Searchgurad index deleted

When asking questions, please provide the following information:

  • Search Guard and Elasticsearch version 6.1

  • Installed and used enterprise modules, if any searchguard 6.1

  • JVM version and operating system version jdk1.8.0_181 and centos 6.7

  • Search Guard configuration files

  • Elasticsearch log messages on debug level

  • Other installed Elasticsearch or Kibana plugins, if any

How to recreate it ?

can some one please answer

···

On Friday, October 19, 2018 at 3:41:39 PM UTC-5, rud wrote:

When asking questions, please provide the following information:

  • Search Guard and Elasticsearch version 6.1
  • Installed and used enterprise modules, if any searchguard 6.1
  • JVM version and operating system version jdk1.8.0_181 and centos 6.7
  • Search Guard configuration files
  • Elasticsearch log messages on debug level
  • Other installed Elasticsearch or Kibana plugins, if any

How to recreate it ?

I don’t understand. Are you saying you have deleted the Search Guard index? Did you use an admin certificate for that? I’m asking because on a SG secured cluster you can’t just delete the SG index without using an admin certificate.

But to answer your question - you simply use sgadmin to create a new one.

···

On Monday, October 22, 2018 at 6:17:01 PM UTC+2, rud wrote:

can some one please answer

On Friday, October 19, 2018 at 3:41:39 PM UTC-5, rud wrote:

When asking questions, please provide the following information:

  • Search Guard and Elasticsearch version 6.1
  • Installed and used enterprise modules, if any searchguard 6.1
  • JVM version and operating system version jdk1.8.0_181 and centos 6.7
  • Search Guard configuration files
  • Elasticsearch log messages on debug level
  • Other installed Elasticsearch or Kibana plugins, if any

How to recreate it ?

I did not use admin certificate to delete searchguard index (we do have admin certificates installed on cluster) , I have deleted searchguard index from kibana.
I wanted to recreate the searchguard index.

Thanks

···

On Oct 22, 2018, at 1:08 PM, Jochen Kressin jkressin@floragunn.com wrote:

I don’t understand. Are you saying you have deleted the Search Guard index? Did you use an admin certificate for that? I’m asking because on a SG secured cluster you can’t just delete the SG index without using an admin certificate.

But to answer your question - you simply use sgadmin to create a new one.

On Monday, October 22, 2018 at 6:17:01 PM UTC+2, rud wrote:

can some one please answer

On Friday, October 19, 2018 at 3:41:39 PM UTC-5, rud wrote:

When asking questions, please provide the following information:

  • Search Guard and Elasticsearch version 6.1
  • Installed and used enterprise modules, if any searchguard 6.1
  • JVM version and operating system version jdk1.8.0_181 and centos 6.7
  • Search Guard configuration files
  • Elasticsearch log messages on debug level
  • Other installed Elasticsearch or Kibana plugins, if any

How to recreate it ?

You received this message because you are subscribed to a topic in the Google Groups “Search Guard Community Forum” group.

To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/l3gHaBgtIWo/unsubscribe.

To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.

To post to this group, send email to search-guard@googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/7f024e91-cc14-4d0a-af8f-d14a0ea27090%40googlegroups.com.

For more options, visit https://groups.google.com/d/optout.

Hi, sorry, but I still don’t understand this: “I have deleted searchguard index from kibana”. What do you mean by it?

Background: The Search Guard index is an index on Elasticsearch which has special access checks that prevent it from being modified (CRUD) without an admin TLS certificate. It has in fact nothing to do with Kibana. It’s just the index where we store the SG configuration. So if Search Guard is installed on Elasticsearch you cannot just delete the index, at least not without an admin cert. So that’s why I don’t fully understand what you mean by " deleted searchguard index from kibana".

···

On Monday, October 22, 2018 at 8:43:34 PM UTC+2, rud wrote:

I did not use admin certificate to delete searchguard index (we do have admin certificates installed on cluster) , I have deleted searchguard index from kibana.
I wanted to recreate the searchguard index.

Thanks

On Oct 22, 2018, at 1:08 PM, Jochen Kressin jkressin@floragunn.com wrote:

I don’t understand. Are you saying you have deleted the Search Guard index? Did you use an admin certificate for that? I’m asking because on a SG secured cluster you can’t just delete the SG index without using an admin certificate.

But to answer your question - you simply use sgadmin to create a new one.

On Monday, October 22, 2018 at 6:17:01 PM UTC+2, rud wrote:

can some one please answer

On Friday, October 19, 2018 at 3:41:39 PM UTC-5, rud wrote:

When asking questions, please provide the following information:

  • Search Guard and Elasticsearch version 6.1
  • Installed and used enterprise modules, if any searchguard 6.1
  • JVM version and operating system version jdk1.8.0_181 and centos 6.7
  • Search Guard configuration files
  • Elasticsearch log messages on debug level
  • Other installed Elasticsearch or Kibana plugins, if any

How to recreate it ?

You received this message because you are subscribed to a topic in the Google Groups “Search Guard Community Forum” group.

To unsubscribe from this topic, visit https://groups.google.com/d/topic/search-guard/l3gHaBgtIWo/unsubscribe.

To unsubscribe from this group and all its topics, send an email to search-guard+unsubscribe@googlegroups.com.

To post to this group, send email to search-guard@googlegroups.com.

To view this discussion on the web visit https://groups.google.com/d/msgid/search-guard/7f024e91-cc14-4d0a-af8f-d14a0ea27090%40googlegroups.com.

For more options, visit https://groups.google.com/d/optout.