# Access issues in shield

**URL:** <https://discuss.elastic.co/t/access-issues-in-shield/115182>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 11, 2018, 10:01pm UTC](https://discuss.elastic.co/t/access-issues-in-shield/115182 "2018-01-11T22:01:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 11, 2018, 10:01pm UTC](https://discuss.elastic.co/t/access-issues-in-shield/115182/1 "2018-01-11T22:01:47Z")

</div>

Hi all,

I was trying to set up access to elastic search. In my scenario, i need to set up discover and kibana dashboards read-only option to a role. From the documentation, i understood kibana\_user will be the right option. However, when I assign that to a person they cannot discover the logs in kibana but a super user can view it. Can somebody help me in solving this issue?

Note: Tried kibana\_system and kibana\_user both didnt allow to use discover option or view dashboards while dashboard\_only option and super user works well

Thanks in advance,

Cheers,  
Kanthi.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 12, 2018, 9:53am UTC](https://discuss.elastic.co/t/access-issues-in-shield/115182/2 "2018-01-12T09:53:35Z")

</div>

> [@kanthimathi](#):
>
> From the documentation, i understood kibana\_user will be the right option. However, when I assign that to a person they cannot discover the logs in kibana but a super user can view it

You've missed step 5 of this doc: [Configuring Security in Kibana | Kibana User Guide [6.1] | Elastic](https://www.elastic.co/guide/en/kibana/6.1/using-kibana-with-security.html#using-kibana-with-security).

The `kibana_user` role grants access to Kibana, but does not give access to the Elasticsearch data, you still need to create specific roles that give access to your log indices.

---

<div class="post-metadata">

**Author:** ![kanthimathi](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kanthimathi](https://discuss.elastic.co/u/kanthimathi)\
**Post date:** [January 14, 2018, 7:49pm UTC](https://discuss.elastic.co/t/access-issues-in-shield/115182/3 "2018-01-14T19:49:12Z")

</div>

Resolved 😉 Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2018, 7:49pm UTC](https://discuss.elastic.co/t/access-issues-in-shield/115182/4 "2018-02-11T19:49:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
