# Unable to restore an ElasticSearch snapshot with Security Error

**URL:** <https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514>\
**Category:** Search Guard\
**Created:** [May 27, 2019, 9:35pm UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514 "2019-05-27T21:35:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.guimaraes](https://avatars.discourse-cdn.com/v4/letter/v/73ab20/32.png) [@victor.guimaraes](https://forum.search-guard.com/u/victor.guimaraes)\
**Post date:** [May 27, 2019, 9:35pm UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514/1 "2019-05-27T21:35:39Z")

</div>

Hello,

I’m using ElasticSearch 6.7.2 with Search Guard and Google Cloud Storage Repository Plugin ([Google Cloud Storage repository plugin | Elasticsearch Plugins and Integrations [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs.html#repository-gcs)) using Google Cloud Storage as a repository for my Snapshots.

I can create the Snapshots without any problem. They doesn’t contains the searchguard index and I set “include\_global\_state” parameter as false.

But I cannot restore any of my snapshots. When I try, I get the error:

> {  
> “error”: {  
> “root\_cause”: [  
> {  
> “type”: “security\_exception”,  
> “reason”: “no permissions for and User [name=admin, roles=[admin], requestedTenant=null]”  
> }  
> ],  
> “type”: “security\_exception”,  
> “reason”: “no permissions for and User [name=admin, roles=[admin], requestedTenant=null]”  
> },  
> “status”: 403  
> }

As you can see, I’m using the admin user for test the request, and I keep the defaults roles.

The cluster logs:

> [2019-05-27T21:01:24,056][WARN][c.f.s.p.SnapshotRestoreEvaluator] [node\_hot\_1] cluster:admin/snapshot/restore is not allowed for a regular user

Has any Search Guard configuration I must set to work with \_restore API?

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 28, 2019, 10:19am UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514/2 "2019-05-28T10:19:35Z")

</div>

For SG6, you need to set:

```auto
searchguard.enable_snapshot_restore_privilege: true

```

in elasticsearch.yml.

> **[Snapshot and restore](https://docs.search-guard.com/6.x-25/snapshot-restore)**
>
> Control access to the snapshot and restore features of Elasticsearch by using Search Guard.

This has been changed in SG7 where “true” is now the default.

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [May 28, 2019, 10:19am UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514/3 "2019-05-28T10:19:43Z")

</div>



---

<div class="post-metadata">

**Author:** ![victor.guimaraes](https://avatars.discourse-cdn.com/v4/letter/v/73ab20/32.png) [@victor.guimaraes](https://forum.search-guard.com/u/victor.guimaraes)\
**Post date:** [May 28, 2019, 1:51pm UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514/4 "2019-05-28T13:51:01Z")

</div>

> [@jkressin](#):
>
> searchguard.enable\_snapshot\_restore\_privilege: true

Now are working fine. Thanks you.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [June 18, 2019, 1:51pm UTC](https://forum.search-guard.com/t/unable-to-restore-an-elasticsearch-snapshot-with-security-error/1514/5 "2019-06-18T13:51:02Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
