# Not able to update security index settings

**URL:** https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886
**Category:** Elasticsearch
**Tags:** elastic-stack-security
**Created:** [July 8, 2025, 6:04am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886 "2025-07-08T06:04:23Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![kuldeep\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuldeep_gupta/32/88162_2.png) [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)
#### Post date: [July 8, 2025, 6:04am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/1 "2025-07-08T06:04:23Z")

</div>

Hello all,  
I am using elasticsearch version **8.9.0**. i want to configure security index to have replica on every node.  
I am using kibana console for running below command

```auto
PUT /_security/settings
{
    "security": {
        "index.auto_expand_replicas": "0-all"
    },
    "security-profile": {
        "index.auto_expand_replicas": "0-all"
    }
}

```

for above command i am getting error

```auto
{
  "error": "Incorrect HTTP method for uri [/_security/settings?pretty=true] and method [PUT], allowed: [POST]",
  "status": 405
}

```

when i changed method from **PUT** to **POST**  
it is giving below error

```auto
{
  "error": "no handler found for uri [/_security/settings?pretty=true] and method [POST]"
}

```

but the same command with PUT method executed successfully on another cluster having version **8.12.0**.  
Can someone please help me with this.

---

<div class="post-metadata">

### Author: ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)
#### Post date: [July 8, 2025, 10:38am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/2 "2025-07-08T10:38:29Z")

</div>

Hello @kuldeep_gupta

I tried to execute the below & did not receive any error on 9.0.3

```auto
PUT /_security/settings
{
    "security": {
        "index.auto_expand_replicas": "0-all"
    },
    "security-profile": {
        "index.auto_expand_replicas": "0-all"
    }
}

```

Could you please try to fetch current settings :

`GET /_security/settings`

Thanks!!

---

<div class="post-metadata">

### Author: ![kuldeep\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuldeep_gupta/32/88162_2.png) [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)
#### Post date: [July 8, 2025, 2:04pm UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/3 "2025-07-08T14:04:36Z")

</div>

> [@Tortoise](#):
>
> `GET /_security/settings`

```auto
{
  "error": "Incorrect HTTP method for uri [/_security/settings?pretty=true] and method [GET], allowed: [POST]",
  "status": 405
}

```

---

<div class="post-metadata">

### Author: ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)
#### Post date: [July 9, 2025, 5:15am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/4 "2025-07-09T05:15:47Z")

</div>

Hello @kuldeep_gupta

As per the documentation , could you please check below point for your user -

```auto
### Required authorization
Cluster privileges: `read_security`

```

> **[Get security index settings | Elasticsearch API documentation (v8)](https://www.elastic.co/docs/api/doc/elasticsearch/v8/operation/operation-security-get-settings)**
>
> Get the user-configurable settings for the security internal index (.security and associated indices).
> Only a subset of the index settings — those that are user-configurable—wil...

Thanks!!

---

<div class="post-metadata">

### Author: ![kuldeep\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuldeep_gupta/32/88162_2.png) [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)
#### Post date: [July 9, 2025, 3:32pm UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/5 "2025-07-09T15:32:46Z")

</div>

```auto
{
  "cluster": [
    "all"
  ],
  "global": [],
  "indices": [
    {
      "names": [
        "*"
      ],
      "privileges": [
        "all"
      ],
      "allow_restricted_indices": false
    },
    {
      "names": [
        "*"
      ],
      "privileges": [
        "monitor",
        "read",
        "read_cross_cluster",
        "view_index_metadata"
      ],
      "allow_restricted_indices": true
    }
  ],
  "applications": [
    {
      "application": "*",
      "privileges": [
        "*"
      ],
      "resources": [
        "*"
      ]
    }
  ],
  "run_as": [
    "*"
  ]
}

```

above is the output of below command

> GET /\_security/user/\_privileges

note that i am using **elastic** user in kibana.

---

<div class="post-metadata">

### Author: ![lcawley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcawley/32/58441_2.png) [@lcawley](https://discuss.elastic.co/u/lcawley)
#### Post date: [July 9, 2025, 4:12pm UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/6 "2025-07-09T16:12:22Z")

</div>

I believe that API was added in 8.10 per [Add an API for managing the settings of Security system indices by gwbrown · Pull Request #97630 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/97630), which I see in the 8.10.0 [release notes](https://www.elastic.co/guide/en/elasticsearch/reference/8.10/release-notes-8.10.0.html)

---

<div class="post-metadata">

### Author: ![kuldeep\_gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kuldeep_gupta/32/88162_2.png) [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)
#### Post date: [July 9, 2025, 4:18pm UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/7 "2025-07-09T16:18:38Z")

</div>

Thank you mam for response,  
Is there any way i can achieve this in version 8.9?

---

<div class="post-metadata">

### Author: ![lcawley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcawley/32/58441_2.png) [@lcawley](https://discuss.elastic.co/u/lcawley)
#### Post date: [July 10, 2025, 2:41am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/8 "2025-07-10T02:41:36Z")

</div>

My area of expertise is the Elastic documentation, so beyond the information that's available in [Productize a way to change index.auto\_expand\_replicas and index.number\_of\_replicas settings on the .security index · Issue #92992 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/92992), I can only offer that per [API convention docs](https://www.elastic.co/docs/reference/elasticsearch/rest-apis/api-conventions#system-indices) "Direct access to system indices is deprecated and will no longer be allowed in a future major version." Thus even if you managed to edit the index settings on the individual security system indices (e.g. via the [update index settings API](https://www.elastic.co/guide/en/elasticsearch/reference/8.9/indices-update-settings.html) or the [Index Management app](https://www.elastic.co/guide/en/elasticsearch/reference/8.9/index-mgmt.html)), the recommended long-term solution would be to use the APIs that were added in 8.10.

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [July 10, 2025, 3:23am UTC](https://discuss.elastic.co/t/not-able-to-update-security-index-settings/379886/9 "2025-07-10T03:23:08Z")

</div>

> [@kuldeep\_gupta](#):
>
> Is there any way i can achieve this in version 8.9?

No.

Also, 8.9 is very old (it was [released](https://www.elastic.co/blog/whats-new-elasticsearch-platform-8-9-0) 2 years ago), so you should try to schedule an upgrade.
