# Login to Kibana indices:data/write/update is unauthorized for user

**URL:** <https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787>\
**Category:** Kibana\
**Created:** [February 21, 2018, 8:31am UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787 "2018-02-21T08:31:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![seyhmus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seyhmus/32/27977_2.png) [@seyhmus](https://discuss.elastic.co/u/seyhmus)\
**Post date:** [February 21, 2018, 8:31am UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787/1 "2018-02-21T08:31:10Z")

</div>

Hi all,

We have started to use x-pack and configured the AD integration according to documentation on elastic website. We have granted read to kibana index for users and necessary permissions for their indices. However time to time they have **Error 403 Forbidden: action [indices:data/write/update] is unauthorized for user** error and there is no entry on elasticsearch or kibana logs. I am attaching

```
GET /_xpack/security/role

```

"identity\_team": {  
"cluster": [],  
"indices": [  
{  
"names": [  
"ldap-_",  
".kibana_"  
],  
"privileges": [  
"monitor",  
"read"  
],  
"field\_security": {  
"grant": [  
"\*"  
]  
}  
}  
],  
"run\_as": [],  
"metadata": {},  
"transient\_metadata": {  
"enabled": true  
}  
}

and

```
GET /_xpack/security/user

```

{  
"logstash\_internal": {  
"username": "logstash\_internal",  
"roles": [  
"logstash\_writer"  
],  
"full\_name": "Internal Logstash User",  
"email": null,  
"metadata": {},  
"enabled": true  
},  
"logstash\_user": {  
"username": "logstash\_user",  
"roles": [  
"logstash\_reader"  
],  
"full\_name": "Kibana User",  
"email": null,  
"metadata": {},  
"enabled": true  
},  
"monuser": {  
"username": "monuser",  
"roles": [  
"remote\_monitoring\_agent"  
],  
"full\_name": "Monitoring User",  
"email": "xxx@yyy.com",  
"metadata": {},  
"enabled": true  
},  
"curator": {  
"username": "curator",  
"roles": [  
"index\_manager"  
],  
"full\_name": "Curator Automation",  
"email": "manager@xxx.com",  
"metadata": {},  
"enabled": true  
},  
"elastic": {  
"username": "elastic",  
"roles": [  
"superuser"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
},  
"kibana": {  
"username": "kibana",  
"roles": [  
"kibana\_system"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
},  
"logstash\_system": {  
"username": "logstash\_system",  
"roles": [  
"logstash\_system"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
}  
}

outputs. Also my elasticsearch.yml is

```
xpack:
  security:
    authc:
      realms:
        file:
          type: file
          order: 0
        native:
          type: native
          order: 1
        active_directory:
          type: active_directory
          order: 2
          domain_name: <my_domain>
          url: ldap://<ad_auth_server>:389
          bind_dn: CN=<es_user>,CN=Users,DC=xx,DC=yyyy,DC=zzz
          bind_password: <es_passwd>
          follow_referrals: false

```

Any ideas to check.

Thanks.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 22, 2018, 9:51pm UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787/2 "2018-02-22T21:51:48Z")

</div>

Do you have Elasticsearch audit logging enabled? It might help narrow the problem down a bit;  
[https://www.elastic.co/guide/en/x-pack/6.2/auditing.html](https://www.elastic.co/guide/en/x-pack/6.2/auditing.html)  
We don't know what index the error was on, but I'm pretty sure that audit logging would show it.

You included the roles and users but you didn't say what user is having this issue?

---

<div class="post-metadata">

**Author:** ![seyhmus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seyhmus/32/27977_2.png) [@seyhmus](https://discuss.elastic.co/u/seyhmus)\
**Post date:** [February 23, 2018, 8:04am UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787/3 "2018-02-23T08:04:17Z")

</div>

Hi Lee,

Thanks for the reply. Firstly i am using version 5.6 until i will setup the ssl between components, so i am not sure about audit logging. i will read about it asap.

All the roles from AD are having the problem time to time. Strange thing is AD admins cannot see any error on the logs and the problem is not occuring everytime, but when it is happening it stays at least few hours or sometimes a couple of days.

---

<div class="post-metadata">

**Author:** ![seyhmus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seyhmus/32/27977_2.png) [@seyhmus](https://discuss.elastic.co/u/seyhmus)\
**Post date:** [February 27, 2018, 1:29pm UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787/4 "2018-02-27T13:29:09Z")

</div>

Solved...

AD group names are case sensitive in elastic and recently they change one of the group names. updating the group name solved the problem.

Thank you Lee.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2018, 1:29pm UTC](https://discuss.elastic.co/t/login-to-kibana-indices-data-write-update-is-unauthorized-for-user/120787/5 "2018-03-27T13:29:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
