# All the apps of kibana are visible in kibana\_dashboard\_only\_user mode

**URL:** <https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096>\
**Category:** Kibana\
**Created:** [December 16, 2017, 5:27pm UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096 "2017-12-16T17:27:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 16, 2017, 5:27pm UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/1 "2017-12-16T17:27:16Z")

</div>

I have created a user and assigned it "kibana\_dashboard\_only\_user" role. But, when I login as this user, I am still able to view all the other apps that kibana provides like Discover, Visualise, etc. I would like to just see the dashboard app without any edit rights which is precisely what the "kibana\_dashboard\_only\_user" role should do according to the [documentation](https://www.elastic.co/guide/en/kibana/6.x/xpack-dashboard-only-mode.html) and this [blog](https://www.elastic.co/blog/kibana-dashboard-only-mode).

Need this urgently. Please help and ask for more details if required.

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [December 17, 2017, 2:56am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/2 "2017-12-17T02:56:54Z")

</div>

What is your kibana version ?  
Can you show role of user in security management?

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 17, 2017, 7:56am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/3 "2017-12-17T07:56:34Z")

</div>

Kibana Version: 6.0.1

Here in the snapshot, you can see the role of the user "visitor". Also, I am logged in as this user only and all apps of kibana are visible.

 ![elastic_discuss](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca47ab20d699661589654d48321830f082be6643.PNG)

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 19, 2017, 7:50am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/4 "2017-12-19T07:50:01Z")

</div>

Can somebody please help? Need this on an urgent basis.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 19, 2017, 9:18am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/5 "2017-12-19T09:18:33Z")

</div>

Hi Rishabh,

I can't reproduce what you are seeing with 6.0.1. Can you please run the following from the Dev Tools tab

`GET /_xpack/security/role`

`GET /_xpack/security/user/visitor`

and share the output here ?

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 19, 2017, 9:43am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/6 "2017-12-19T09:43:46Z")

</div>

On running GET /\_xpack/security/user/visitor, the output is:

{  
"visitor": {  
"username": "visitor",  
"roles": [  
"kibana\_dashboard\_only\_user"  
],  
"full\_name": "GIaaS Visitor",  
"email": "abc@xyz.com",  
"metadata": {},  
"enabled": true  
}  
}

On running GET /\_xpack/security/role, the output is:

{  
"kibana\_dashboard\_only\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".kibana\*"  
],  
"privileges": [  
"read",  
"view\_index\_metadata"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"watcher\_admin": {  
"cluster": [  
"manage\_watcher"  
],  
"indices": [  
{  
"names": [  
".watches",  
".triggered\_watches",  
".watcher-history-_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"logstash\_system": {  
"cluster": [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"kibana\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".kibana_"  
],  
"privileges": [  
"manage",  
"read",  
"index",  
"delete"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"machine\_learning\_user": {  
"cluster": [  
"monitor\_ml"  
],  
"indices": [  
{  
"names": [  
".ml-anomalies\*",  
".ml-notifications"  
],  
"privileges": [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"remote\_monitoring\_agent": {  
"cluster": [  
"manage\_index\_templates",  
"manage\_ingest\_pipelines",  
"monitor",  
"cluster:monitor/xpack/watcher/watch/get",  
"cluster:admin/xpack/watcher/watch/put",  
"cluster:admin/xpack/watcher/watch/delete"  
],  
"indices": [  
{  
"names": [  
".monitoring-_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"machine\_learning\_admin": {  
"cluster": [  
"manage\_ml"  
],  
"indices": [  
{  
"names": [  
".ml-_"  
],  
"privileges": [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"watcher\_user": {  
"cluster": [  
"monitor\_watcher"  
],  
"indices": [  
{  
"names": [  
".watches"  
],  
"privileges": [  
"read"  
]  
},  
{  
"names": [  
".watcher-history-_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"monitoring\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".monitoring-_"  
],  
"privileges": [  
"read",  
"read\_cross\_cluster"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"reporting\_user": {  
"cluster": [],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"kibana\_system": {  
"cluster": [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices": [  
{  
"names": [  
".kibana\*",  
".reporting-_"  
],  
"privileges": [  
"all"  
]  
},  
{  
"names": [  
".monitoring-_"  
],  
"privileges": [  
"read",  
"read\_cross\_cluster"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"logstash\_admin": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".logstash\*"  
],  
"privileges": [  
"create",  
"delete",  
"index",  
"manage",  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"transport\_client": {  
"cluster": [  
"transport\_client"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"superuser": {  
"cluster": [  
"all"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": [  
"_"  
],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"ingest\_admin": {  
"cluster": [  
"manage\_index\_templates",  
"manage\_pipeline"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"giaas\_dashboard\_only\_mode": {  
"cluster": [],  
"indices": [  
{  
"names": [  
"logstash\*"  
],  
"privileges": [  
"view\_index\_metadata",  
"read"  
],  
"field\_security": {  
"grant": [  
"\*"  
]  
}  
}  
],  
"run\_as": [],  
"metadata": {},  
"transient\_metadata": {  
"enabled": true  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 19, 2017, 11:56am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/7 "2017-12-19T11:56:05Z")

