# Security error with beats\_system account and Filebeat with system module

**URL:** <https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 31, 2018, 7:50am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822 "2018-08-31T07:50:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![itblaked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itblaked/32/35621_2.png) [@itblaked](https://discuss.elastic.co/u/itblaked)\
**Post date:** [August 31, 2018, 7:50am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822/1 "2018-08-31T07:50:01Z")

</div>

Hey,

I'm encountering an error which indicates that the builtin beats\_system user account doesn't have enough permissions in the ES cluster to perform a particular task, though it works when I test with a superuser account. I was expecting the builtin account to have permissions to do what it needs for supported modules in default states.

I've installed FIlebeat 6.4 on CentOS7 and enabled the system module from cli 'sudo filebeat modules enable system'.

I've got x-pack configured and I've configured filebeat to use the beats\_system account and output to elasticsearch cluster operating 6.4.

I tested filebeat ingestion into elasticsearch using superuser creds and it worked fine, I also used these to execute filebeat setup as well successfully.

I've setup a keystore and added the variable I'm using for the password.

The settings I've configured in filebeat.yml are:

```
filebeat.config.modules:
  reload.enabled: true
setup.kibana:
  host: "kibana.mydomain"
output.elasticsearch:
  host: ["es1.mydomain:9200","es2.mydomain:9200"]
  protocol: "http"
  username"beats_system"
  password: "${filebeat_pwd}"
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch:

```

This is the log error I'm getting:

`2018-08-31T17:28:00.967+1000	ERROR	pipeline/output.go:91	Failed to connect: Connection marked as failed because the onConnect callback failed: Error loading pipeline for fileset system/auth: couldn't load pipeline: couldn't load json. Error: 403 Forbidden: {"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:admin/ingest/pipeline/put] is unauthorized for user [beats_system]"}],"type":"security_exception","reason":"action [cluster:admin/ingest/pipeline/put] is unauthorized for user [beats_system]"},"status":403}. Response body: {"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:admin/ingest/pipeline/put] is unauthorized for user [beats_system]"}],"type":"security_exception","reason":"action [cluster:admin/ingest/pipeline/put] is unauthorized for user [beats_system]"},"status":403}`

---

<div class="post-metadata">

**Author:** ![itblaked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itblaked/32/35621_2.png) [@itblaked](https://discuss.elastic.co/u/itblaked)\
**Post date:** [August 31, 2018, 8:06am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822/2 "2018-08-31T08:06:22Z")

</div>

I've got a fix, but am wondering if this should be part of the beats\_system role by default?

I looked through the xpack security privileges for users and found the permission needed. I've created a new account/role and given the role Monitor, Manage\_index\_templates, Manage\_ingest\_pipelines permissions. Monitor = same as beats\_system role, manage\_index\_templates to enable it to load index template for beat, manage\_ingest\_pipelines cause it clearly wanted it in order to load it's pipeline.

---

<div class="post-metadata">

**Author:** ![paltryeffort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paltryeffort/32/28717_2.png) [@paltryeffort](https://discuss.elastic.co/u/paltryeffort)\
**Post date:** [September 2, 2018, 10:22am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822/3 "2018-09-02T10:22:27Z")

</div>

The documentation states in:  
[https://www.elastic.co/guide/en/elastic-stack-overview/6.4/built-in-roles.html](https://www.elastic.co/guide/en/elastic-stack-overview/6.4/built-in-roles.html)

beats\_system  
This role does not provide access to the beats indices and is not suitable for writing beats output to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![itblaked](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/itblaked/32/35621_2.png) [@itblaked](https://discuss.elastic.co/u/itblaked)\
**Post date:** [September 3, 2018, 2:47am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822/4 "2018-09-03T02:47:48Z")

</div>

I missed that point, that's exactly the clarification I needed, thanks @paltryeffort.

Recap - builtin '\*\_system' accounts are for xpack endpoint monitoring, not for operational data handling/application functionality.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 1, 2018, 2:47am UTC](https://discuss.elastic.co/t/security-error-with-beats-system-account-and-filebeat-with-system-module/146822/5 "2018-10-01T02:47:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
