# Possible error in documentaion about creating an API key for central management

**URL:** <https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [January 18, 2025, 12:06pm UTC](https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355 "2025-01-18T12:06:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jack\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_a/32/133082_2.png) [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Post date:** [January 18, 2025, 12:06pm UTC](https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355/1 "2025-01-18T12:06:19Z")

</div>

So i was reading the document:[Secure your connection to Elasticsearch](https://www.elastic.co/guide/en/logstash/current/ls-security.html) section:[Create an API key for central management](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-api-key-man) and when i try to run the provided example:

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": ["read"]
    }
  }
}

```

i get the following error:

```auto

{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "failed to parse indices privileges for role [logstash_monitoring]. expected field [null] value to be an array of objects, but found an array element of type [VALUE_STRING]"
      }
    ],
    "type": "x_content_parse_exception",
    "reason": "[6:17] [api_key_request] failed to parse field [role_descriptors]",
    "caused_by": {
      "type": "x_content_parse_exception",
      "reason": "[6:17] [role_descriptors] failed to parse field [logstash_monitoring]",
      "caused_by": {
        "type": "parse_exception",
        "reason": "failed to parse indices privileges for role [logstash_monitoring]. expected field [null] value to be an array of objects, but found an array element of type [VALUE_STRING]"
      }
    }
  },
  "status": 400
}

```

just want to make sure that the example is right?!

also as i was trying to figure out what is wrong, i came across another problem. there is another example in the same document in the section above : [Create an API key for monitoring](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-api-key-monitor) which is as follow :

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": [
        {
          "names": [".monitoring-ls-*"],
          "privileges": ["create_index", "create"]
        }
      ]
    }
  }
}

```

and this works. Then i read the document [Create API key API](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/security-api-create-api-key.html) and it says

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/6/966a14842ae3fcf1ea8d0280559eb238777a24e4.png)  
so i thought maybe the problem with the first example is not defining `names` field as document says it is **required**. Then there is another problem that in both documents [(1)](https://www.elastic.co/guide/en/elasticsearch/reference/8.17/security-api-create-api-key.html) and [(2)](https://www.elastic.co/docs/api/doc/elasticsearch/v8/operation/operation-security-create-api-key) under `role_descriptors` there is a field named `indices` but not `index`, so maybe, although it works, this is also a old reference and need to be updated?

to recap:  
1 . is the first example right?  
2. should the field `index` be changed to `indices` to represent latest api changes?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 19, 2025, 7:15pm UTC](https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355/2 "2025-01-19T19:15:58Z")

</div>

Hi @jack_a

I am confused... or perhaps you are ... the definitions of the API keys are correct but then need to be used in the correct context...

Your first example is to create a key for Central monitoring per the docs but the error message you provide is not for that API Key

You created

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": ["read"]
    }
  }
}

```

but there error you show is for a different key...

```auto
 "reason": "failed to parse indices privileges for role >>>[logstash_monitoring]<<<<. expected field [null] value to be an array of objects, but found an array element of type [VALUE_STRING]"

```

You need to create the keys per the specs and then use them for the correct authentication...

> [@jack\_a](#):
>
> just want to make sure that the example is right?!

Yes that is correct but then it is only valid for management not monitoring

```auto
xpack.management.elasticsearch.api_key: TiNAGG4BaaMdaH1tRfuU:KnR6yE41RrSowb0kQ0HWoA 

```

You can not mix them  
perhaps you are creating a management key ... and then trying to use that key for monitoring which will no work....or vice versa

---

<div class="post-metadata">

**Author:** ![jack\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_a/32/133082_2.png) [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Post date:** [January 25, 2025, 1:05pm UTC](https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355/3 "2025-01-25T13:05:02Z")

</div>

Thanks for the reply.

OH! my bad. So it is a configuration related to central pipeline management and it probably need some pre-configuration to be able generate the api key.

about

> but there error you show is for a different key...

what i did was to run the following example:

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": ["read"]
    }
  }
}

```

and the error that i provided is what i got when i ran the above command.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 25, 2025, 5:08pm UTC](https://discuss.elastic.co/t/possible-error-in-documentaion-about-creating-an-api-key-for-central-management/373355/4 "2025-01-25T17:08:35Z")

</div>

Not sure where you got that ... but this.... what you show is malformed

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": ["read"] <<<< THIS IS NOT CORRECT
    }
  }
}

```

According to the docs here

> **[Secure your connection to Elasticsearch | Logstash Reference \[8.17\] | Elastic](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-api-key-monitor)**

Note how `index` is form `name` and `privileges`

```auto
POST /_security/api_key
{
  "name": "logstash_host001", 
  "role_descriptors": {
    "logstash_monitoring": { 
      "cluster": ["monitor"],
      "index": [
        {
          "names": [".monitoring-ls-*"],
          "privileges": ["create_index", "create"]
        }
      ]
    }
  }
}

```