</div>

Please use the \</\> markdown in order to add long text so that it can be readable 🙂

The only thing I can think of is that you have created the visitor user also in the [file realm](https://www.elastic.co/guide/en/x-pack/current/file-realm.html) and you have assigned them the necessary rights via [file-based role management](https://www.elastic.co/guide/en/x-pack/current/defining-roles.html#roles-management-file)

Can you share your elasticsearch.yml file and the output of the

> $ES\_HOME/bin/x-pack/users list

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [December 19, 2017, 1:17pm UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/8 "2017-12-19T13:17:05Z")

</div>

You'll also want to check the `xpackDashboardMode:roles` Kibana Advanced Setting to make sure that it lists the `kibana_dashboard_only_user`.

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 19, 2017, 6:58pm UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/9 "2017-12-19T18:58:52Z")

</div>

> [@Brandon\_Kobel](#):
>
> You'll also want to check the `xpackDashboardMode:roles` Kibana Advanced Setting to make sure that it lists the `kibana_dashboard_only_user`.

yes it lists the `kibana_dashboard_only_user`.

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 19, 2017, 7:02pm UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/10 "2017-12-19T19:02:14Z")

</div>

> [@ikakavas](#):
>
> Please use the \</\> markdown in order to add long text so that it can be readable 🙂
> 
> The only thing I can think of is that you have created the visitor user also in the [file realm](https://www.elastic.co/guide/en/x-pack/current/file-realm.html) and you have assigned them the necessary rights via [file-based role management](https://www.elastic.co/guide/en/x-pack/current/defining-roles.html#roles-management-file)
> 
> Can you share your elasticsearch.yml file and the output of the
> 
> > $ES\_HOME/bin/x-pack/users list

Yes you were right, I had created a 'visitor' user in the file realm as well. I found an entry with the name 'visitor' in `/etc/elasticsearch/x-pack/users` file. After deleting that entry and restarting kibana and elasticsearch, it is working the way it should have been.  
Thanks for all the help, guys. 🙂

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 20, 2017, 7:31am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/11 "2017-12-20T07:31:15Z")

</div>

Good to hear that all is resolved

> [@rishabhg](#):
>
> After deleting that entry

Keep in mind you can use the `users` CLI tool of X-Pack that offers the same functionality. You could have done:  
`bin/x-pack/users userdel visitor`

---

<div class="post-metadata">

**Author:** ![rishabhg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishabhg/32/25704_2.png) [@rishabhg](https://discuss.elastic.co/u/rishabhg)\
**Post date:** [December 20, 2017, 8:29am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/12 "2017-12-20T08:29:40Z")

</div>

> [@ikakavas](#):
>
> Keep in mind you can use the `users` CLI tool of X-Pack that offers the same functionality. You could have done:  
> `bin/x-pack/users userdel visitor`

Thanks for the information. Would use that in the future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2018, 8:29am UTC](https://discuss.elastic.co/t/all-the-apps-of-kibana-are-visible-in-kibana-dashboard-only-user-mode/112096/13 "2018-01-17T08:29:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
