# Watcher and Shield integration issue

**URL:** <https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 30, 2017, 3:36pm UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879 "2017-08-30T15:36:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Boozehound77](https://avatars.discourse-cdn.com/v4/letter/b/c67d28/32.png) [@Boozehound77](https://discuss.elastic.co/u/Boozehound77)\
**Post date:** [August 30, 2017, 3:36pm UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/1 "2017-08-30T15:36:03Z")

</div>

Hello,  
we are running Elasticsearch 2.4.1 with Shield and trying to configure watcher.  
Plugin installation was successfull, plugin itself is running.

```
{
	"watcher_state": "started",
	"watch_count": 0,
	"execution_thread_pool": {
		"queue_size": 0,
		"max_size": 0
	},
	"manually_stopped": false
}

```

We are however not able to create any watches.  
When I try to create new one, I get security excetpion.

{  
"error": {  
"root\_cause": [  
{  
"type": "security\_exception",  
"reason": "action [indices:data/write/index] is unauthorized for user [\_\_watcher\_user]"  
}  
],  
"type": "security\_exception",  
"reason": "action [indices:data/write/index] is unauthorized for user [\_\_watcher\_user]"  
},  
"status": 403  
}

However according to the documentation [https://www.elastic.co/guide/en/watcher/current/shield-integration.html](https://www.elastic.co/guide/en/watcher/current/shield-integration.html) \_\_watcher\_user is internal user of the plugin and privileges should not be set up via Shield.  
How do I set up the privileges for the \_\_watcher\_user and make this work?  
Sorry but documentation doesn't really answers this question.  
Thanks a lot!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 31, 2017, 6:39am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/2 "2017-08-31T06:39:03Z")

</div>

can you post a full recreation, otherwise everything is just guessing. Also include the users/roles that are configured for completeness.

---

<div class="post-metadata">

**Author:** ![Boozehound77](https://avatars.discourse-cdn.com/v4/letter/b/c67d28/32.png) [@Boozehound77](https://discuss.elastic.co/u/Boozehound77)\
**Post date:** [August 31, 2017, 8:17am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/3 "2017-08-31T08:17:30Z")

</div>

Hello,  
is this sufficient?

**/\_shield/user**

{  
"marvel\_user": {  
"username": "marvel\_user",  
"roles": [  
"marvel\_user"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"kibana4\_server": {  
"username": "kibana4\_server",  
"roles": [  
"kibana4\_server"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"webapi\_webapi\_sys\_app": {  
"username": "webapi\_webapi\_sys\_app",  
"roles": [  
"webapi\_webapi\_sys\_app"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"kibana4": {  
"username": "kibana4",  
"roles": [  
"kibana4"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"webapi\_webapi\_admin": {  
"username": "webapi\_webapi\_admin",  
"roles": [  
"admin"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"cluster\_monitor": {  
"username": "cluster\_monitor",  
"roles": [  
"cluster\_monitor"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
},  
"maintenance": {  
"username": "maintenance",  
"roles": [  
"maintenance",  
"kibana4"  
],  
"full\_name": null,  
"email": null,  
"metadata": {}  
}  
}

