# “reason”: “action \[cluster:monitor/task/get\] is unauthorized for user \[X\]”

**URL:** <https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464>\
**Category:** Elasticsearch\
**Created:** [September 5, 2018, 7:30pm UTC](https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464 "2018-09-05T19:30:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 5, 2018, 7:30pm UTC](https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464/1 "2018-09-05T19:30:07Z")

</div>

I'm using Elastic Stack 6.4.0 and while trying to look up status for current task via `Dev Tools` (in Kibana) with non-superadmin user, I'm getting following error:

> “reason”: “action [cluster:monitor/task/get] is unauthorized for user ”

I did add following role to that user:

- "Indicies privileges": `.tasks*`
- "privileges": `read`

Please advise.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 6, 2018, 1:33am UTC](https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464/2 "2018-09-06T01:33:40Z")

</div>

> [@alexus](#):
>
> action [cluster:monitor/task/get]

Actions that begin with `cluster:` are always handled by cluster level privileges.  
In this case you need the `monitor` [cluster privilege](https://www.elastic.co/guide/en/elastic-stack-overview/6.4/security-privileges.html#privileges-list-cluster).

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 6, 2018, 2:15pm UTC](https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464/3 "2018-09-06T14:15:37Z")

</div>

@TimV, Ok, after adding `monitor` to role, I now get different message instead:

> action [indices:data/read/get] is unauthorized for user

Do I still need user to have `read` privilege for `.tasks*` indices?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 2:15pm UTC](https://discuss.elastic.co/t/reason-action-cluster-monitor-task-get-is-unauthorized-for-user-x/147464/4 "2018-10-04T14:15:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
