# Shield Elasticsearch & logstash cluster health monitor security exception

**URL:** <https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 29, 2016, 12:29pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802 "2016-04-29T12:29:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![helper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helper/32/9484_2.png) [@helper](https://discuss.elastic.co/u/helper)\
**Post date:** [April 29, 2016, 12:29pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/1 "2016-04-29T12:29:19Z")

</div>

Hi there,

I am trying to test the shield configuration with in elasticsearch facing an issue.

License and Shield have been installed on elasticsearch host.  
LDAP user created as "logstash"  
LDAP realm has been updated in "elasticsearch.yml"

When I tried to make a curl request on cluster health the following exception is thrown. I am wondering whether there is a problem in my role\_mapping.yml file or some thing else is causing the issue.

'[http://localhost:9200/\_cluster/health?pretty](http://localhost:9200/_cluster/health?pretty)'  
{  
"error" : {  
"root\_cause" : [ {  
"type" : "security\_exception",  
"reason" : "action [cluster:monitor/health] is unauthorized for user [logstash]"  
} ],  
"type" : "security\_exception",  
"reason" : "action [cluster:monitor/health] is unauthorized for user [logstash]"  
},  
"status" : 403

# In logstash.log

:message=\>"[403] {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:data/write/bulk] is unauthorized for user [logstash]"}]

Please could you let me know what is the issue here.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 29, 2016, 2:40pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/2 "2016-04-29T14:40:34Z")

</div>

I think your role mapping could be the issue. If you set the logging to debug for `shield.authc` you should see a log line that prints out the DNs of the groups retrieved from ldap and what roles were mapped. [https://www.elastic.co/guide/en/shield/current/troubleshooting.html#\_ldap](https://www.elastic.co/guide/en/shield/current/troubleshooting.html#_ldap)

---

<div class="post-metadata">

**Author:** ![helper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helper/32/9484_2.png) [@helper](https://discuss.elastic.co/u/helper)\
**Post date:** [April 29, 2016, 3:23pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/3 "2016-04-29T15:23:51Z")

</div>

Thanks for the reply. Please could you go through the below configure and find if any thing wrong.

**elasticsearch version : 2.2.0**  
**shield : 2.2.0**  
**logstash version : 2.2.2**

As per the response, I have updated the logging to debug but after the server restart none were logged related to DN.

It looks to me authentication to LDAP is happing, in case if i pass in my curl request for health check as wrong password. it throws the below exception otherwise no messages in the log.

shield.authc.ldap ] [node-01] authentication failed for user [logstash]: failed LDAP authentication for

The only exception in my ES.log are

**[INFO][rest.suppressed] /\_bulk Params: {}**  
**ElasticsearchSecurityException[action [indices:data/write/bulk] is unauthorized for user [logstash]]**

**Here is my setting for logger.yml** ,  
logger:  
shield.audit.logfile: DEBUG, access\_log  
shield.authc: debug

**elasticsearch.yml for ldap settings**

shield:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldap://xxxx:389"  
bind\_dn: "uid=logstash,ou=users,dc=example,dc=com"  
bind\_password: "xxxxx"  
user\_search:  
base\_dn: "dc=example,dc=com"  
attribute: cn  
group\_search:  
base\_dn: "dc=example,dc=com"  
files:  
role\_mapping: "/usr/share/elasticsearch/plugins/shield/config/role\_mapping.yml"  
unmapped\_groups\_as\_roles: false

**role\_mapping.yml, the following has been set**

logstash:

- "cn=logstash\_users\_group,ou=groups,dc=example,dc=com"
- "cn=logstash,dc=example,dc=com"

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [April 29, 2016, 4:23pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/4 "2016-04-29T16:23:22Z")

</div>

The logger settings need to go in the elasticsearch logging file; it looks like you have them in the shield logging.yml file. It may be easier to do this:

```
curl -XPUT -u admin 'localhost:9200/_cluster/settings' -d '{
    "transient" : {
        "shield.authc" : "DEBUG"
    }
}'

```

See [https://www.elastic.co/guide/en/elasticsearch/guide/current/logging.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/logging.html)

---

<div class="post-metadata">

**Author:** ![helper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helper/32/9484_2.png) [@helper](https://discuss.elastic.co/u/helper)\
**Post date:** [May 3, 2016, 1:46pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/5 "2016-05-03T13:46:28Z")

</div>

I cannot able to run the above curl request due to my esusers realm user does not have privileges. BTW just switched over esusers to run the above command. The user "esusers\_user1" is part of admin, power\_user, user, logstash roles.

Also is there any way can we specifiy manually this entry in the yml file rather via curl request? If so in which yml does that goes i.e elasticsearch.yml?

{"error":{"root\_cause":[{"type":"security\_exception","reason":"action [cluster:admin/settings/update] is unauthorized for user [esusers\_user1]"}],"type":"security\_exception","reason":"action [cluster:admin/settings/update] is unauthorized for user [esusers\_user1]"},"status":403}

===================

I did bit more investigation, It looks to me that the RPM installation and Puppet module slightly using different approach. When I start the elasticsearch instance manually from "/usr/share/elasticsearch/bin/" by setting the export ES\_JAVA\_OPTS="-Des.path.conf=/etc/elasticsearch" then I can access the cluster health commands.

I will have to find the way of using these variable in the current puppet module of 0.10.3. In the mean while if you spot any thing related. Please update me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/shield-elasticsearch-logstash-cluster-health-monitor-security-exception/48802/6 "2017-07-06T13:44:55Z")

</div>


