# Kibana 7.17.6 \> 8 Kibana\_system 403 unauthorized?

**URL:** <https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288>\
**Category:** Elasticsearch\
**Created:** [January 3, 2024, 8:57am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288 "2024-01-03T08:57:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 3, 2024, 8:57am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288/1 "2024-01-03T08:57:10Z")

</div>

Hi everyone !

i've been upgrading my cluster recently everything went well until i got kibana HTTP 403 Errors with both kibana\_system and elastic users.

Am i supposed to create a user with [manage] [manage\_all] perms in order to migrate system indices ?

```auto
e (api)];"},"status":403},{"index":".kibana_7.17.6_001","id":"ui-metric:upgrade_assistant:overview_page_load","cause":{"type":"cluster_block_exception","reason":"index [.kibana_7.17.6_001] blocked by: [FORBIDDEN/8/index write (api)];"},"status":403},{"index":".kibana_7.17.6_001","id":"application_usage_daily:uptime:2024-01-02","cause":{"type":"cluster_block_exception","reason":"index [.kibana_7.17.6_001] blocked by: [FORBIDDEN/8/index write (api)];"},"status":403},{"index":".kibana_7.17.6_001","id":"search-telemetry:search-telemetry","cause":{"type":"cluster_block_exception"}

```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 3, 2024, 10:44am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288/2 "2024-01-03T10:44:33Z")

</div>

After some hours on the Elastic documentation i came across few things, i should have not created a kibana\_system user with the kibana\_system role as it breaks the role update ?

Now i'm stuck creating a new user, granting some roles, still not authorized 😒

i've basically grant every permissions to the kibana\_test user and incides:admin/mapping/put is unauthorized...

What's the deal with kibana permissions ? am i missing something and also big time strugglin between the API, and the realm where i cannot seem to understand why creating a user with the realm is not replicating it the whole cluster but just the node ?

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 3, 2024, 10:49am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288/3 "2024-01-03T10:49:41Z")

</div>

From kibana startup :

```auto
["error","elasticsearch-service"],"pid":8975,"message":"Unable to retrieve version information from Elasticsearch nodes. security_exception: [security_exception] Reason: unable to authenticate user [kibana_test] for REST request [/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip]"}

```

Meanwhile i can still query curl -k -u 'kibana\_test:x' -X GET "[https://192.168.1.420:9200/\_nodes/](https://192.168.1.420:9200/_nodes/)"

With reply !

Also while booting up Kibana :

```auto
'security_exception: [security_exception] Reason: action [indices:admin/mapping/put] is unauthorized

```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 3, 2024, 11:10am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288/4 "2024-01-03T11:10:32Z")

</div>

> **[Resolve migration failures | Kibana Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/kibana/current/resolve-migrations-failures.html)**

Solved

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2024, 11:10am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288/5 "2024-01-31T11:10:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