**/\_shield/role**  
{  
"kibana4\_server\_cleanup": {  
"cluster": [  
"cluster:monitor/state",  
"indices:admin/template/put",  
"cluster:monitor/nodes/info",  
"indices:admin/template/get",  
"cluster:monitor/health"  
],  
"indices": [  
{  
"names": [  
".kibana"  
],  
"privileges": [  
"indices:admin/create",  
"indices:admin/exists",  
"indices:admin/mapping/put",  
"indices:admin/mappings/fields/get",  
"indices:admin/refresh",  
"indices:admin/validate/query",  
"indices:data/read/get",  
"indices:data/read/mget",  
"indices:data/read/search",  
"indices:data/write/delete",  
"indices:data/write/index",  
"indices:data/write/update"  
]  
},  
{  
"names": [  
"_"  
],  
"privileges": [  
"indices:data/read/count",  
"indices:data/read/exists",  
"indices:data/read/explain",  
"indices:data/read/field\_stats",  
"indices:data/read/get",  
"indices:data/read/mget",  
"indices:data/read/mpercolate",  
"indices:data/read/msearch",  
"indices:data/read/mtv",  
"indices:data/read/percolate",  
"indices:data/read/script/get",  
"indices:data/read/scroll",  
"indices:data/read/scroll/clear",  
"indices:data/read/search",  
"indices:data/read/tv",  
"indices:data/write/bulk",  
"indices:data/write/update",  
"indices:data/write/delete",  
"indices:data/write/script/put",  
"indices:data/write/script/delete"  
]  
},  
{  
"names": [  
".cleanup"  
],  
"privileges": [  
"all"  
]  
},  
{  
"names": [  
"cleanup-log_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": []  
},  
"kibana4\_server": {  
"cluster": [  
"cluster:monitor/nodes/info",  
"cluster:monitor/health"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"indices:admin/mappings/fields/get",  
"indices:admin/validate/query",  
"indices:data/read/search",  
"indices:data/read/msearch",  
"indices:data/read/field\_stats"  
]  
},  
{  
"names": [  
".kibana"  
],  
"privileges": [  
"indices:admin/create",  
"indices:admin/exists",  
"indices:admin/mapping/put",  
"indices:admin/mappings/fields/get",  
"indices:admin/refresh",  
"indices:admin/validate/query",  
"indices:data/read/get",  
"indices:data/read/mget",  
"indices:data/read/search",  
"indices:data/write/delete",  
"indices:data/write/index",  
"indices:data/write/update"  
]  
}  
],  
"run\_as": []  
},  
"kibana4": {  
"cluster": [  
"cluster:monitor/nodes/info",  
"cluster:monitor/health"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"indices:admin/mappings/fields/get",  
"indices:admin/validate/query",  
"indices:data/read/search",  
"indices:data/read/msearch",  
"indices:data/read/field\_stats",  
"indices:admin/get"  
]  
},  
{  
"names": [  
".kibana"  
],  
"privileges": [  
"indices:admin/exists",  
"indices:admin/mapping/put",  
"indices:admin/mappings/fields/get",  
"indices:admin/refresh",  
"indices:admin/validate/query",  
"indices:data/read/get",  
"indices:data/read/mget",  
"indices:data/read/search",  
"indices:data/write/delete",  
"indices:data/write/index",  
"indices:data/write/update"  
]  
}  
],  
"run\_as": []  
},  
"logstash": {  
"cluster": [  
"indices:admin/template/get",  
"indices:admin/template/put"  
],  
"indices": [  
{  
"names": [  
"logstash-_"  
],  
"privileges": [  
"indices:data/write/bulk",  
"indices:data/write/delete",  
"indices:data/write/update",  
"indices:data/read/search",  
"indices:data/read/scroll",  
"create\_index"  
]  
}  
],  
"run\_as": []  
},  
"marvel\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".marvel-es-_"  
],  
"privileges": [  
"read"  
]  
},  
{  
"names": [  
".kibana"  
],  
"privileges": [  
"indices:admin/exists",  
"indices:admin/mappings/fields/get",  
"indices:admin/validate/query",  
"indices:data/read/get",  
"indices:data/read/mget",  
"indices:data/read/search"  
]  
}  
],  
"run\_as": []  
},  
"webapi\_webapi\_sys\_app": {  
"cluster": [  
"cluster:monitor/nodes/liveness",  
"cluster:monitor",  
"cluster:monitor/health"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": []  
},  
"remote\_marvel\_agent": {  
"cluster": [  
"indices:admin/template/put",  
"indices:admin/template/get"  
],  
"indices": [  
{  
"names": [  
".marvel-es-_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": []  
},  
"power\_user": {  
"cluster": [  
"all"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": []  
},  
"user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": []  
},  
"transport\_client": {  
"cluster": [  
"cluster:monitor/nodes/liveness"  
],  
"indices": [],  
"run\_as": []  
},  
"cluster\_monitor": {  
"cluster": [  
"cluster:monitor"  
],  
"indices": [],  
"run\_as": []  
},  
}  
auto create in **elasticsearch.yml**

action.auto\_create\_index: +.marvel-_,+.kibana_,.security,.watches,.triggered\_watches,.watch\_history-\*

**Request**  
PUT /\_watcher/watch/cluster\_health\_watch  
{  
"trigger" : {  
"schedule" : { "interval" : "10s" }  
}  
}

**Response**  
{  
"error": {  
"root\_cause": [  
{  
"type": "security\_exception",  
"reason": "action [indices:data/write/index] is unauthorized for user [\_\_watcher\_user]"  
}  
],  
"type": "security\_exception",  
"reason": "action [indices:data/write/index] is unauthorized for user [\_\_watcher\_user]"  
},  
"status": 403  
}

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 31, 2017, 8:42am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/4 "2017-08-31T08:42:01Z")

</div>

Is the user you are logged into kibana with allowed to put watches (cant see which user you are logged in as, or missed it)? Also can you include the full watch just to be able to reproduce this?

---

<div class="post-metadata">

**Author:** ![Boozehound77](https://avatars.discourse-cdn.com/v4/letter/b/c67d28/32.png) [@Boozehound77](https://discuss.elastic.co/u/Boozehound77)\
**Post date:** [August 31, 2017, 9:01am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/5 "2017-08-31T09:01:52Z")

</div>

I am using external client not native sense (although tried Sense as well with same results).  
User being used for requests is admin therefore should be able to perform any action.  
I thought that there might be an issue with \_\_watcher\_user . However I am not really sure where to set up privileges for user which is part of plugin not shield.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 8, 2017, 8:49am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/6 "2017-09-08T08:49:47Z")

</div>

if you are not running in sense/console.. then can you share the **full** http request, including credentials (password omitted of course), headers, URI etc? I just want to make sure I get the whole picture

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2017, 8:49am UTC](https://discuss.elastic.co/t/watcher-and-shield-integration-issue/98879/7 "2017-10-06T08:49:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
