# Logstash user in Xpack

**URL:** <https://discuss.elastic.co/t/logstash-user-in-xpack/95727>\
**Category:** Logstash\
**Created:** [August 3, 2017, 2:02pm UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727 "2017-08-03T14:02:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dencowboy](https://avatars.discourse-cdn.com/v4/letter/d/c67d28/32.png) [@dencowboy](https://discuss.elastic.co/u/dencowboy)\
**Post date:** [August 3, 2017, 2:02pm UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727/1 "2017-08-03T14:02:42Z")

</div>

there are 2 configuration files for our logstash:

- config/logstash.yml
- pipeline/logstash.conf

Now I want to know which roles and which user(s) we minimal need to define to get data to elasticsearch and to see it in kibana.

must the logstash.yml user be the same user als the user in logstash.conf?  
Which roles do we need? The build\_in logstash\_system user had only the logstash\_system role which does not seem to be enough for indices:

```
Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [indices:data/write/bulk] is unauthorized for user [logstash_system]\"}],\"type\":\"security_exception\",\"reason\":\"action [indices:data/write/bulk] is unauthorized for user [logstash_system]\"},\"status\":403}"}

```

> This role does not provide access to the logstash indices and is not suitable for use within a Logstash pipeline.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 4, 2017, 6:15am UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727/2 "2017-08-04T06:15:29Z")

</div>

The documentation for setting up a logstash with X-Pack security is here:

- [https://www.elastic.co/guide/en/x-pack/current/logstash.html](https://www.elastic.co/guide/en/x-pack/current/logstash.html)

You need to create your own user (the docs use `logstash_internal` with role `logstash_writer`) and grant it the specific permissions that are needed for your use of logstash.

---

<div class="post-metadata">

**Author:** ![dencowboy](https://avatars.discourse-cdn.com/v4/letter/d/c67d28/32.png) [@dencowboy](https://discuss.elastic.co/u/dencowboy)\
**Post date:** [August 4, 2017, 12:36pm UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727/4 "2017-08-04T12:36:07Z")

</div>

I did the configuration like on the URL. It works. It's visible in kibana. Log's are send. But the logs of logstash itself are a bit 'strange'.

Every time I perform a manual curl to trigger logs. It's going through logstash so all fine. But when there isn't really happening anything it's showing some forbidden log. I don't know what logstash tries to do. Maybe some health check?

So I did nothing. Than I did a curl (10 times on my apache container). Logs are from logstash to Elastic search. Fine. Then I wait again a bit. Then I curl 4 times. So it works but the logstash logging isn't what I want! Thanks

```
 tion\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:20:58,516][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:21:08,535][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
2017-08-03T20:21:12.487Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.516Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.533Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.546Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.556Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.572Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.589Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.598Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.611Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:21:12.630Z 172.17.0.1 - - [03/Aug/2017:20:21:12 +0000] "GET / HTTP/1.1" 200 45
[2017-08-03T20:21:18,532][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:21:28,542][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:21:38,540][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:21:49,181][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:21:58,552][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
[2017-08-03T20:22:08,553][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}
2017-08-03T20:22:11.375Z 172.17.0.1 - - [03/Aug/2017:20:22:11 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:22:11.398Z 172.17.0.1 - - [03/Aug/2017:20:22:11 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:22:11.456Z 172.17.0.1 - - [03/Aug/2017:20:22:11 +0000] "GET / HTTP/1.1" 200 45
2017-08-03T20:22:11.456Z 172.17.0.1 - - [03/Aug/2017:20:22:11 +0000] "GET / HTTP/1.1" 200 45
[2017-08-03T20:22:18,566][ERROR][logstash.outputs.elasticsearch] Got a bad response code from server, but this code is not considered retryable. Request will be dropped {:code=>403, :response_body=>"{\"error\":{\"root_cause\":[{\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"}],\"type\":\"security_exception\",\"reason\":\"action [cluster:admin/xpack/monitoring/bulk] is unauthorized for user [logstash_internal]\"},\"status\":403}"}

```

Same issue as: [Logstash security\_exception, can't write to ES after installing X-pack](https://discuss.elastic.co/t/logstash-security-exception-cant-write-to-es-after-installing-x-pack/88973) I think

---

<div class="post-metadata">

**Author:** ![dencowboy](https://avatars.discourse-cdn.com/v4/letter/d/c67d28/32.png) [@dencowboy](https://discuss.elastic.co/u/dencowboy)\
**Post date:** [August 4, 2017, 1:20pm UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727/5 "2017-08-04T13:20:31Z")

</div>

adding monitor\_role fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 1:20pm UTC](https://discuss.elastic.co/t/logstash-user-in-xpack/95727/6 "2017-09-01T13:20:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
