# Can't get authorization for \`index:monitor/stats\`

**URL:** <https://forum.search-guard.com/t/cant-get-authorization-for-index-monitor-stats/539>\
**Category:** Search Guard\
**Created:** [July 27, 2017, 2:35pm UTC](https://forum.search-guard.com/t/cant-get-authorization-for-index-monitor-stats/539 "2017-07-27T14:35:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcostantini](https://avatars.discourse-cdn.com/v4/letter/m/4bbf92/32.png) [@mcostantini](https://forum.search-guard.com/u/mcostantini)\
**Post date:** [July 27, 2017, 2:35pm UTC](https://forum.search-guard.com/t/cant-get-authorization-for-index-monitor-stats/539/1 "2017-07-27T14:35:39Z")

</div>

Hello,  
I’m running SG and ES 5.2.2. No matter what role I pin my user to, I cannot run many ES commands (requests) and simply see the following error:

{

“error” : {

“root\_cause” : [

{

“type” : “security\_exception”,

“reason” : “no permissions for indices:monitor/stats”

}

],

“type” : “security\_exception”,

“reason” : “no permissions for indices:monitor/stats”

},

“status” : 403

}

``

Today, this problem arose when I ran

curl ‘[http://localhost:9200/\_cat/indices?v&pretty=true](http://localhost:9200/_cat/indices?v&pretty=true)’ -u awesomeuser:awesomepass

``

This user is successfully mapped to the following role:

sg\_all\_access\_2:

cluster:

- CLUSTER\_ALL

indices:

‘\*’:

‘\*’:

- ALL

``

The ActionGroups are untouched.

To me the following proves that the user is mapped to the role correctly:  
[RolesChecked [sg\_all\_access\_2, sg\_delete, sg\_monitor, sg\_public]]

``

Please give me some insight into what could be wrong here. Maybe it’s fixed in a later version?

Please and thank you,

Marco.

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [July 27, 2017, 7:29pm UTC](https://forum.search-guard.com/t/cant-get-authorization-for-index-monitor-stats/539/2 "2017-07-27T19:29:19Z")

</div>

Pls send/post your logfiles and make sure you no more than one filtered alias defined.

> **···**
>
> On Thursday, 27 July 2017 16:35:39 UTC+2, mco…@n…com wrote:
> 
> > Hello,  
> > I’m running SG and ES 5.2.2. No matter what role I pin my user to, I cannot run many ES commands (requests) and simply see the following error:
> > 
> > {
> 
> > “error” : {
> 
> > “root\_cause” : [
> 
> > {
> 
> > “type” : “security\_exception”,
> 
> > “reason” : “no permissions for indices:monitor/stats”
> 
> > }
> 
> > ],
> 
> > “type” : “security\_exception”,
> 
> > “reason” : “no permissions for indices:monitor/stats”
> 
> > },
> 
> > “status” : 403
> 
> > }
> 
> > ``
> 
> > 
> 
> > Today, this problem arose when I ran
> 
> > 
> 
> > curl ‘[http://localhost:9200/\_cat/indices?v&pretty=true](http://localhost:9200/_cat/indices?v&pretty=true)’ -u awesomeuser:awesomepass
> 
> > ``
> 
> > 
> 
> > This user is successfully mapped to the following role:
> 
> > sg\_all\_access\_2:
> 
> > cluster:
> 
> > - CLUSTER\_ALL
> 
> > indices:
> 
> > ‘\*’:
> 
> > ‘\*’:
> 
> > - ALL
> 
> > ``
> 
> > The ActionGroups are untouched.
> 
> > 
> 
> > To me the following proves that the user is mapped to the role correctly:  
> > [RolesChecked [sg\_all\_access\_2, sg\_delete, sg\_monitor, sg\_public]]
> 
> > ``
> 
> > Please give me some insight into what could be wrong here. Maybe it’s fixed in a later version?
> 
> > 
> 
> > Please and thank you,
> 
> > Marco.

---

<div class="post-metadata">

**Author:** ![Marco\_Costantini](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@Marco\_Costantini](https://forum.search-guard.com/u/Marco_Costantini)\
**Post date:** [July 31, 2017, 9:48am UTC](https://forum.search-guard.com/t/cant-get-authorization-for-index-monitor-stats/539/3 "2017-07-31T09:48:45Z")

</div>

For some reason, I am not encountering this problem at all today. Let’s ignore this for now. Thank you for your time.

> **···**
>
> On Thursday, July 27, 2017 at 9:29:20 PM UTC+2, Search Guard wrote:
> 
> > Pls send/post your logfiles and make sure you no more than one filtered alias defined.
> 
> > On Thursday, 27 July 2017 16:35:39 UTC+2, mco…@n…com wrote:
> > 
> > > Hello,  
> > > I’m running SG and ES 5.2.2. No matter what role I pin my user to, I cannot run many ES commands (requests) and simply see the following error:
> > > 
> > > {
> 
> > > “error” : {
> 
> > > “root\_cause” : [
> 
> > > {
> 
> > > “type” : “security\_exception”,
> 
> > > “reason” : “no permissions for indices:monitor/stats”
> 
> > > }
> 
> > > ],
> 
> > > “type” : “security\_exception”,
> 
> > > “reason” : “no permissions for indices:monitor/stats”
> 
> > > },
> 
> > > “status” : 403
> 
> > > }
> 
> > > ``
> 
> > >
> 
> > > Today, this problem arose when I ran
> 
> > >
> 
> > > curl ‘[http://localhost:9200/\_cat/indices?v&pretty=true](http://localhost:9200/_cat/indices?v&pretty=true)’ -u awesomeuser:awesomepass
> 
> > > ``
> 
> > >
> 
> > > This user is successfully mapped to the following role:
> 
> > > sg\_all\_access\_2:
> 
> > > cluster:
> 
> > > - CLUSTER\_ALL
> 
> > > indices:
> 
> > > ‘\*’:
> 
> > > ‘\*’:
> 
> > > - ALL
> 
> > > ``
> 
> > > The ActionGroups are untouched.
> 
> > >
> 
> > > To me the following proves that the user is mapped to the role correctly:  
> > > [RolesChecked [sg\_all\_access\_2, sg\_delete, sg\_monitor, sg\_public]]
> 
> > > ``
> 
> > > Please give me some insight into what could be wrong here. Maybe it’s fixed in a later version?
> 
> > >
> 
> > > Please and thank you,
> 
> > > Marco.
