# About user authentication: action \[indices:data/read/search\] is unauthorized for user

**URL:** <https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506>\
**Category:** Elasticsearch\
**Created:** [September 14, 2017, 9:55am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506 "2017-09-14T09:55:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chu\_Jun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chu_jun/32/22102_2.png) [@Chu\_Jun](https://discuss.elastic.co/u/Chu_Jun)\
**Post date:** [September 14, 2017, 9:55am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506/1 "2017-09-14T09:55:07Z")

</div>

Hi,  
I used kibana -\> management -\> (security) user to created an user 'test' with role 'kibana\_user',  
but I won't able to see any index and perform GET indexname/\_search for all the index when I logged in as user test.

It gave me an error:  
{  
"error": {  
"root\_cause": [  
{  
"type": "security\_exception",  
"reason": "action [indices:data/read/search] is unauthorized for user [test]"  
}  
],  
"type": "security\_exception",  
"reason": "action [indices:data/read/search] is unauthorized for user [test]"  
},  
"status": 403  
}

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 14, 2017, 10:51am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506/2 "2017-09-14T10:51:11Z")

</div>

Granting the `kibana_user` role doesn't provide access to any underlying data.

Per the [documentation](https://www.elastic.co/guide/en/x-pack/5.5/kibana.html)

> You also need to grant Kibana users access to the indices that they will be working with in Kibana.

---

<div class="post-metadata">

**Author:** ![Chu\_Jun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chu_jun/32/22102_2.png) [@Chu\_Jun](https://discuss.elastic.co/u/Chu_Jun)\
**Post date:** [September 15, 2017, 2:05am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506/3 "2017-09-15T02:05:14Z")

</div>

Thank you. I will try it now.

---

<div class="post-metadata">

**Author:** ![Chu\_Jun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chu_jun/32/22102_2.png) [@Chu\_Jun](https://discuss.elastic.co/u/Chu_Jun)\
**Post date:** [September 15, 2017, 8:48am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506/4 "2017-09-15T08:48:15Z")

</div>

Hi VimV, may I check with you that is it a must to use SSL ( Install server certificate) for kibana in order to perform user authentication?

> BlockquoteTo prevent user passwords from being sent in the clear, you must configure Kibana to encrypt communications between the browser and the Kibana server. If are encrypting traffic to and from the nodes in your Elasticsearch cluster, you must also configure Kibana to connect to Elasticsearch via HTTPS.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2017, 8:48am UTC](https://discuss.elastic.co/t/about-user-authentication-action-indices-data-read-search-is-unauthorized-for-user/100506/5 "2017-10-13T08:48:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
