# Issue with Installing X-Pack on ELK - Security Exception Error

**URL:** <https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002>\
**Category:** Elasticsearch\
**Created:** [January 11, 2018, 5:16am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002 "2018-01-11T05:16:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![thelonestargeek](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@thelonestargeek](https://discuss.elastic.co/u/thelonestargeek)\
**Post date:** [January 11, 2018, 5:16am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/1 "2018-01-11T05:16:10Z")

</div>

I'm trying to install the X-Pack on ELK, but I'm having difficulty. Here is where I'm at:

- The elasticsearch and kibana installs have completed without issue

- I've installed X-Pack on logstash

- Issue #1: the instructions said to under #5 here: [https://www.elastic.co/guide/en/logstash/6.x/installing-xpack-log.html](https://www.elastic.co/guide/en/logstash/6.x/installing-xpack-log.html) to edit the logstash.yml config file and change the username and password. Those two settings didn't existing in my logstash.yml file so I added them manually.

- Issue #2  
When I try to query data that has been loaded via logstash I get:  
{  
"error": {  
"root\_cause": [  
{  
"type": "security\_exception",  
"reason": "action [indices:data/read/search] is unauthorized for user [kibana]"  
}  
],  
"type": "security\_exception",  
"reason": "action [indices:data/read/search] is unauthorized for user [kibana]"  
},  
"status": 403  
}

Question #1: How can I fix this?

Question #2: Was it correct to edit the logstash.yml manually?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 11, 2018, 5:48am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/2 "2018-01-11T05:48:15Z")

</div>

> [@thelonestargeek](#):
>
> Question #1: How can I fix this?

It looks like you have logged into Kibana as the `kibana` user.  
That's a common mistake that new users make.

The _kibana_ user is the user that the Kibana application uses for its own purposes when it connects to Elasticsearch. For example, it is how Kibana can tell whether your ES server is available, and whether it has security turned on. You should not log in to Kibana as that user, because it doesn't have permission to do very much (which is intentional - it has just enough access to run Kibana but no more)

You should initially login to Kibana using the `elastic` user. This is a _superuser_ that can do everything.  
You _can_ use that user for everything you want to do, and always login to Kibana as _elastic_, but we don't recommend it. Because that user can do everything, it can make a horrible mess of your cluster if you're not careful, and one of the benefits of X-Pack security is that it can protect you from mistakes like that.

Rather, we recommend that you use the `elastic` user to login the first time, and then use the Kibana admin screens to create new, lower privileged users and roles that have just the permissions that you need, but nothing more. You can then safely use those users to do your work in Kibana, and you can always login as `elastic` if you need to make major changes.

> [@thelonestargeek](#):
>
> Question #2: Was it correct to edit the logstash.yml manually?

Yes, it is entirely unrelated to the error above.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [January 11, 2018, 5:51am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/3 "2018-01-11T05:51:08Z")

</div>

if you are using 6.x then type this command:  
bin/x-pack/setup-passwords auto -u "[http://localhost:9200](http://localhost:9200)"  
and check what is the ELK password.

if you change in logstash.yml file then you have to edit in same in elasticsearch.yml and kibana.yml also

xpack.security.enabled: true in three of .yml file and restart your cluster it should work.

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![thelonestargeek](https://avatars.discourse-cdn.com/v4/letter/t/77aa72/32.png) [@thelonestargeek](https://discuss.elastic.co/u/thelonestargeek)\
**Post date:** [January 11, 2018, 6:16am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/4 "2018-01-11T06:16:49Z")

</div>

Thanks for the quick response. I have resolved my first issues, however I  
am now having issues loading the data into logstash. I am getting this  
output:

#cat stocks.csv | ./logstash -f stocks.conf

Sending Logstash's logs to /Users//Downloads/logstash-6.1.1/logs  
which is now configured via log4j2.properties

[2018-01-11T00:12:44,197][INFO][logstash.modules.scaffold] Initializing  
module {:module\_name=\>"netflow",  
:directory=\>"/Users//Downloads/logstash-6.1.1/modules/netflow/configuration"}

[2018-01-11T00:12:44,211][INFO][logstash.modules.scaffold] Initializing  
module {:module\_name=\>"fb\_apache",  
:directory=\>"/Users//Downloads/logstash-6.1.1/modules/fb\_apache/configuration"}

[2018-01-11T00:12:45,118][INFO][logstash.modules.scaffold] Initializing  
module {:module\_name=\>"arcsight",  
:directory=\>"/Users//Downloads/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/x-pack-6.1.1-java/modules/arcsight/configuration"}

[2018-01-11T00:12:45,238][FATAL][logstash.runner] An unexpected  
error occurred! {:error=\>#\<ArgumentError: Setting "xpack.security.enabled"  
hasn't been registered\>,  
:backtrace=\>["/Users//Downloads/logstash-6.1.1/logstash-core/lib/logstash/settings.rb:32:in  
`get_setting'", "/Users/<USERNAME>/Downloads/logstash-6.1.1/logstash-core/lib/logstash/settings.rb:65:in`set\_value'",  
"/Users//Downloads/logstash-6.1.1/logstash-core/lib/logstash/settings.rb:84:in  
`block in merge'", "org/jruby/RubyHash.java:1343:in`each'",  
"/Users//Downloads/logstash-6.1.1/logstash-core/lib/logstash/settings.rb:84:in  
`merge'", "/Users/<USERNAME>/Downloads/logstash-6.1.1/logstash-core/lib/logstash/settings.rb:133:in`validate\_all'",  
"/Users//Downloads/logstash-6.1.1/logstash-core/lib/logstash/runner.rb:259:in  
`execute'", "/Users/<USERNAME>/Downloads/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'",  
"/Users//Downloads/logstash-6.1.1/logstash-core/lib/logstash/runner.rb:214:in  
`run'", "/Users/<USERNAME>/Downloads/logstash-6.1.1/vendor/bundle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'",  
"/Users//Downloads/logstash-6.1.1/lib/bootstrap/environment.rb:67:in  
`'"]}

How can I resolve this error?

Thanks,

Christina Galligan

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 11, 2018, 6:41am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/5 "2018-01-11T06:41:35Z")

</div>

Remove the

```auto
xpack.security.enabled: true

```

line from your `logstash.yml` file.

@Krunal_kalaria is mistaken, it shouldn't be there.  
In fact you shouldn't need to add it to any configuration file - security is on by default if x-pack is installed with an appropriate license (trial, gold, or platinum).

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [January 11, 2018, 6:47am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/6 "2018-01-11T06:47:16Z")

</div>

once time my kibana is not working then i was try this in .yml file then its working i dont know its wrong thnks @TimV to correct me. 😊🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2018, 6:47am UTC](https://discuss.elastic.co/t/issue-with-installing-x-pack-on-elk-security-exception-error/115002/7 "2018-02-08T06:47:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
