# Logstash - Elasticsearch filter plugin with basic authentication

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473>\
**Category:** Logstash\
**Created:** [October 14, 2019, 1:57pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473 "2019-10-14T13:57:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlessandroKP](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alessandrokp/32/45312_2.png) [@AlessandroKP](https://discuss.elastic.co/u/AlessandroKP)\
**Post date:** [October 14, 2019, 1:57pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473/1 "2019-10-14T13:57:35Z")

</div>

Hi all,

I have a problem with the Logstash `elasticsearch` filter plugin when using basic authentication. I have created a specific  
user called "logstash\_internal\_reader" which has the built-in `logstash_admin` role and a custom role called `logstash_reader` :

```
{
  "logstash_reader" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "*"
        ],
        "privileges" : [
          "read",
          "view_index_metadata"
        ],
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

I'm testing the `elasticsearch` filter plugin with a very simple pipeline:

```
input { stdin { } }

filter {
        elasticsearch {
                hosts => ["<my-host>"]
                index => "test"
                query => "message:Hello"
                fields => { "message" => "doc_message" }
                user => "logstash_internal_reader"
                password => "<my-password>"
                enable_sort => false
        }
}

output {
  stdout { codec => rubydebug }
}

```

The pipeline is not working. Logstash gives me the following error message:

Pipeline aborted due to error {:pipeline\_id=\>"MY-PIPELINE", :exception=\>#\<Elasticsearch::Transport::Transport::Errors::Forbidden: [403] \>, :backtrace=\>["/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/base.rb:202:in `__raise_transport_error'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/base.rb:319:in`perform\_request'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/transport/http/manticore.rb:67:in `perform_request'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/elasticsearch-transport-5.0.5/lib/elasticsearch/transport/client.rb:131:in`perform\_request'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/elasticsearch-api-5.0.5/lib/elasticsearch/api/actions/ping.rb:20:in `ping'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/logstash-filter-elasticsearch-3.6.0/lib/logstash/filters/elasticsearch.rb:192:in`test\_connection!'", "/app/elk/LOGSTASH/vendor/bundle/jruby/2.5.0/gems/logstash-filter-elasticsearch-3.6.0/lib/logstash/filters/elasticsearch.rb:74:in `register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:56:in`register'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java\_pipeline.rb:195:in `block in register_plugins'", "org/jruby/RubyArray.java:1800:in`each'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java\_pipeline.rb:194:in `register_plugins'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java_pipeline.rb:468:in`maybe\_setup\_out\_plugins'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java\_pipeline.rb:207:in `start_workers'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java_pipeline.rb:149:in`run'", "/app/elk/LOGSTASH/logstash-core/lib/logstash/java\_pipeline.rb:108:in `block in start'"], :thread=\>"#\<Thread:0x2dfae9b0 run\>"}

NB: Using the same logstash\_internal\_reader user I can:  
1. Successfully query documents via CURL  
2. Successfully query documents via Elasticsearch input plugin

---

<div class="post-metadata">

**Author:** ![ea1987](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ea1987/32/51356_2.png) [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Post date:** [October 25, 2019, 9:09am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473/2 "2019-10-25T09:09:31Z")

</div>

Hi guys,  
any news about this issue? Or is there something wrong in our implementation? I would like to be sure, before submitting a github issue.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2019, 9:09am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473/3 "2019-11-22T09:09:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [July 3, 2020, 1:13pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-with-basic-authentication/203473/4 "2020-07-03T13:13:29Z")

</div>

Hello @ea1987  
Late answer, but starting from 3.5.0 (ES Filter plugin), we introduced health checks which require the rights to monitor the cluster (it will perform a `HEAD /`).  
Please add the `monitor` cluster permission.
