# User can't create index, even with create\_index and create permissions

**URL:** <https://discuss.elastic.co/t/user-cant-create-index-even-with-create-index-and-create-permissions/78159>\
**Category:** Elasticsearch\
**Created:** [March 10, 2017, 3:30pm UTC](https://discuss.elastic.co/t/user-cant-create-index-even-with-create-index-and-create-permissions/78159 "2017-03-10T15:30:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 10, 2017, 3:30pm UTC](https://discuss.elastic.co/t/user-cant-create-index-even-with-create-index-and-create-permissions/78159/1 "2017-03-10T15:30:53Z")

</div>

Hello everybody.

I had this issue before using Metricbeat. I created an user called metricbeat\_internal to write and read all the stuff related to that Beat and to make it visible on Kibana. So, I assigned two roles to it (a reader and a writer). They have the following privileges:  
writer\_role:

- monitor and manage\_index\_templates (cluster)
- write, delete, create\_index, create (index)  
reader\_role:
- read and view\_index\_metadata (index)

But, after creating the user and restarting the stack, I received the following error on Metricbeat logs:  
`2017-02-21T14:22:38-06:00 WARN Can not index event (status=403): {"type":"security_exception","reason":"action [indices:admin/create] is unauthorized for user [metricbeat_internal]"}`

I fixed it by assigning superuser roles for a while and it solved the problem, even though it isn't a proper solution at all.

Now, I'm trying the Netflow codec on Logstash, where I have a similar user with the same roles as described before, and got the same issue:  
`[2017-03-10T09:15:33,085][WARN][logstash.outputs.elasticsearch] Failed action. {:status=>403, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.03.10", :_type=>"netflow", :_routing=>nil}, 2017-03-10T15:15:06.000Z 130.164.225.20 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.03.10", "_type"=>"netflow", "_id"=>nil, "status"=>403, "error"=>{"type"=>"security_exception", "reason"=>"action [indices:admin/create] is unauthorized for user [logstash_internal]"}}}}`

How can this be solved?  
Thanks

---

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [March 10, 2017, 4:01pm UTC](https://discuss.elastic.co/t/user-cant-create-index-even-with-create-index-and-create-permissions/78159/2 "2017-03-10T16:01:07Z")

</div>

I just saw what happened. The netflow data was being sent to another index, instead of the logstash one. I had to set it on the roles and set the index pattern on Kibana to see the information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2017, 4:01pm UTC](https://discuss.elastic.co/t/user-cant-create-index-even-with-create-index-and-create-permissions/78159/3 "2017-04-07T16:01:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
