# \[logstash.outputs.elasticsearch\]\[main\] Failed to install template

**URL:** <https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [March 4, 2022, 10:43am UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835 "2022-03-04T10:43:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khaled\_Saidi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled_saidi/32/98636_2.png) [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Post date:** [March 4, 2022, 10:43am UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835/1 "2022-03-04T10:43:05Z")

</div>

Hi everyone,

After enabling SSL communication on my Elasticsearch server (v7.14.0), i noticed an error in my logstash logs:

`[ERROR][logstash.outputs.elasticsearch][main] Failed to install template {:message=>"Got response code '403' contacting Elasticsearch.........block in after_successful_connection"]`

here is my Elasticsearch.yml ssl conf :

```auto
xpack.security.enabled: true
xpack.security.transport.ssl.enabled: true
xpack.security.http.ssl.enabled: true
xpack.security.transport.ssl.supported_protocols: TLSv1.3,TLSv1.2
xpack.security.http.ssl.key: /path/to/file/file.key
xpack.security.http.ssl.certificate: /path/to/file/file.crt
xpack.security.http.ssl.certificate_authorities: /path/to/file/file.crt
xpack.security.transport.ssl.key: /path/to/file/file.key
xpack.security.transport.ssl.certificate: /path/to/file/file.crt
xpack.security.transport.ssl.certificate_authorities: /path/to/file/file.crt
logger.org.elasticsearch.discovery: info

```

And in my logstash output plugin :

```auto
output {
        elasticsearch {
                hosts => "https://elastic_server_url:9200"
                cacert => "/path/to/file/file.crt"
                index => "my_index"
                user => "elastic-user"
                password => "XXXXX"
                codec => "json"
        }
}

```

The user connected has the role :

```auto
logstash_writer_role:
  cluster: ['monitor']
  run_as: ['{{ elasticsearch_logstash_login }}']
  indices:
          - names: ['{{ elasticsearch_index_name }}']
            privileges: ['write']

```

It works fine with the superuser role. And i don't know what clusters and indexes privileges i need to add to my custom role to make it works.

Any help would be appreciate !  
Thx a lot

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 4, 2022, 10:36pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835/2 "2022-03-04T22:36:05Z")

</div>

I'd use what they have here and remove anything that's not required.

> **[Secure your connection to Elasticsearch | Logstash Reference \[master\] | Elastic](https://www.elastic.co/guide/en/logstash/master/ls-security.html#ls-http-auth-basic)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2022, 10:36pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835/3 "2022-04-01T22:36:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
