# Metricbeat and Elastic Security

**URL:** <https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637>\
**Category:** Beats\
**Tags:** elastic-stack-security, metricbeat\
**Created:** [February 8, 2022, 4:38pm UTC](https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637 "2022-02-08T16:38:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![holobolo0815](https://avatars.discourse-cdn.com/v4/letter/h/ecc23a/32.png) [@holobolo0815](https://discuss.elastic.co/u/holobolo0815)\
**Post date:** [February 8, 2022, 4:38pm UTC](https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637/1 "2022-02-08T16:38:28Z")

</div>

Hello,

So I have setup Elasticsearch security. Usual logging works fine using a logstash\_internal user using the appropriate role recommended by the docs.

I'm having a hard time however finding out how to configure Metricbeat...

[This page](https://www.elastic.co/guide/en/beats/metricbeat/current/feature-roles.html) says that several roles need to exist, like for "setup" but don't exactly tell where they are used / should be configured.

What I'm getting at startup:

```auto
metricbeat[27436]: 2022-02-08T17:06:40.845+0100#011ERROR#011[publisher_pipeline_output]#011pipeline/output.go:154#011Failed to connect to backoff(elasticsearch(http://localhost:9200)): Connection marked as failed because the onConnect callback failed: error loading template: failure while checking if template exists: 403 Forbidden:

```

`output.elasticsearch` is using the metricbeat\_writer user as described [here](https://www.elastic.co/guide/en/beats/metricbeat/current/privileges-to-publish-events.html) and [here](https://www.elastic.co/guide/en/beats/metricbeat/current/securing-communication-elasticsearch.html).

However [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-users.html) it says to use remote\_monitoring\_user.

So which is true?

Which user do I use in metricbeat.yml for output.Elasticsearch?

Which user do I use in modules.d/Elasticsearch-xpack.yml for monitoring Elasticsearch?

Thx,  
Marki

```auto
# metricbeat modules list
Enabled:
elasticsearch-xpack
kibana-xpack
logstash-xpack
system

```

```auto
#metricbeat.yml
metricbeat.config.modules:
  path: ${path.config}/modules.d/*.yml

  reload.enabled: false

setup.template.settings:
  index.number_of_shards: 1
  index.codec: best_compression

setup.kibana:

  username: "metricbeat_kib_setup"
  password: "password"

output.elasticsearch:
  hosts: ["localhost:9200"]

  username: "metricbeat_internal"
  password: "password"

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

path.logs: /var/log/metricbeat

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2022, 6:38pm UTC](https://discuss.elastic.co/t/metricbeat-and-elastic-security/296637/2 "2022-03-08T18:38:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
