# Indices:data/write/bulk\[s\] access denied for reporting user

**URL:** <https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259>\
**Category:** Elasticsearch\
**Created:** [June 5, 2017, 11:06am UTC](https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259 "2017-06-05T11:06:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![azelezni](https://avatars.discourse-cdn.com/v4/letter/a/b5ac83/32.png) [@azelezni](https://discuss.elastic.co/u/azelezni)\
**Post date:** [June 5, 2017, 11:06am UTC](https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259/1 "2017-06-05T11:06:24Z")

</div>

Hello, I've been configuring a user for auto generating and sending reports via watch.

The user is an LDAP user and I have configured the "kibana\_user" and "reporting\_user" roles via "/etc/elasticsearch/x-pack/role\_mappings.yml" but every time I try and run the watch to generate the reports I get a 403 return code.  
Looking at elasticsearch\_access.log I see:

> [2017-06-05T13:56:28,475] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[cluster:admin/xpack/security/user/authenticate], request=[AuthenticateRequest]  
> [2017-06-05T13:56:28,478] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[cluster:admin/xpack/security/user/authenticate], request=[AuthenticateRequest]  
> [2017-06-05T13:56:28,492] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[cluster:admin/xpack/security/user/authenticate], request=[AuthenticateRequest]  
> [2017-06-05T13:56:28,494] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[indices:data/read/get], indices=[.kibana], request=[GetRequest]  
> [2017-06-05T13:56:28,495] [transport] [access\_granted] origin\_type=[local\_node], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[indices:data/read/get[s]], indices=[.kibana], request=[GetRequest]  
> [2017-06-05T13:56:28,502] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[indices:data/write/index], indices=[.reporting-2017.06.04], request=[IndexRequest]  
> [2017-06-05T13:56:28,502] [transport] [access\_granted] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[indices:data/write/bulk], request=[BulkRequest]  
> [2017-06-05T13:56:28,502] [transport] [access\_denied] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[bgu\_testuser], action=[indices:data/write/bulk[s]], indices=[.reporting-2017.06.04], request=[BulkShardRequest]

I've even tried giving the reporting user the superuser role, and still the same error, but if I try with my own user (LDAP also) everything works find.

Using curl:

> curl -v -u reporting\_user -XPOST '[https://elk.example.com/api/reporting/generate/dashboard/9ccbe5a0-4902-11e7-b901-6b6ef7aa4db7?\_g=(some\_stuff)](https://elk.example.com/api/reporting/generate/dashboard/9ccbe5a0-4902-11e7-b901-6b6ef7aa4db7?_g=(some%5C_stuff))' -H kbn-version:5.4.0

The report is created and I can download it from web UI or via curl.

Here is the watch:

> {  
> "trigger": {  
> "schedule": {  
> "interval": "1h"  
> }  
> },  
> "input": {  
> "none": {}  
> },  
> "condition": {  
> "always": {}  
> },  
> "actions": {  
> "email\_bgu": {  
> "email": {  
> "profile": "standard",  
> "to": [  
> "[alex@example.com](mailto:alex@example.com)"  
> ],  
> "subject": "Report",  
> "attachments": {  
> "report.pdf": {  
> "reporting": {  
> "url": "[https://elk.example.com/api/reporting/generate/dashboard/9ccbe5a0-4902-11e7-b901-6b6ef7aa4db7?\_g=(some\_settings)](https://elk.example.com/api/reporting/generate/dashboard/9ccbe5a0-4902-11e7-b901-6b6ef7aa4db7?_g=(some_settings))",  
> "auth": {  
> "basic": {  
> "username": "reporting\_user",  
> "password": "some\_pass"  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [June 5, 2017, 11:11am UTC](https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259/2 "2017-06-05T11:11:48Z")

</div>

Since this question is about security, watcher and reporting in x-pack I'm going to move this to the X-Pack category

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 6, 2017, 12:42pm UTC](https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259/3 "2017-06-06T12:42:52Z")

</div>

Can you paste the output of the [Execute Watch API](https://www.elastic.co/guide/en/x-pack/5.4/watcher-api-execute-watch.html)

This will allow us to check what happens here with a bit more detail. Run the API like this

```auto
POST _xpack/watcher/watch/your_watch_id/_execute

```

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2017, 12:43pm UTC](https://discuss.elastic.co/t/indices-data-write-bulk-s-access-denied-for-reporting-user/88259/4 "2017-07-04T12:43:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
