# Unauthorized logstash role for bulk writes

**URL:** <https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318>\
**Category:** Logstash\
**Created:** [March 20, 2017, 10:13pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318 "2017-03-20T22:13:26Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 20, 2017, 10:13pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/1 "2017-03-20T22:13:26Z")

</div>

```auto

```

Here are my current role that is attached to the user logstash

 ![](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4cd762b3e4d4153556d2775f46a5d794fc352e7f.png)

I know create\_index and create aren't necessary but I figured I would give that at try.

I had originally followed this guide [https://www.elastic.co/guide/en/x-pack/current/logstash.html](https://www.elastic.co/guide/en/x-pack/current/logstash.html) but it makes no mention of how to handle this. I thought having the write permission would be enough.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 22, 2017, 5:34pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/2 "2017-03-22T17:34:04Z")

</div>

If you try to do that manually from cURL using the same user, does it manage to create the index?

> curl --user logstash:YourPasswordHere -XPUT 'localhost:9200/error-test?pretty' -H 'Content-Type: application/json' -d'  
> {  
> "settings" : {  
> "index" : {  
> "number\_of\_shards" : 3,  
> "number\_of\_replicas" : 2  
> }  
> }  
> }  
> '

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 22, 2017, 6:44pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/3 "2017-03-22T18:44:47Z")

</div>

> [@Marius\_Dragomir](#):
>
> curl --user logstash:YourPasswordHere -XPUT 'localhost:9200/error-test?pretty' -H 'Content-Type: application/json' -d'{ "settings" : { "index" : { "number\_of\_shards" : 3, "number\_of\_replicas" : 2 } }}'

When I run that command with my credentials and cluster url instead of localhost

```auto
{
  "acknowledged" : true,
  "shards_acknowledged" : true
}

```

If I go to Kibana dev console

```auto
GET error-test
{
  "error-test": {
    "aliases": {},
    "mappings": {},
    "settings": {
      "index": {
        "creation_date": "1490208027717",
        "number_of_shards": "3",
        "number_of_replicas": "2",
        "uuid": <someuuid>,
        "version": {
          "created": "5010299"
        },
        "provided_name": "error-test"
      }
    }
  }
}

```

I've been able to send logs that did NOT use the bulk API for a while now.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 22, 2017, 8:03pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/4 "2017-03-22T20:03:04Z")

</div>

Hmm, that's weird. If there was an issue with the permissions, it should not have been able to auth and create the index via cURL.  
Can you paste your Logstash .conf file?  
Also, it would be nice to have the auditing log event for that specific "access\_denied".  
This is how you enable auditing.  
[https://www.elastic.co/guide/en/x-pack/current/auditing.html](https://www.elastic.co/guide/en/x-pack/current/auditing.html)

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 22, 2017, 8:55pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/5 "2017-03-22T20:55:29Z")

</div>

Correct me if I'm wrong, but I'm under the impression that auditing cannot be enabled when using Elastic cloud. Whenever I add the following, I am unable to save my configurations due to the "Illegal user settings" error message.

```auto
xpack:
  security:
    audit:
      enabled: true

```

```auto
curl --user <username>:<password> https://<clusterid>.us-east-1.aws.found.io:9243/error-test/logs/_bulk?pretty=True -XPOST -d '
{"index": {}}
{"title": "Two", "tags": ["ruby", "python"] }
{"index": {}}
{"title": "Three", "tags": ["java"] }
{"index": {}}
{"title": "Four", "tags": ["ruby", "php"] }
'
{
  "took" : 23,
  "errors" : false,
  "items" : [
    {
      "index" : {
        "_index" : "error-test",
        "_type" : "logs",
        "_id" : "AVr3y1VO7ApZg6ubVQzj",
        "_version" : 1,
        "result" : "created",
        "_shards" : {
          "total" : 3,
          "successful" : 1,
          "failed" : 0
        },
        "created" : true,
        "status" : 201
      }
    },
    {
      "index" : {
        "_index" : "error-test",
        "_type" : "logs",
        "_id" : "AVr3y1VO7ApZg6ubVQzk",
        "_version" : 1,
        "result" : "created",
        "_shards" : {
          "total" : 3,
          "successful" : 1,
          "failed" : 0
        },
        "created" : true,
        "status" : 201
      }
    },
    {
      "index" : {
        "_index" : "error-test",
        "_type" : "logs",
        "_id" : "AVr3y1VO7ApZg6ubVQzl",
        "_version" : 1,
        "result" : "created",
        "_shards" : {
          "total" : 3,
          "successful" : 1,
          "failed" : 0
        },
        "created" : true,
        "status" : 201
      }
    }
  ]
}

