# Logstash can't index into ES: \`action \[indices:admin/auto\_create\] is unauthorized for user\`

**URL:** <https://discuss.elastic.co/t/logstash-cant-index-into-es-action-indices-admin-auto-create-is-unauthorized-for-user/317650>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 27, 2022, 10:42pm UTC](https://discuss.elastic.co/t/logstash-cant-index-into-es-action-indices-admin-auto-create-is-unauthorized-for-user/317650 "2022-10-27T22:42:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 27, 2022, 10:42pm UTC](https://discuss.elastic.co/t/logstash-cant-index-into-es-action-indices-admin-auto-create-is-unauthorized-for-user/317650/1 "2022-10-27T22:42:58Z")

</div>

I created a user `demoTester` with the following roles:

```auto
/usr/share/elasticsearch/bin/elasticsearch-users useradd demoTester -p demoTester -r kibana_admin,logstash_admin,beats_admin,logstash_system,monitoring_user,watcher_admin,editor,machine_learning_admin

```

When I run my deployment script, I can see that Logstash is listening on port `5044` and the logs are being sent, but the user demoTester can't index into ES. I have read the documentation on how to create privileges, but the examples are not clear to me. I am not creating via the Kibana UI, I am automating everything through a script.

```auto
error=>{"type"=>"security_exception", "reason"=>"action [indices:admin/auto_create] is unauthorized for user [demotester] with roles [watcher_admin,editor,monitoring_user,logstash_system,beats_admin,machine_learning_admin,kibana_admin,logstash_admin] on indices [demo-2022.10.27], this action is granted by the index privileges [auto_configure,create_index,manage,all]"}}

```

Here's my logstash conf file:

```auto

input {
  beats {
    port => 5044
  }
}
output {
    elasticsearch {
      ssl => true
      ssl_certificate_verification => true
      cacert => '/etc/logstash/certs/http_ca.crt'
      user => demoTester
      password => demoTester
      hosts => ["https://10.0.8.19:9200"]
      index =>"demo-%{+YYYY.MM.dd}"
    }
}

```

---

<div class="post-metadata">

**Author:** ![Chma](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@Chma](https://discuss.elastic.co/u/Chma)\
**Post date:** [October 27, 2022, 11:14pm UTC](https://discuss.elastic.co/t/logstash-cant-index-into-es-action-indices-admin-auto-create-is-unauthorized-for-user/317650/2 "2022-10-27T23:14:48Z")

</div>

Haven't understood how to add privileges. But as a temporary fix. I made the user `superuser`.

```auto
/usr/share/elasticsearch/bin/elasticsearch-users useradd demoTester -p demoTester -r superuser

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 11:15pm UTC](https://discuss.elastic.co/t/logstash-cant-index-into-es-action-indices-admin-auto-create-is-unauthorized-for-user/317650/3 "2022-11-24T23:15:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
