# Security\_exeption Xpack

**URL:** <https://discuss.elastic.co/t/security-exeption-xpack/93140>\
**Category:** Elasticsearch\
**Created:** [July 14, 2017, 8:14am UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140 "2017-07-14T08:14:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hampel](https://avatars.discourse-cdn.com/v4/letter/h/91b2a8/32.png) [@Hampel](https://discuss.elastic.co/u/Hampel)\
**Post date:** [July 14, 2017, 8:14am UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140/1 "2017-07-14T08:14:04Z")

</div>

Hey guys,

i have successfully installed an elk stack with the sec pack "x-pack". Further i created 1 user with the roles kibana\_user and events\_admin. The kibana\_user ist default and the events\_admin has: Cluster Priv: all, index Priv indices: \* Privs: all  
configured over the Kibana webinterface with elastic user.

Every time i get following error:  
Config: Error 403 Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user

Any Idea? Thanks for help!

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [July 17, 2017, 9:06pm UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140/2 "2017-07-17T21:06:39Z")

</div>

What version of Elasticsearch and Kibana are you using?

When and where do you see that error? In Kibana? When you log in? Or in a log file?

To Just use Kibana and have access to the data in an index, a user would typically only require;

1. `kibana_user`
2. a role with `read` and `view_index_metadata` privs on that particular index (and no cluster privs)

Plus optionally `reporting_user` and `monitoring_user` roles.

But the fact that you've given more privs should not be the problem.

You could turn on audit logging in your Elasticsearch cluster and that would show you what user it is getting the error and what index they are accessing.

[https://www.elastic.co/guide/en/x-pack/current/auditing.html](https://www.elastic.co/guide/en/x-pack/current/auditing.html)

You could also query Elasticsearch for your users and roles and paste it here so we could check that you really have everything set correctly.

curl -XGET [http://localhost:9200/\_xpack/security/role?pretty](http://localhost:9200/_xpack/security/role?pretty)

curl -XGET [http://localhost:9200/\_xpack/security/user?pretty](http://localhost:9200/_xpack/security/user?pretty)

Please let us know if that helps.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![Hampel](https://avatars.discourse-cdn.com/v4/letter/h/91b2a8/32.png) [@Hampel](https://discuss.elastic.co/u/Hampel)\
**Post date:** [July 18, 2017, 9:55am UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140/3 "2017-07-18T09:55:13Z")

</div>

Hi Lee,  
thanks for some tips...  
I'll get this error: **Config: Error 403 Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user [network]** with the login over kibana...

curl -XGET [http://elastic:changeme@localhost:9200/\_xpack/security/user?pretty](http://elastic:changeme@localhost:9200/_xpack/security/user?pretty)  
{  
"elastic" : {  
"username" : "elastic",  
"roles" : [  
"superuser"  
],  
"full\_name" : null,  
"email" : null,  
"metadata" : {  
"\_reserved" : true  
},  
"enabled" : true  
},  
"kibana" : {  
"username" : "kibana",  
"roles" : [  
"kibana\_system"  
],  
"full\_name" : null,  
"email" : null,  
"metadata" : {  
"\_reserved" : true  
},  
"enabled" : true  
},  
"logstash\_system" : {  
"username" : "logstash\_system",  
"roles" : [  
"logstash\_system"  
],  
"full\_name" : null,  
"email" : null,  
"metadata" : {  
"\_reserved" : true  
},  
"enabled" : true  
},  
"network" : {  
"username" : "network",  
"roles" : [  
"kibana\_user",  
"events\_admin2"  
],  
"full\_name" : "network",  
"email" : "ntwk@nt.com",  
"metadata" : { },  
"enabled" : true  
}  
}

