Hello World!
I'm trying to follow these:
- Grant privileges and roles needed for setup | Auditbeat Reference [7.17] | Elastic
- Grant privileges and roles needed for setup | Filebeat Reference [7.17] | Elastic
- Grant privileges and roles needed for setup | Metricbeat Reference [7.17] | Elastic
and yet running into following error (for all of the beats: auditbeat, filebeat and metricbeat)
Unable to bulk_create index-pattern
setup role(s):
GET /_security/role/auditbeat_setup
{
"auditbeat_setup" : {
"cluster" : [
"monitor",
"manage_ilm"
],
"indices" : [
{
"names" : [
"auditbeat-*"
],
"privileges" : [
"manage"
],
"field_security" : {
"grant" : [
"*"
],
"except" : [ ]
},
"allow_restricted_indices" : false
},
{
"names" : [
"auditbeat-*"
],
"privileges" : [
"write"
],
"field_security" : {
"grant" : [
"*"
]
},
"allow_restricted_indices" : false
}
],
"applications" : [ ],
"run_as" : [ ],
"metadata" : { },
"transient_metadata" : {
"enabled" : true
}
}
}
GET /_security/role/filebeat_setup
{
"filebeat_setup" : {
"cluster" : [
"monitor",
"manage_ilm",
"manage_ml"
],
"indices" : [
{
"names" : [
"filebeat-*"
],
"privileges" : [
"manage",
"write",
"read"
],
"field_security" : {
"grant" : [
"*"
],
"except" : [ ]
},
"allow_restricted_indices" : false
}
],
"applications" : [ ],
"run_as" : [ ],
"metadata" : { },
"transient_metadata" : {
"enabled" : true
}
}
}
GET /_security/role/metricbeat_setup
{
"metricbeat_setup" : {
"cluster" : [
"monitor",
"manage_ilm"
],
"indices" : [
{
"names" : [
"metricbeat-*"
],
"privileges" : [
"manage"
],
"field_security" : {
"grant" : [
"*"
],
"except" : [ ]
},
"allow_restricted_indices" : false
}
],
"applications" : [ ],
"run_as" : [ ],
"metadata" : { },
"transient_metadata" : {
"enabled" : true
}
}
}
user(s) w/ setup role and several others:
GET /_security/user/auditbeat
{
"auditbeat" : {
"username" : "auditbeat",
"roles" : [
"auditbeat_setup",
"kibana_admin",
"ingest_admin"
],
"full_name" : "X",
"email" : "X@X.X",
"metadata" : { },
"enabled" : true
}
}
GET /_security/user/filebeat
{
"filebeat" : {
"username" : "filebeat",
"roles" : [
"filebeat_setup",
"kibana_admin",
"ingest_admin",
"machine_learning_admin"
],
"full_name" : "X",
"email" : "X@X.X",
"metadata" : { },
"enabled" : true
}
}
GET /_security/user/metricbeat
{
"metricbeat" : {
"username" : "metricbeat",
"roles" : [
"kibana_admin",
"ingest_admin",
"metricbeat_setup"
],
"full_name" : "X",
"email" : "X@X.X",
"metadata" : { },
"enabled" : true
}
}
the actual error:
auditbeat:
root@647411e7353a:/usr/share/auditbeat# auditbeat setup -e -E setup.kibana.host=https://X.X.X:5601
...
2022-07-15T16:50:36.433Z ERROR instance/beat.go:1014 Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create index-pattern: <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create index-pattern"}
Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create index-pattern: <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create index-pattern"}
filebeat:
root@6fd37f1e7d0a:/usr/share/filebeat# filebeat setup -e -E setup.kibana.host=https://X.X.X:5601
...
2022-07-15T17:18:22.539Z ERROR instance/beat.go:1014 Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create : <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create "}
Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create : <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create "}
metricbeat:
root@2a22d73960da:/usr/share/metricbeat# metricbeat setup -e -E setup.kibana.host=https://X.X.X:5601
...
2022-07-15T17:17:37.951Z ERROR instance/beat.go:1014 Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create index-pattern: <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create index-pattern"}
Exiting: 1 error: error loading index pattern: returned 403 to import file: Unable to bulk_create index-pattern: <nil>. Response: {"statusCode":403,"error":"Forbidden","message":"Unable to bulk_create index-pattern"}
Please advise)
Thank you in advance!