# Unable to setup authentication using x-pack

**URL:** <https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585>\
**Category:** Elasticsearch\
**Created:** [April 17, 2017, 2:47pm UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585 "2017-04-17T14:47:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![praveen133t](https://avatars.discourse-cdn.com/v4/letter/p/43a26b/32.png) [@praveen133t](https://discuss.elastic.co/u/praveen133t)\
**Post date:** [April 17, 2017, 2:47pm UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/1 "2017-04-17T14:47:08Z")

</div>

I have setup the ELK stack and also installed `x-pack` plugin. I then created a new user. Now whenever I run the following command it gives me this response.

`curl -u adminuser:password -XGET http://localhost:9200`

`{"error":{"root_cause":[{"type":"security_exception","reason":"action [cluster:monitor/main] is unauthorized for user [adminuser]"}],"type":"security_exception","reason":"action [cluster:monitor/main] is unauthorized for user [adminuser]"},"status":403}`

and when I list the users. I see the following output

`./users list`  
`adminuser : -`

the `adminuser` is a `superuser`

Now I don't see any logs shipped through `filebeat` either. Can this be an issue? How do I fix this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 18, 2017, 7:26am UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/2 "2017-04-18T07:26:08Z")

</div>

Which roles do the adminuser have? Does any of them include cluster level privileges?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 18, 2017, 7:30am UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/3 "2017-04-18T07:30:55Z")

</div>

> [@](#):
>
> ```auto
> ./users list
> adminuser : -
> 
> ```

> [@](#):
>
> the adminuser is a superuser

If it prints `adminuser : -` then that means that `adminuser` has _no roles_ .

If adminuser was a superuser, then you would get:

```auto
bin/x-pack/users list
adminuser : superuser

```

What makes you think `adminuser` should be a _superuser_?  
What did you do to configure that?

---

<div class="post-metadata">

**Author:** ![praveen133t](https://avatars.discourse-cdn.com/v4/letter/p/43a26b/32.png) [@praveen133t](https://discuss.elastic.co/u/praveen133t)\
**Post date:** [April 18, 2017, 9:47am UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/4 "2017-04-18T09:47:54Z")

</div>

@TimV , @Christian_Dahlqvist : I did .`/users roles adminuser -r superuser` assuming that it will assign a role to the user. But looks like it didn't. Am I doing it right?

Also I have installed x-pack for `kibana` and also for `Logstash`. Do I have to create users/roles in these as well? I have already created users in `Kibana` UI (Browser).

I'm not quite understanding the setup process here. What I'm trying to do is, I need to have user/role based authentication in Kibana so that some of my team members will only get "Read-Only" like privilege.

I see that without these proper authentication process `ElasticSearch` is not accepting any logs from `LogStash`. But if I remove `x-pack` from `ES, Logstash and Kibana`, the logs are displayed in `Kibana` as usual.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [April 18, 2017, 1:38pm UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/5 "2017-04-18T13:38:27Z")

</div>

```
./users roles adminuser -r superuser

```

When running the `roles` sub-command a `-r` is a _remove_ option.  
The command you ran remove the superuser role from adminuser.

You can see the help text for by running

```
 bin/x-pack/users roles --help    

```

With respect to your other questions:

> [@](#):
>
> I have installed x-pack for kibana and also for Logstash. Do I have to create users/roles in these as well?

No, users are only created in Elasticsearch. The other products in the Elastic Stack use Elasticsearch as their user store where applicable. However, you will need to configure those products so that they can authenticate to Elasticsearch.

> [@](#):
>
> I see that without these proper authentication process Elasticsearch is not accepting any logs from LogStash

Please see: [Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/x-pack/current/logstash.html)

---

<div class="post-metadata">

**Author:** ![praveen133t](https://avatars.discourse-cdn.com/v4/letter/p/43a26b/32.png) [@praveen133t](https://discuss.elastic.co/u/praveen133t)\
**Post date:** [April 18, 2017, 10:19pm UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/6 "2017-04-18T22:19:23Z")

</div>

@TimV : Thank you that fixed the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2017, 10:25pm UTC](https://discuss.elastic.co/t/unable-to-setup-authentication-using-x-pack/82585/7 "2017-05-16T22:25:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
