# Synthetic Monitoring currently using elastic super user in run.sh file

**URL:** <https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368>\
**Category:** Synthetics\
**Tags:** synthetics\
**Created:** [March 5, 2021, 12:23pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368 "2021-03-05T12:23:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![shahidraza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahidraza/32/102889_2.png) [@shahidraza](https://discuss.elastic.co/u/shahidraza)\
**Post date:** [March 5, 2021, 12:23pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/1 "2021-03-05T12:23:49Z")

</div>

Hi Team,

What is the minimum user permission required to run synthetic monitoring. I don't want to provide superuser privilege to users who all deploy the synthetic monitoring using docker.

sh run.sh 7.11.0   
'-E output.elasticsearch.hosts=["localhost:9200"]'   
'-E output.elasticsearch.username=elastic'   
'-E output.elasticsearch.password=changeme'

Thanks,  
Shahid

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [March 5, 2021, 1:42pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/2 "2021-03-05T13:42:38Z")

</div>

The run.sh script is only meant as an example. Sending data to ES securely from heartbeat (which synthetics is based on) is documented here: [Grant users access to secured resources | Heartbeat Reference [7.11] | Elastic](https://www.elastic.co/guide/en/beats/heartbeat/current/feature-roles.html)

---

<div class="post-metadata">

**Author:** ![shahidraza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahidraza/32/102889_2.png) [@shahidraza](https://discuss.elastic.co/u/shahidraza)\
**Post date:** [March 5, 2021, 3:02pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/3 "2021-03-05T15:02:31Z")

</div>

Thanks, @Andrew_Cholakian1 for the quick support.

I have created synthetic\_test user and provided the below role as per your provided link but still getting errors.

Cluster - monitor, manage\_ilm  
Index - manage and write on `heartbeat-*` indices  
Role - kibana\_admin, ingest\_admin

ERROR [publisher\_pipeline\_output] pipeline/output.go:154 Failed to connect to backoff(elasticsearch([https://localhost:9200](https://localhost:9200))): Connection marked as failed because the onConnect callback failed: failed to check for alias 'heartbeat-7.11.0': (status=403) {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/aliases/get] is unauthorized for user [synthetic\_test]"}],"type":"security\_exception","reason":"action [indices:admin/aliases/get] is unauthorized for user [synthetic\_test]"},"status":403}: 403 Forbidden: {"error":{"root\_cause":[{"type":"security\_exception","reason":"action [indices:admin/aliases/get] is unauthorized for user [synthetic\_test]"}],"type":"security\_exception","reason":"action [indices:admin/aliases/get] is unauthorized for user [synthetic\_test]"},"status":403}

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [March 5, 2021, 4:56pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/4 "2021-03-05T16:56:44Z")

</div>

A 403 error indicates that you haven't setup roles with correct privileges. I see you're using canned roles, but you'll need to create a custom role with rights to write to the heartbeat indices. See this page specifically: [Grant privileges and roles needed for publishing | Heartbeat Reference [7.11] | Elastic](https://www.elastic.co/guide/en/beats/heartbeat/current/privileges-to-publish-events.html)

---

<div class="post-metadata">

**Author:** ![shahidraza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahidraza/32/102889_2.png) [@shahidraza](https://discuss.elastic.co/u/shahidraza)\
**Post date:** [March 5, 2021, 6:14pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/5 "2021-03-05T18:14:53Z")

</div>

Thanks a lot @Andrew_Cholakian1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2021, 6:15pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-currently-using-elastic-super-user-in-run-sh-file/266368/6 "2021-03-29T18:15:35Z")

</div>

This topic was automatically closed 24 days after the last reply. New replies are no longer allowed.
