# Security\_exception

**URL:** <https://discuss.elastic.co/t/security-exception/74494>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 9, 2017, 12:14pm UTC](https://discuss.elastic.co/t/security-exception/74494 "2017-02-09T12:14:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sudharsan](https://avatars.discourse-cdn.com/v4/letter/s/858c86/32.png) [@sudharsan](https://discuss.elastic.co/u/sudharsan)\
**Post date:** [February 9, 2017, 12:14pm UTC](https://discuss.elastic.co/t/security-exception/74494/1 "2017-02-09T12:14:46Z")

</div>

Hello,  
I have deployed Elasticsearch and Kibana from Azure Marketplace.Elastic cluster is created with 3 data nodes,3 master nodes,1 Kibana node as per my selection during deployment. Kibana VM can be communicated with the help of its Public IP.Azure Internal load balancer selects one of the data nodes to store index, based on traffic load on it.Also 1 client node is deployed externally in same Virtual Network where the elastic cluster is.The main aim is to visualize logs of Client VM with the help of filebeat on it and with help of Elastic cluster nodes.Azure marketplace image is integrated with X-Pack of elastic that is cluster is protected with Shield. While communicating elastic cluster with REST API commands we known that we should pass Shield user name and password.

I am able to get reply from elastic server when i do normal API calls with shield user name and password like "list of indices" , "knowing cluster health" , "list of nodes",etc

I tried with username "es\_admin" which has admin rights

But when am trying to load filebeat-index-template am getting below "security\_exception" error

{  
"error" : {  
"root\_cause" : [ {  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_template/filebeat?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="shield" charset="UTF-8""  
}  
} ],  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_template/filebeat?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="shield" charset="UTF-8""  
}  
},  
"status" : 401  
}

Clarification is needed.

Thanks in advance,

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 9, 2017, 1:54pm UTC](https://discuss.elastic.co/t/security-exception/74494/2 "2017-02-09T13:54:30Z")

</div>

Try creating a role for filebeat. And assign this role to a user specific to filebeat.

There is an example for Packetbeat in the [X-Pack docs](https://www.elastic.co/guide/en/x-pack/5.2/beats.html). Just change packetbeat to filebeat.

---

<div class="post-metadata">

**Author:** ![sudharsan](https://avatars.discourse-cdn.com/v4/letter/s/858c86/32.png) [@sudharsan](https://discuss.elastic.co/u/sudharsan)\
**Post date:** [February 10, 2017, 4:52am UTC](https://discuss.elastic.co/t/security-exception/74494/3 "2017-02-10T04:52:22Z")

</div>

Thanks @andrewkroh .Let me try

---

<div class="post-metadata">

**Author:** ![sudharsan](https://avatars.discourse-cdn.com/v4/letter/s/858c86/32.png) [@sudharsan](https://discuss.elastic.co/u/sudharsan)\
**Post date:** [March 1, 2017, 2:55pm UTC](https://discuss.elastic.co/t/security-exception/74494/4 "2017-03-01T14:55:41Z")

</div>

Thanks @andrewkroh. Created filebeat role and assigned the same to the user.I able to see the logs forwarded by filebeat in Kibana UI and it helped me lot.Thanks again.

But es\_admin or elastic are superusers by [default.As](http://default.As) a superuser it should have all admin permissions to create index, load index templates ,etc and all.Then why we need to create and assign some specific role to particular superuser.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 1, 2017, 11:34pm UTC](https://discuss.elastic.co/t/security-exception/74494/5 "2017-03-01T23:34:29Z")

</div>

It's hard to tell _exactly_ what was going on with your original issue, but the problem seems to have been that you didn't provide credentials in your request.

> "reason" : "missing authentication token for REST request [/\_template/filebeat?pretty]",

This indicates that there was no username/password provided in the REST request. It's not that `es_admin` wasn't permitted to view the template, it's that you hadn't actually authenticated as `es_admin`.

---

<div class="post-metadata">

**Author:** ![sudharsan](https://avatars.discourse-cdn.com/v4/letter/s/858c86/32.png) [@sudharsan](https://discuss.elastic.co/u/sudharsan)\
**Post date:** [March 17, 2017, 7:23am UTC](https://discuss.elastic.co/t/security-exception/74494/6 "2017-03-17T07:23:41Z")

</div>

Thanks for your Reply @TimV. Even though es\_admin\elastic credentials are provided during API Calls, I got the same issue.

"missing authentication token" error is coming only while loading filebeat-index template.

Other API Calls with es\_admin:password are serving outputs without any authentication issues.

But the project is done successfully as per andrewkroh guide lines.

Thanks a lot @TimV @andrewkroh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2017, 7:23am UTC](https://discuss.elastic.co/t/security-exception/74494/7 "2017-04-14T07:23:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
