Hi Lee,
thanks for some tips...
I'll get this error: Config: Error 403 Forbidden: [security_exception] action [indices:data/write/update] is unauthorized for user [network] with the login over kibana...
curl -XGET http://elastic:changeme@localhost:9200/_xpack/security/user?pretty
{
"elastic" : {
"username" : "elastic",
"roles" : [
"superuser"
],
"full_name" : null,
"email" : null,
"metadata" : {
"_reserved" : true
},
"enabled" : true
},
"kibana" : {
"username" : "kibana",
"roles" : [
"kibana_system"
],
"full_name" : null,
"email" : null,
"metadata" : {
"_reserved" : true
},
"enabled" : true
},
"logstash_system" : {
"username" : "logstash_system",
"roles" : [
"logstash_system"
],
"full_name" : null,
"email" : null,
"metadata" : {
"_reserved" : true
},
"enabled" : true
},
"network" : {
"username" : "network",
"roles" : [
"kibana_user",
"events_admin2"
],
"full_name" : "network",
"email" : "ntwk@nt.com",
"metadata" : { },
"enabled" : true
}
}
curl -XGET http://elastic:changeme@localhost:9200/_xpack/security/role?pretty
{
"watcher_admin" : {
"cluster" : [
"manage_watcher"
],
"indices" : [
{
"names" : [
".watches",
".triggered_watches",
".watcher-history-"
],
"privileges" : [
"read"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"logstash_system" : {
"cluster" : [
"monitor",
"cluster:admin/xpack/monitoring/bulk"
],
"indices" : [ ],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"kibana_user" : {
"cluster" : [ ],
"indices" : [
{
"names" : [
".kibana"
],
"privileges" : [
"manage",
"read",
"index",
"delete"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"machine_learning_user" : {
"cluster" : [
"monitor_ml"
],
"indices" : [
{
"names" : [
".ml-anomalies*",
".ml-notifications"
],
"privileges" : [
"view_index_metadata",
"read"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"remote_monitoring_agent" : {
"cluster" : [
"manage_index_templates",
"manage_ingest_pipelines",
"monitor",
"cluster:admin/xpack/watcher/watch/get",
"cluster:admin/xpack/watcher/watch/put",
"cluster:admin/xpack/watcher/watch/delete"
],
"indices" : [
{
"names" : [
".marvel-es-",
".monitoring-"
],
"privileges" : [
"all"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"machine_learning_admin" : {
"cluster" : [
"manage_ml"
],
"indices" : [
{
"names" : [
".ml-"
],
"privileges" : [
"view_index_metadata",
"read"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"watcher_user" : {
"cluster" : [
"monitor_watcher"
],
"indices" : [
{
"names" : [
".watches",
".watcher-history-"
],
"privileges" : [
"read"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"monitoring_user" : {
"cluster" : [ ],
"indices" : [
{
"names" : [
".marvel-es-",
".monitoring-"
],
"privileges" : [
"read"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"reporting_user" : {
"cluster" : [ ],
"indices" : [
{
"names" : [
".reporting-"
],
"privileges" : [
"read",
"write"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"kibana_system" : {
"cluster" : [
"monitor",
"cluster:admin/xpack/monitoring/bulk"
],
"indices" : [
{
"names" : [
".kibana",
".reporting-"
],
"privileges" : [
"all"
]
}
],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"transport_client" : {
"cluster" : [
"transport_client"
],
"indices" : [ ],
"run_as" : [ ],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"superuser" : {
"cluster" : [
"all"
],
"indices" : [
{
"names" : [
""
],
"privileges" : [
"all"
]
}
],
"run_as" : [
""
],
"metadata" : {
"_reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"ingest_admin" : {
"cluster" : [
"manage_index_templates",
"manage_pipeline"
],
"indices" : [ ],
"run_as" : [ ],
"metadata" : {
"reserved" : true
},
"transient_metadata" : {
"enabled" : true
}
},
"events_admin2" : {
"cluster" : [ ],
"indices" : [
{
"names" : [
"logstash"
],
"privileges" : [
"read",
"view_index_metadata"
]
}
],
"run_as" : [ ],
"metadata" : { },
"transient_metadata" : {
"enabled" : true
}
}
}
Maybe an idea?
i will turn on audit-logging now, giving response later! Thank you again!