# How to display the documents present in .security index?

**URL:** <https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 1, 2016, 9:26pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602 "2016-09-01T21:26:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sampathkumar23](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sampathkumar23](https://discuss.elastic.co/u/sampathkumar23)\
**Post date:** [September 1, 2016, 9:26pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/1 "2016-09-01T21:26:06Z")

</div>

When I try to fetch all the documents in .security index, getting 403 even with admin user.

[http://localhost:9200/.security/\_search](http://localhost:9200/.security/_search)

{"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:data/read/search] is unauthorized for user [es\_admin]"}],"type":"security\_exception","reason":"action [indices:data/read/search] is unauthorized for user [es\_admin]"},"status":403}

My goal is see all the users present.

[http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) - works and gives me the count of users/documents that I have added (i have added 3 users)  
health status index pri rep docs.count docs.deleted store.size pri.store.size  
green open .security 1 0 3 0 12.2kb 12.2kb

Can someone please help?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [September 1, 2016, 9:58pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/2 "2016-09-01T21:58:06Z")

</div>

Hey Sam,

You should be able to use the Shield Users API to list the current users

[https://www.elastic.co/guide/en/shield/current/shield-rest.html#shield-users-rest](https://www.elastic.co/guide/en/shield/current/shield-rest.html#shield-users-rest)

so you could hit `http://localhost:9200/_shield/user` and it will return all configured users.

Hope that helps!  
Steve

---

<div class="post-metadata">

**Author:** ![sampathkumar23](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sampathkumar23](https://discuss.elastic.co/u/sampathkumar23)\
**Post date:** [September 2, 2016, 6:38pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/3 "2016-09-02T18:38:27Z")

</div>

Thanks a lot Steve. It works. It doesn't return the admin user name. Is there a way to fetch the admin user name too?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [September 2, 2016, 9:25pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/4 "2016-09-02T21:25:43Z")

</div>

Which admin username are you expecting to see returned that you're not?

As a quick guess: It can sometimes be confusing that we have two "built-in" realms - a `file` based realm, and the `native` API-based realm. The API will only return users that were created via the API, so if your "admin" user was defined in the File-based realm, it won't be returned.

If possible, I suggest using the API-based realm exclusively!

---

<div class="post-metadata">

**Author:** ![sampathkumar23](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sampathkumar23](https://discuss.elastic.co/u/sampathkumar23)\
**Post date:** [September 2, 2016, 10:21pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/5 "2016-09-02T22:21:33Z")

</div>

Hi Steve,

Thanks a lot for response.  
You are right. I created the admin user using esusers tool and the remaining users I created using the API.  
bin/shield/esusers useradd es\_admin -r admin

/\_shield/user returns every user I have created using the api. Just the admin user is not returned.

Follow up question.  
I first installed elastic search and then added shield to it. The moment I added shield, I was not able to make any requests. I read through the documentation and interpreted (probably mis-interpreted) that the admin user has to be created first using the esusers utility only and then the other users can be created using API.  
[https://www.elastic.co/guide/en/shield/current/enable-basic-auth.html](https://www.elastic.co/guide/en/shield/current/enable-basic-auth.html)

But you sound like we can use api to create the admin user too in the very beginning too. Is that right? Can you please help me understand this?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [September 6, 2016, 2:01am UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/6 "2016-09-06T02:01:11Z")

</div>

Indeed, in ES 2.3 and 2.4, you will need to create a file-based administrative user, so you can use the API to create additional users. Depending on your use-case, a good practice might be to create the file-based user, and use it to create a `native` realm administrative account, then delete the file-based user. This way, you can manage the user, including password changes, etc., via API.

Note that starting in 5.0, Shield will have a built-in admin (`elastic`) and kibana server user (`kibana`), which will simplify this process!

---

<div class="post-metadata">

**Author:** ![sampathkumar23](https://avatars.discourse-cdn.com/v4/letter/s/2acd7d/32.png) [@sampathkumar23](https://discuss.elastic.co/u/sampathkumar23)\
**Post date:** [September 6, 2016, 3:05pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/7 "2016-09-06T15:05:31Z")

</div>

Hi Steve,

Thanks a lot for your help.

Thanks,  
Sam

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-present-in-security-index/59602/8 "2017-07-06T13:41:56Z")

</div>


