# Insufficent permission for apm\_system user

**URL:** https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197
**Category:** APM
**Tags:** server
**Created:** [July 6, 2019, 8:18am UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197 "2019-07-06T08:18:38Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![chikien276](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chikien276/32/49551_2.png) [@chikien276](https://discuss.elastic.co/u/chikien276)
#### Post date: [July 6, 2019, 8:18am UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/1 "2019-07-06T08:18:38Z")

</div>

My APM server cannot connect to ElasticSearch using apm\_system user and ,  
I've tried disable and enabled `setup.template.overwrite`.

**Kibana version** :  
7.2.0

**Elasticsearch version** :  
7.2.0

**APM Server version** :  
7.2.0

**APM Agent language and version** :

**Browser version** :

**Original install method (e.g. download page, yum, deb, from source, etc.) and version**: I downloaded zips and created Windows services

**Fresh install or upgraded from other version?** Fresh

**Is there anything special in your setup?**  
I started with no X-Pack security enabled first, then hours later, I enabled security and created password for default system users/accounts  
**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:  
APM server logs show that it cannot connect to ElasticSearch due to following logs.

**Errors in browser console (if relevant)**:

**Provide logs and/or server output (if relevant)**:  
ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([http://localhost:9200](http://localhost:9200))): Connection marked as failed because the onConnect callback failed: error loading Elasticsearch template: could not load template. Elasticsearch returned: couldn't load template: 403 Forbidden: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/template/put] is unauthorized for user [apm\_system]"}],"type":"security\_exception","reason":"action [indices:admin/template/put] is unauthorized for user [apm\_system]"},"status":403}. Response body: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/template/put] is unauthorized for user [apm\_system]"}],"type":"security\_exception","reason":"action [indices:admin/template/put] is unauthorized for user [apm\_system]"},"status":403}. Template is: {  
"index\_patterns": [  
"apm-7.2.0\*"  
],  
...  
}

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [July 7, 2019, 10:37pm UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/2 "2019-07-07T22:37:38Z")

</div>

Hello and thanks for trying Elastic APM and welcome to the Elastic Discuss Forum.

Question ... how did you configure the Output section in the `apm-server.yml` did you use the built in `elastic` user or some other user?

```
#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  # Scheme and port can be left out and will be set to the default (http and 9200)
  # In case you specify and additional path, the scheme is required: http://localhost:9200/path
  # IPv6 addresses should always be defined as: https://[2001:db8::1]:9200
  hosts: ["my-es-cluster:9200"]

  # Boolean flag to enable or disable the output module.
  #enabled: true

  # Set gzip compression level.
  #compression_level: 0

  # Optional protocol and basic auth credentials.
  protocol: "https"
  username: "elastic"
  password: "changeme"
```

---

<div class="post-metadata">

### Author: ![chikien276](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chikien276/32/49551_2.png) [@chikien276](https://discuss.elastic.co/u/chikien276)
#### Post date: [July 8, 2019, 8:38am UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/3 "2019-07-08T08:38:45Z")

</div>

Thank you,  
I used `apm_system` built in user. So, according to your answer, I should use `elastic` user instead of `apm_system`, shouldn't I?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [July 8, 2019, 3:07pm UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/4 "2019-07-08T15:07:01Z")

</div>

Yes apologies for not being clear use the `elastic` user not the `apm_system` user which is typically used for monitoring the APM Server not for ingesting APM events. See built in roles [here](https://www.elastic.co/guide/en/elastic-stack-overview/7.2/built-in-roles.html)

---

<div class="post-metadata">

### Author: ![chikien276](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chikien276/32/49551_2.png) [@chikien276](https://discuss.elastic.co/u/chikien276)
#### Post date: [July 8, 2019, 5:08pm UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/5 "2019-07-08T17:08:30Z")

</div>

Thank you very much for your reply.

I’m sure that it is going to work well.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 29, 2019, 1:08pm UTC](https://discuss.elastic.co/t/insufficent-permission-for-apm-system-user/189197/6 "2019-07-29T13:08:35Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
