# View\_index\_metadata doesn't allow indices:admin/get (solved)

**URL:** <https://discuss.elastic.co/t/view-index-metadata-doesnt-allow-indices-admin-get-solved/169861>\
**Category:** Elasticsearch\
**Created:** [February 25, 2019, 3:13pm UTC](https://discuss.elastic.co/t/view-index-metadata-doesnt-allow-indices-admin-get-solved/169861 "2019-02-25T15:13:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![matt\_p](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@matt\_p](https://discuss.elastic.co/u/matt_p)\
**Post date:** [February 25, 2019, 3:13pm UTC](https://discuss.elastic.co/t/view-index-metadata-doesnt-allow-indices-admin-get-solved/169861/1 "2019-02-25T15:13:14Z")

</div>

How should I grant permissions for GET index ([https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-index.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-index.html)).

From the [docs](https://www.elastic.co/guide/en/elastic-stack-overview/6.6/security-privileges.html#privileges-list-indices) I expected that `view_index_metadata` should do this. I can search the index OK, but GET index gives an error. What am I doing wrong?

```auto
GET index-that-exists
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:admin/get] is unauthorized for user [_anonymous]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:admin/get] is unauthorized for user [_anonymous]"
  },
  "status" : 403
}

```

Elasticsearch 6.6.0, elasticsearch.yml:

```auto
xpack.security.authc:

  anonymous:
    roles: anon
    authz_exception: true

  realms:
    native:
      type: native
      order: 0    
    file:
      type: file
      order: 1

```

roles.yml:

```auto
anon:
  cluster:
    - monitor
  indices:
    - names: '*'
      privileges:
        - monitor
        - view_index_metadata
        - read

```

---

<div class="post-metadata">

**Author:** ![matt\_p](https://avatars.discourse-cdn.com/v4/letter/m/e47774/32.png) [@matt\_p](https://discuss.elastic.co/u/matt_p)\
**Post date:** [March 6, 2019, 1:21pm UTC](https://discuss.elastic.co/t/view-index-metadata-doesnt-allow-indices-admin-get-solved/169861/2 "2019-03-06T13:21:35Z")

</div>

I found this was because the `roles.yml` config was not mirrored on the other node of the cluster.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 1:21pm UTC](https://discuss.elastic.co/t/view-index-metadata-doesnt-allow-indices-admin-get-solved/169861/3 "2019-04-03T13:21:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
