# Beat cannot send the data to the cluster.

**URL:** <https://forum.search-guard.com/t/beat-cannot-send-the-data-to-the-cluster/1376>\
**Category:** Search Guard\
**Created:** [March 18, 2019, 9:11am UTC](https://forum.search-guard.com/t/beat-cannot-send-the-data-to-the-cluster/1376 "2019-03-18T09:11:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Worapoj\_Chokeanankun](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/worapoj_chokeanankun/32/485_2.png) [@Worapoj\_Chokeanankun](https://forum.search-guard.com/u/Worapoj_Chokeanankun)\
**Post date:** [March 18, 2019, 9:11am UTC](https://forum.search-guard.com/t/beat-cannot-send-the-data-to-the-cluster/1376/1 "2019-03-18T09:11:47Z")

</div>

Hi,

I tried to configure Beat with Elasticsearch. My cluster installed Search Guard plugin.

Here is the error message.

2019-03-18T09:10:19.204Z INFO template/load.go:130 Template already exists and will not be overwritten.

2019-03-18T09:10:19.204Z INFO instance/beat.go:894 Template successfully loaded.

2019-03-18T09:10:24.367Z INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {“monitoring”: {“metrics”: {“beat”:{“cpu”:{“system”:{“ticks”:300,“time”:{“ms”:4}},“total”:{“ticks”:1120,“time”:{“ms”:13},“value”:1120},“user”:{“ticks”:820,“time”:{“ms”:9}}},“handles”:{“limit”:{“hard”:4096,“soft”:1024},“open”:12},“info”:{“ephemeral\_id”:“ed18843f-ed37-45b2-a197-518ea9f6efa9”,“uptime”:{“ms”:1650015}},“memstats”:{“gc\_next”:18523728,“memory\_alloc”:13163256,“memory\_total”:85844408}},“filebeat”:{“harvester”:{“open\_files”:7,“running”:7}},“libbeat”:{“config”:{“module”:{“running”:0}},“output”:{“read”:{“bytes”:3223},“write”:{“bytes”:5142}},“pipeline”:{“clients”:9,“events”:{“active”:4119,“retry”:100}}},“registrar”:{“states”:{“current”:23}},“system”:{“load”:{“1”:0.02,“15”:0,“5”:0.03,“norm”:{“1”:0.0025,“15”:0,“5”:0.0038}}}}}}

2019-03-18T09:10:35.969Z ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([https://10.49.113.81:9200](https://10.49.113.81:9200))): Connection marked as failed because the onConnect callback failed: Error loading pipeline for fileset elasticsearch/audit: couldn’t load pipeline: couldn’t load json. Error: 403 Forbidden: {“error”:{“root\_cause”:[{“type”:“security\_exception”,“reason”:“no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]”}],“type”:“security\_exception”,“reason”:“no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]”},“status”:403}. Response body: {“error”:{“root\_cause”:[{“type”:“security\_exception”,“reason”:“no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]”}],“type”:“security\_exception”,“reason”:“no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]”},“status”:403}

2019-03-18T09:10:35.970Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(elasticsearch([https://10.49.113.81:9200](https://10.49.113.81:9200))) with 42 reconnect attempt(s)

2019-03-18T09:10:35.970Z INFO [publish] pipeline/retry.go:189 retryer: send unwait-signal to consumer

2019-03-18T09:10:35.970Z INFO [publish] pipeline/retry.go:191 done

2019-03-18T09:10:35.970Z INFO [publish] pipeline/retry.go:166 retryer: send wait signal to consumer

2019-03-18T09:10:35.970Z INFO [publish] pipeline/retry.go:168 done

2019-03-18T09:10:35.971Z INFO elasticsearch/client.go:721 Connected to Elasticsearch version 6.6.0

``

Why it need permission to write **cluster:admin/ingest/pipeline/put**? If it needs this permission, where should I put this grant? sg\_action\_groups or sg\_role\_mapping?

When asking questions, please provide the following information:

- Search Guard and Elasticsearch version

24.1 and 6.6.0

- Installed and used enterprise modules, if any

No

- JVM version and operating system version

1.8

- Search Guard configuration files

Attached

- Elasticsearch log messages on debug level

No, It is Beat logs.

