# Metricbeat user and Elasticsearch connection

**URL:** <https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [February 21, 2017, 8:42pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952 "2017-02-21T20:42:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [February 21, 2017, 8:42pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/1 "2017-02-21T20:42:38Z")

</div>

I have been configuring Metricbeat on my ELK configuration using these two documents:  
[Securing Communication With Elasticsearch](https://www.elastic.co/guide/en/beats/metricbeat/current/securing-communication-elasticsearch.html)  
[Beats and Security](https://www.elastic.co/guide/en/x-pack/current/beats.html)

The Metricbeat user I configured is based on the Packetbeat user example on Beats and Security, the following way:

```
POST /_xpack/security/role/metricbeat_writer
{
  "cluster": ["manage_index_templates", "monitor"],
  "indices": [
    {
      "names": ["metricbeat-*"], 
      "privileges": ["read","write","create_index"]
    }
  ]
}

POST _xpack/security/role/metricbeat_reader
{
  "indices": [
    {
      "names": ["metricbeat-*"], 
      "privileges": ["read","view_index_metadata"]
    }
  ]
}

POST /_xpack/security/user/metricbeat_internal
{
  "password" : "<password>",
  "roles" : ["metricbeat_writer", "metricbeat_reader"],
  "full_name" : "Internal Metricbeat User"
}

```

When I execute Metricbeat on my system, I receive the following message repeated times:

`2017-02-21T14:22:38-06:00 WARN Can not index event (status=403): {"type":"security_exception","reason":"action [indices:admin/create] is unauthorized for user [metricbeat_internal]"}`

And even assigning the create privilege, it keeps throwing the same message.  
And I guess it is receiving the information properly, because I also receive this:

`2017-02-21T14:44:49-06:00 INFO Non-zero metrics in the last 30s: fetches.system-filesystem.success=1 fetches.system-fsstat.events=1 libbeat.es.publish.read_bytes=40005 fetches.system-filesystem.events=13 fetches.system-load.success=1`

What should I do?

Thanks in advance

EDIT: I will also add part of what I have configured in `metricbeat.yml`

```
#================================ Outputs =====================================

# Configure what outputs to use when sending the data collected by the beat.
# Multiple outputs may be used.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["https://<my_hostname>"]

  # Optional protocol and basic auth credentials.
  username: "metricbeat_internal"
  password: "<password>"
  ssl.enabled: true
  ssl.verification_mode: none
  ssl.certificate_authorities:
    - <my_path_to_ca.crt>
  template.name: "metricbeat"
  template.path: "<path_to_metricbeat.template.json>"
  template.overwrite: false
```

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [February 22, 2017, 3:15pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/2 "2017-02-22T15:15:45Z")

</div>

This is mostly a workaround I did. I gave somehow a lot of privileges to the Metricbeat user I created, and it seems it works alright. I got it working on Kibana and the logs are being shown.

So I guess it has to be a bug, because when I assign the create privilege to a role which is assigned to the Metricbeat user, it still sends the same message. I will open an issue on Github.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 23, 2017, 2:19pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/3 "2017-02-23T14:19:21Z")

</div>

Can you try to add `create` privileges? This should allow to also load the template: [https://www.elastic.co/guide/en/x-pack/current/security-privileges.html](https://www.elastic.co/guide/en/x-pack/current/security-privileges.html)

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [February 23, 2017, 6:05pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/4 "2017-02-23T18:05:33Z")

</div>

Thanks @ruflin. I did that before, but the same error was given. Although, it seems the issue has been solved, and this is what I did:

After creating the user and adding the superuser role to it, I created a new index pattern on Kibana called metricbeat-\*, so it showed all the data received from Metricbeat. Besides, I also updated my stack version from 5.2.0 to 5.2.1.

Now, I stopped metricbeat service, and also deleted the roles metricbeat\_writer and metricbeat\_reader and the user metricbeat\_internal to later recreate them all, but now adding the create privilege to metricbeat\_writer. Luckily, the error message isn't showing up. I don't know if it is related to the version upgrade or to the index pattern creation.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [February 24, 2017, 9:59am UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/5 "2017-02-24T09:59:16Z")

</div>

Glad it works. Unfortunately I'm not an export on the security x-pack behaviour. If you are interested in what went wrong and why it is probably best to post it in [https://discuss.elastic.co/c/x-pack](https://discuss.elastic.co/c/x-pack).

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 10, 2017, 3:19pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/6 "2017-03-10T15:19:40Z")

</div>

Hey @ruflin, found again the security exception problem. It is not related to the Beats but totally to X-Pack, so I will close the thread here and marked as solved. Thanks for the support!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2017, 3:20pm UTC](https://discuss.elastic.co/t/metricbeat-user-and-elasticsearch-connection/75952/7 "2017-04-07T15:20:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
