# GKE Elastic Agent, Ingest pipeline permissions question

**URL:** <https://discuss.elastic.co/t/gke-elastic-agent-ingest-pipeline-permissions-question/370571>\
**Category:** Elasticsearch\
**Created:** [November 14, 2024, 6:38pm UTC](https://discuss.elastic.co/t/gke-elastic-agent-ingest-pipeline-permissions-question/370571 "2024-11-14T18:38:30Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![marksie1988](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marksie1988/32/138606_2.png) [@marksie1988](https://discuss.elastic.co/u/marksie1988)\
**Post date:** [November 14, 2024, 6:38pm UTC](https://discuss.elastic.co/t/gke-elastic-agent-ingest-pipeline-permissions-question/370571/1 "2024-11-14T18:38:30Z")

</div>

Hi All,

I have elastic cloud, with the elastic-agent deployed in a kubernetes cluster, this has a GCP integration to get messages from pubsub.

Once the agent gets the messages from pubsub i have an ingest pipeline that has a script processor in it to use a specific index e.g. my-index-yyyy.mm.dd

if the index doesnt exist it tries to create it but i get the error:

`Cannot index event (status=403): dropping event!`

I enabled debug logging and get this error:

```auto
action [indices:admin/auto_create] is unauthorized for API key id [123123123] of user [elastic/fleet-server] on indices [my-index-2024.11.11], this action is granted by the index privileges [auto_configure,create_index,manage,all]

```

I cant for the life of me figure out where i can assign these privileges so that it is able to create the index, does anyone know?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 14, 2024, 7:22pm UTC](https://discuss.elastic.co/t/gke-elastic-agent-ingest-pipeline-permissions-question/370571/2 "2024-11-14T19:22:56Z")

</div>

> [@marksie1988](#):
>
> I cant for the life of me figure out where i can assign these privileges so that it is able to create the index, does anyone know?

If I'm not wrong you cannot use an Elastic Agent managed by Fleet to write into a custom index like that.

Check this [answer](https://discuss.elastic.co/t/elastic-fleet-server-cannot-create-write-to-index-insufficient-permissions/294181/2) to a similar question.

> No, it is not possible. The fleet-server service account is only able to write to indices that are managed by fleet, and there is no way to change that.

The alternative would be to write into something that the service account has permission, for example a data stream starting with `logs-*`.