- Other installed Elasticsearch or Kibana plugins, if any

No

[sg\_action\_groups.yml](https://forum.search-guard.com/uploads/short-url/6xqsSpzIXYQXWdM0wKfNdmoumcr.yml) (2.27 KB)

[sg\_config.yml](https://forum.search-guard.com/uploads/short-url/jrb6vftouAkecIVvBRZyUpQZMXF.yml) (9.4 KB)

[sg\_internal\_users.yml](https://forum.search-guard.com/uploads/short-url/6yQtEQUj5cOBy8Vv2uRYqaK1sxF.yml) (1.05 KB)

[sg\_roles\_mapping.yml](https://forum.search-guard.com/uploads/short-url/z7T84Z8ivptGZJjd79NltKtEBsI.yml) (548 Bytes)

[sg\_roles.yml](https://forum.search-guard.com/uploads/short-url/hJXzqDN3JJd89LCWcFpfwqSToXc.yml) (6.88 KB)

[filebeat.yml](https://forum.search-guard.com/uploads/short-url/pp2fMsZluYEi95YooXUGwOUR7lh.yml) (1.27 KB)

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [March 18, 2019, 3:34pm UTC](https://forum.search-guard.com/t/beat-cannot-send-the-data-to-the-cluster/1376/2 "2019-03-18T15:34:41Z")

</div>

in sg\_roles.yml try

sg\_logstash:  
&nbsp;&nbsp;cluster:  
&nbsp;&nbsp;&nbsp;&nbsp;- CLUSTER\_MONITOR  
&nbsp;&nbsp;&nbsp;&nbsp;- CLUSTER\_COMPOSITE\_OPS  
&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/template/get  
&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/template/put  
&nbsp;&nbsp;&nbsp;&nbsp;- cluster:admin/ingest/pipeline/put  
&nbsp;&nbsp;&nbsp;&nbsp;- cluster:admin/ingest/pipeline/get  
&nbsp;&nbsp;indices:  
&nbsp;&nbsp;&nbsp;&nbsp;'logstash-\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- CRUD  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- CREATE\_INDEX  
&nbsp;&nbsp;&nbsp;&nbsp;'\*beat\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- CRUD  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- CREATE\_INDEX

> **···**
>
> > Am 18.03.2019 um 09:55 schrieb Worapoj Chokeanankun \<worapojc@gmail.com\>:
> > 
> > Hi,
> > 
> > I tried to configure Beat with Elasticsearch. My cluster installed Search Guard plugin.
> > 
> > Here is the error message.  
> > 2019-03-18T08:43:31.023Z ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch([https://10.49.112.126:9200](https://10.49.112.126:9200))): Connection marked as failed because the onConnect callback failed: Error loading pipeline for fileset system/syslog: couldn't load pipeline: couldn't load json. Error: 403 Forbidden: {"error":{"root\_cause":[{"type":"security\_exception","reason":"no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]"}],"type":"security\_exception","reason":"no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]"},"status":403}. Response body: {"error":{"root\_cause":[{"type":"security\_exception","reason":"no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]"}],"type":"security\_exception","reason":"no permissions for [cluster:admin/ingest/pipeline/put] and User [name=logstash, roles=[logstash], requestedTenant=null]"},"status":403}
> > 
> > Why it need permission to write cluster:admin/ingest/pipeline/put? If it needs this permission, where should I put this grant? sg\_action\_groups or sg\_role\_mapping?
> > 
> > When asking questions, please provide the following information:
> > 
> > \* Search Guard and Elasticsearch version  
> > 24.1 and 6.6.0  
> > \* Installed and used enterprise modules, if any  
> > No  
> > \* JVM version and operating system version  
> > 1.8  
> > \* Search Guard configuration files  
> > Attached  
> > \* Elasticsearch log messages on debug level  
> > No, It is Beat logs.  
> > \* Other installed Elasticsearch or Kibana plugins, if any  
> > No
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/a08fb070-7545-493a-95ff-d83d470be0da%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/a08fb070-7545-493a-95ff-d83d470be0da%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).  
> > \<sg\_action\_groups.yml\>\<sg\_config.yml\>\<sg\_internal\_users.yml\>\<sg\_roles\_mapping.yml\>\<sg\_roles.yml\>\<filebeat.yml\>

---

<div class="post-metadata">

**Author:** ![Worapoj\_Chokeanankun](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/worapoj_chokeanankun/32/485_2.png) [@Worapoj\_Chokeanankun](https://forum.search-guard.com/u/Worapoj_Chokeanankun)\
**Post date:** [March 19, 2019, 4:47am UTC](https://forum.search-guard.com/t/beat-cannot-send-the-data-to-the-cluster/1376/3 "2019-03-19T04:47:13Z")

</div>

It works. Thanks
