build_snapshot" : false,
    "lucene_version" : "9.8.0",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}
hyperion:~ sbrown$ curl http://localhost:9200/_stats?pretty
{
  "_shards" : {
    "total" : 2,
    "successful" : 2,
    "failed" : 0
  },
  "_all" : {
    "primaries" : {
      "docs" : {
        "count" : 8,
        "deleted" : 0
      },
      "shard_stats" : {
        "total_count" : 2
      },
      "store" : {
        "size_in_bytes" : 91290,
        "total_data_set_size_in_bytes" : 91290,
        "reserved_in_bytes" : 0
      },

```

And on a cluster with full security, it works...

```auto
hyperion:~ sbrown$ 
hyperion:~ sbrown$ curl -k -u elastic:mypassword https://localhost:9200
{
  "name" : "es01",
  "cluster_name" : "docker-cluster",
  "cluster_uuid" : "DCBYiyU1ST-l5tDxM7tquw",
  "version" : {
    "number" : "8.11.0",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "d9ec3fa628c7b0ba3d25692e277ba26814820b20",
    "build_date" : "2023-11-04T10:04:57.184859352Z",
    "build_snapshot" : false,
    "lucene_version" : "9.8.0",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}
hyperion:~ sbrown$ curl -k -u elastic:mypassword https://localhost:9200/_stats?pretty
{
  "_shards" : {
    "total" : 11,
    "successful" : 11,
    "failed" : 0
  },
  "_all" : {
    "primaries" : {
      "docs" : {
        "count" : 0,
        "deleted" : 0
      },
      "shard_stats" : {
        "total_count" : 11
      },
      "store" : {
        "size_in_bytes" : 2497,
        "total_data_set_size_in_bytes" : 2497,
        "reserved_in_bytes" : 0
      },
      "indexing" : {
        "index_total" : 0,
        "index_time_in_millis" : 0,
        "index_current" : 0,
......

```

I noticed when you have security enabled, you were not passing a username in the curl request... not sure if that was intentional ... or how you are authenticating.

---

<div class="post-metadata">

**Author:** ![shweta.c](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@shweta.c](https://discuss.elastic.co/u/shweta.c)\
**Post date:** [December 13, 2023, 4:48pm UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/5 "2023-12-13T16:48:40Z")

</div>

We are using the readonlyrest plugin with our cluster, could that be causing this erroneous behavior? Since that is used only for authentication, I presumed it should not be throwing the `wildcard` usage error.

> I noticed when you have security enabled, you were not passing a username in the curl request... not sure if that was intentional ... or how you are authenticating.

Yes, even without providing the credentials, the `/_stats` specific API calls work and there is no access issue and we get the response for `/<target>/_stats`.

I did try by explicitly passing the readonlyrest user, but it yielded the same response.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 13, 2023, 4:51pm UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/6 "2023-12-13T16:51:38Z")

</div>

> [@shweta.c](#):
>
> We are using the readonlyrest plugin with our cluster, could that be causing this erroneous behavior?

I do not use / not experienced with ROR ... but if that is the different between yours and mine that would be my first suspect 🙂

---

<div class="post-metadata">

**Author:** ![Oleg2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleg2/32/125215_2.png) [@Oleg2](https://discuss.elastic.co/u/Oleg2)\
**Post date:** [December 28, 2023, 12:24am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/7 "2023-12-28T00:24:12Z")

</div>

@shweta.c commenting about your post from 2022: [ES 7.17 | Exponentially growing query cache](https://discuss.elastic.co/t/es-7-17-exponentially-growing-query-cache/298784)

The issue was fixed in this PR [Make LRUQueryCache respect Accountable queries on eviction and consisten… by gtroitskiy · Pull Request #12614 · apache/lucene · GitHub](https://github.com/apache/lucene/pull/12614)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2024, 12:24am UTC](https://discuss.elastic.co/t/getting-stats-n-does-not-support-wildcards-for-stats-es-api/349135/8 "2024-01-25T00:24:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
