# Sgtenant header not affected on index-pattern creation

**URL:** <https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423>\
**Category:** Search Guard\
**Created:** [April 4, 2019, 10:33am UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423 "2019-04-04T10:33:50Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexivenkov](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/alexivenkov/32/475_2.png) [@alexivenkov](https://forum.search-guard.com/u/alexivenkov)\
**Post date:** [April 4, 2019, 10:33am UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/1 "2019-04-04T10:33:51Z")

</div>

When I enable multytenancy feature on SG and kibana, tenants menu bar appear in kibana and it works as expected. But when I try to create index pattern via kibana API with `sgtenant` header, index pattern always created inside default global tenant. Where is my mistake?

Here is my configs:

part of kibana.yml

```
elasticsearch.username: "system_user"
elasticsearch.password: "kibanaserver"

elasticsearch.ssl.verificationMode: none
searchguard.accountinfo.enabled: true
searchguard.multitenancy.enabled: true
elasticsearch.requestHeadersWhitelist: ["sgtenant", "Authorization"]

```

part of sg\_config.yml

```
searchguard:
  dynamic:
    kibana:
      multitenancy_enabled: true
      server_username: 'system_user'

```

and my request: url [POST] [http://localhost:5601/api/saved\_objects/index-pattern/test](http://localhost:5601/api/saved_objects/index-pattern/test)

body

```auto
{
    "attributes" : {
        "title" : "test"
    }
}

```

headers

```
kbn-xsrf : true
sgtenant : admin_tenant
Content-Type: application/json
Authorization : Basic <key here>

```

---

<div class="post-metadata">

**Author:** ![cstaley](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/cstaley/32/463_2.png) [@cstaley](https://forum.search-guard.com/u/cstaley)\
**Post date:** [April 4, 2019, 11:54am UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/2 "2019-04-04T11:54:33Z")

</div>



---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 4, 2019, 6:48pm UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/3 "2019-04-04T18:48:55Z")

</div>

Hm … actually the configuration you posted seems ok, and also the headers you send in the API call seem to be ok. Which version of ES/SG are you using?

Maybe you have run into an issue with the naming of the HTTP header. For a quick cross-check, can you add “sg\_tenant” (with an underscore) to the whitelist:

`elasticsearch.requestHeadersWhitelist: ["sgtenant", "sg_tenant", "Authorization"]`

and try to use sg\_tenant in your call curl? This is just a guess but would help to eliminate that particular issue from the list.

---

<div class="post-metadata">

**Author:** ![alexivenkov](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/alexivenkov/32/475_2.png) [@alexivenkov](https://forum.search-guard.com/u/alexivenkov)\
**Post date:** [April 5, 2019, 9:52am UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/4 "2019-04-05T09:52:30Z")

</div>

Hello @jkressin, thank you for your reply.

Unfortunately additional header doesnt help.  
ES version - 6.6.0  
Kibana version - 6.6.0

 ![photo_2019-04-05_12-40-11](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/c6a1ff10cb8aa0b0289884abc08925a1eb80c8e3.jpeg)

Maybe I missed something in configs or request params?

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 5, 2019, 10:47am UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/5 "2019-04-05T10:47:06Z")

</div>

To me, the config and the request parameters look good.

Here’s a sample call from one of our integration tests:

`curl --insecure -Ss -u admin:admin -H 'Content-Type: application/json' -H "kbn-xsrf: true" -H "sg_tenant: adm_tenant" -XPOST "https://kibana.example.com:5601/api/saved_objects/index-pattern/humanresources" -d "@../resources/kibana/index-pattern.json"`

which works fine here. Can you check if your call looks the same?

If this does not help I will need to try to recreate the issue on one of our staging systems.

---

<div class="post-metadata">

**Author:** ![alexivenkov](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/alexivenkov/32/475_2.png) [@alexivenkov](https://forum.search-guard.com/u/alexivenkov)\
**Post date:** [April 5, 2019, 5:06pm UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/6 "2019-04-05T17:06:01Z")

</div>

Unfortunately your example wasnt success…

I do next follow:

1. Create new role via sg roles api [PUT] `"/roles/test"` (test is name of tole)  
params:

2. Create role mapping [PUT] `/rolesmapping/test`  
params:

```auto
"backendroles" : ["test"],

```

1. Create user [PUT] `internalusers/user`

```auto
{
  "password": "admin",
  "roles": ["role", "test"]
}

```

1. Create index pattern with params as I described in a message before (with sgtenant “my\_tenant”).

So, can you recreate issue on staging system, please?

---

<div class="post-metadata">

**Author:** ![alexivenkov](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/alexivenkov/32/475_2.png) [@alexivenkov](https://forum.search-guard.com/u/alexivenkov)\
**Post date:** [April 5, 2019, 5:17pm UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/7 "2019-04-05T17:17:44Z")

</div>

Here response from server from previous tests:  
[http://joxi.ru/52azLaPuEDKyjA](http://joxi.ru/52azLaPuEDKyjA)

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [April 7, 2019, 6:52pm UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/8 "2019-04-07T18:52:55Z")

</div>

Unfortunately I was not able to reproduce the issue. I followed the steps you provided, but the index pattern was correctly created in the tenant.

To further analyse:

Can you please provide the exact API curl call, including the returned JSON from Kibana, like:

**Call:**

```
curl --insecure -Ss -u admin:admin -H 'Content-Type: application/json' -H "kbn-xsrf: true" -H "sg_tenant: admin_tenant" -XPOST "http://kibana.example.com:5601/api/saved_objects/index-pattern/myid123" -d '
    {
        "attributes" : {
            "title" : "my_index"
        }
    }
'

```

**Response**

```
{
	"type": "index-pattern",
	"id": "myid123",
	"attributes": {
		"title": "my_index"
	},
	"migrationVersion": {
		"index-pattern": "6.5.0"
	},
	"updated_at": "2019-04-07T18:41:03.186Z",
	"version": 1
}

```

Also, you please set the loglevel on Elasticsearch to debug:

> **[Search Guard logging](https://docs.search-guard.com/latest/troubleshooting-setting-log-level)**
>
> Hot to set the Search Guard log level in a running Elasticsearch cluster for debugging.

Then, please issue the curl API call and post the log output here.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [April 28, 2019, 7:00pm UTC](https://forum.search-guard.com/t/sgtenant-header-not-affected-on-index-pattern-creation/1423/9 "2019-04-28T19:00:15Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
