# Granting Privileges on Datastream Alias not the same in Backing Indices

**URL:** <https://discuss.elastic.co/t/granting-privileges-on-datastream-alias-not-the-same-in-backing-indices/306643>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 8, 2022, 7:28am UTC](https://discuss.elastic.co/t/granting-privileges-on-datastream-alias-not-the-same-in-backing-indices/306643 "2022-06-08T07:28:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silver137](https://avatars.discourse-cdn.com/v4/letter/s/839c29/32.png) [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Post date:** [June 8, 2022, 7:28am UTC](https://discuss.elastic.co/t/granting-privileges-on-datastream-alias-not-the-same-in-backing-indices/306643/1 "2022-06-08T07:28:08Z")

</div>

I'm using filebeat and i have created 3 datastreams .

```auto
PUT _data_stream/data_s1-2022.06.08
PUT _data_stream/data_s2-2022.06.08
PUT _data_stream/data_s3-2022.06.08

```

And created 3 alias for that datastreams:

```auto
POST _aliases
{
  "actions": [
    {
      "add": {
        "index": "data_s1-2022.06.08",
        "alias": "data_s1",
        "is_write_index": true
      }
    }
  ]
}

POST _aliases
{
  "actions": [
    {
      "add": {
        "index": "data_s2-2022.06.08",
        "alias": "data_s2",
        "is_write_index": true
      }
    }
  ]
}

POST _aliases
{
  "actions": [
    {
      "add": {
        "index": "data_s3-2022.06.08",
        "alias": "data_s3",
        "is_write_index": true
      }
    }
  ]
}

```

Then an API Key for give permissions:

```auto
POST /_security/api_key
{
  "name": "filebeat_datastreams", 
  "role_descriptors": {
    "filebeat_writer": { 
      "cluster": ["monitor", "manage_ingest_pipelines"],
      "index": [
        {
          "names": ["data_s1", "data_s2", "data_s3"],
          "privileges": ["create_doc", "auto_configure"]
        }
      ]
    }
  }
}

```

After give the API Key to filebeat all works well for data\_s1, and data\_s3 but data\_s2 complains.

```auto
action [indices:admin/mapping/auto_put] is unauthorized for API key id [ID] of user [elastic] on indices [.ds-data_s2-2022.06.08-2022.06.08-000001], this action is granted by the index privileges [auto_configure,manage,write,all]\"}

```

I can say that data\_s2 is generated by the netflow filebeat module for version 8.1.0, the other datastreams works well.

- My use case requires the minimun privilege for the API key.
- I can't understand why the privilege is requested by the backing indice if the other datastreams works well.
- I need to resolve the indirection level using the alias on Elasticsearch for management reasons.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2022, 7:28am UTC](https://discuss.elastic.co/t/granting-privileges-on-datastream-alias-not-the-same-in-backing-indices/306643/2 "2022-07-06T07:28:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