```

I'm throughly confused. If I curl a bulk request, I seem to have no issue submitting those writes despite the issue I'm having in the OP.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 23, 2017, 1:10am UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/6 "2017-03-23T01:10:38Z")

</div>

This is quite strange. You seem to be doing everything correctly, but something isn't working right.

To help with debugging can you try the following and provide the results:

```bash
    curl --user logstash "https://<clusterid>.us-east-1.aws.found.io:9243/_xpack/security/_authenticate?pretty"

```

```bash
    curl --user elastic "https://<clusterid>.us-east-1.aws.found.io:9243/_xpack/security/role/<your-logstash-role-name>?pretty"

```

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 24, 2017, 9:11pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/7 "2017-03-24T21:11:52Z")

</div>

Running the first command:

```auto
{
  "username" : "logstash",
  "roles" : [
    "logstash_writer",
    "logstash_reader"
  ],
  "full_name" : "Internal Logstash User",
  "email" : "someemail@email.com",
  "metadata" : { },
  "enabled" : true
}

```

Running the second command

```auto
{
  "logstash_writer" : {
    "cluster" : [
      "manage_index_templates",
      "monitor"
    ],
    "indices" : [
      {
        "names" : [
          "info-*",
          "debug-*",
          "critical-*",
          "error-*",
          "warn-*"
        ],
        "privileges" : [
          "write",
          "delete",
          "create_index",
          "create"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { }
  }
}

```

Looks like what I've put in.

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 27, 2017, 8:59pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/8 "2017-03-27T20:59:17Z")

</div>

Is it perhaps possible to disable bulk from logstash?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 27, 2017, 11:19pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/9 "2017-03-27T23:19:21Z")

</div>

> [@addyk](#):
>
> Is it perhaps possible to disable bulk from logstash?

No, `write` grants `bulk` and once it's granted it isn't supposed to be possible to disable it.

I'll try and find some spare time to dig in and see if I can work out what's going on here, because you seem to be doing everything correctly.

Can you tell me the exact version of elasticsearch that you're running? If you don't know, then you can access it from the root page of your cluster (`curl --user elastic "https://<clusterid>.us-east-1.aws.found.io:9243/"`).

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [March 29, 2017, 6:34pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/10 "2017-03-29T18:34:57Z")

</div>

I am using 5.1.2 of Elasticsearch on Elastic Cloud.

---

<div class="post-metadata">

**Author:** ![addyk](https://avatars.discourse-cdn.com/v4/letter/a/c2a13f/32.png) [@addyk](https://discuss.elastic.co/u/addyk)\
**Post date:** [April 10, 2017, 8:10pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/11 "2017-04-10T20:10:15Z")

</div>

For fun I went back just now and tried running `curl --user elastic:<password> "https://<clusterid>.us-east-1.aws.found.io:9243/`  
along with `curl --user logstash:<password> "https://<clusterid>.us-east-1.aws.found.io/9243"` and have found that both commands hangs whenever I am experiencing [this issue](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-hangs-at-health-check/77040) that I had in a previous thread I posted. It seems that issue still is occurring on my end and I have not been able to get the error to consistently occur.

In addition, if I run a command like `curl -L google.com` (-L for redirecting since omitting the -L will just result in a 301) I receive html as expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2017, 8:18pm UTC](https://discuss.elastic.co/t/unauthorized-logstash-role-for-bulk-writes/79318/12 "2017-05-08T20:18:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