curl -XGET [http://elastic:changeme@localhost:9200/\_xpack/security/role?pretty](http://elastic:changeme@localhost:9200/_xpack/security/role?pretty)  
{  
"watcher\_admin" : {  
"cluster" : [  
"manage\_watcher"  
],  
"indices" : [  
{  
"names" : [  
".watches",  
".triggered\_watches",  
".watcher-history-_"  
],  
"privileges" : [  
"read"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"logstash\_system" : {  
"cluster" : [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices" : [],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"kibana\_user" : {  
"cluster" : [],  
"indices" : [  
{  
"names" : [  
".kibana_"  
],  
"privileges" : [  
"manage",  
"read",  
"index",  
"delete"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"machine\_learning\_user" : {  
"cluster" : [  
"monitor\_ml"  
],  
"indices" : [  
{  
"names" : [  
".ml-anomalies\*",  
".ml-notifications"  
],  
"privileges" : [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"remote\_monitoring\_agent" : {  
"cluster" : [  
"manage\_index\_templates",  
"manage\_ingest\_pipelines",  
"monitor",  
"cluster:admin/xpack/watcher/watch/get",  
"cluster:admin/xpack/watcher/watch/put",  
"cluster:admin/xpack/watcher/watch/delete"  
],  
"indices" : [  
{  
"names" : [  
".marvel-es-_",  
".monitoring-_"  
],  
"privileges" : [  
"all"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"machine\_learning\_admin" : {  
"cluster" : [  
"manage\_ml"  
],  
"indices" : [  
{  
"names" : [  
".ml-_"  
],  
"privileges" : [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"watcher\_user" : {  
"cluster" : [  
"monitor\_watcher"  
],  
"indices" : [  
{  
"names" : [  
".watches",  
".watcher-history-_"  
],  
"privileges" : [  
"read"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"monitoring\_user" : {  
"cluster" : [],  
"indices" : [  
{  
"names" : [  
".marvel-es-_",  
".monitoring-_"  
],  
"privileges" : [  
"read"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"reporting\_user" : {  
"cluster" : [],  
"indices" : [  
{  
"names" : [  
".reporting-_"  
],  
"privileges" : [  
"read",  
"write"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"kibana\_system" : {  
"cluster" : [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices" : [  
{  
"names" : [  
".kibana_",  
".reporting-_"  
],  
"privileges" : [  
"all"  
]  
}  
],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"transport\_client" : {  
"cluster" : [  
"transport\_client"  
],  
"indices" : [],  
"run\_as" : [],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"superuser" : {  
"cluster" : [  
"all"  
],  
"indices" : [  
{  
"names" : [  
"_"  
],  
"privileges" : [  
"all"  
]  
}  
],  
"run\_as" : [  
"_"  
],  
"metadata" : {  
"\_reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"ingest\_admin" : {  
"cluster" : [  
"manage\_index\_templates",  
"manage\_pipeline"  
],  
"indices" : [],  
"run\_as" : [],  
"metadata" : {  
"reserved" : true  
},  
"transient\_metadata" : {  
"enabled" : true  
}  
},  
"events\_admin2" : {  
"cluster" : [],  
"indices" : [  
{  
"names" : [  
"logstash_"  
],  
"privileges" : [  
"read",  
"view\_index\_metadata"  
]  
}  
],  
"run\_as" : [],  
"metadata" : { },  
"transient\_metadata" : {  
"enabled" : true  
}  
}  
}

Maybe an idea?  
i will turn on audit-logging now, giving response later! Thank you again! 🙂

---

<div class="post-metadata">

**Author:** ![Hampel](https://avatars.discourse-cdn.com/v4/letter/h/91b2a8/32.png) [@Hampel](https://discuss.elastic.co/u/Hampel)\
**Post date:** [July 18, 2017, 10:28am UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140/4 "2017-07-18T10:28:51Z")

</div>

With the audit-log i found the error...

**[2017-07-18T12:18:41,333] [transport] [access\_denied] origin\_type=[rest], origin\_address=[127.0.0.1], principal=[floham], action=[indices:data/write/update], indices=[.logstash], request=[UpdateRequest]**

Thanks for all! cya

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2017, 10:28am UTC](https://discuss.elastic.co/t/security-exeption-xpack/93140/5 "2017-08-15T10:28:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
