# Superuser doesn't have access to read a document?

**URL:** <https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 31, 2021, 2:51pm UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128 "2021-07-31T14:51:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [July 31, 2021, 2:51pm UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128/1 "2021-07-31T14:51:47Z")

</div>

This is my user's privileges

```auto
{
  "cluster" : [
    "all"
  ],
  "global" : [],
  "indices" : [
    {
      "names" : [
        "*"
      ],
      "privileges" : [
        "all"
      ],
      "allow_restricted_indices" : true
    }
  ],
  "applications" : [
    {
      "application" : "*",
      "privileges" : [
        "*"
      ],
      "resources" : [
        "*"
      ]
    }
  ],
  "run_as" : [
    "*"
  ]
}

```

It's a super user.

But somehow when i try to access an index for example the `metricbeat` index i get 403 Forbidden.

Error message:

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:data/read/get] is unauthorized for user [elastic] with roles [superuser], this action is granted by the index privileges [read,all]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:data/read/get] is unauthorized for user [elastic] with roles [superuser], this action is granted by the index privileges [read,all]",
    "caused_by" : {
      "type" : "illegal_state_exception",
      "reason" : "There are no external requests known to support wildcards that don't support replacing their indices"
    }
  },
  "status" : 403
}

```

Thanks in advance

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 1, 2021, 12:20pm UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128/2 "2021-08-01T12:20:35Z")

</div>

> [@panagiss](#):
>
> ```auto
> "There are no external requests known to support wildcards that don't support replacing their indices"
> 
> ```

This message has been improved in more recent versions of Elasticsearch. It typically means that you're passing a wildcard (`*`) to the get API (e.g. `GET /metricbeat-*/_doc/1`) which is not allowed.

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 2, 2021, 11:20am UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128/3 "2021-08-02T11:20:51Z")

</div>

Thanks! So i cannot specify wildcards in the URL path for indices ever, right?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 2, 2021, 1:43pm UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128/4 "2021-08-02T13:43:26Z")

</div>

Hi @panagiss

To be more precise you can not use `*` when you are doing a `GET` by document `_id`, you can't use a wildcard with when searching by `_id` you must provide the individual index (or alias)

Incorrect Syntax  
`GET /filebeat-*/_doc/1JbB83oBFS-aXHYZYwPk`

Correct Syntax  
`GET /filebeat-7.13.4-2021.07.29-000001/_doc/1JbB83oBFS-aXHYZYwPk`

Correct Syntax  
`GET /filebeat-*/_search`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2021, 1:43pm UTC](https://discuss.elastic.co/t/superuser-doesnt-have-access-to-read-a-document/280128/5 "2021-08-30T13:43:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
