# API Post role for kibana privileges - unexpected field \[kibana\]

**URL:** <https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123>\
**Category:** Kibana\
**Created:** [January 30, 2020, 7:50am UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123 "2020-01-30T07:50:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tennis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tennis/32/47746_2.png) [@Tennis](https://discuss.elastic.co/u/Tennis)\
**Post date:** [January 30, 2020, 7:50am UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123/1 "2020-01-30T07:50:57Z")

</div>

I want to create a role to control user access kibana feature (ref: [Kibana privileges | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-privileges.html))

My role in python code:

```
my_role = '{\
   "applications":[\
       {\
           "application":"kibana-.kibana",\
           "resources":["*"],\
           "privileges":["saved_object:dashboard/p1_dashboard",\
           "saved_object:dashboard/p2_dashboard"]\
       }\
   ],\
   "indices": [\
    {\
      "names": ["p1"],\
      "privileges": ["all"]\
    }\
  ],\
  "kibana": [\
    {\
      "base": [],\
      "feature": {\
        "dashboard": ["all"]\
      },\
      "spaces": ["marketing"]\
    }\
  ]\
}'

req = requests.post('http://my_node:<port>/_security/role/my_role, data = my_role , headers = headers, auth=HTTPBasicAuth('...', '...'))
print (req.content) 

```

request contents output:

> b'{"error":{"root\_cause":[{"type":"parse\_exception","reason":"failed to parse role [my\_role]. unexpected field [kibana]"}],"type":"parse\_exception","reason":"failed to parse role [my\_role]. unexpected field [kibana]"},"status":400}'

how to fix it?

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [January 30, 2020, 6:57pm UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123/2 "2020-01-30T18:57:16Z")

</div>

Hi @Tennis,

I got it to work with a few updates. I removed the 'applications' key as it gave me an error, I am not sure what that should correspond to in the API. Then the 'indices' key I moved under 'elasticsearch' key. I updated to use put instead of post, fixed the endpoint, sent the data as JSON, here is the full example below, hope that helps. Thanks.

my\_role = {  
"elasticsearch": {  
"indices": [  
{  
"names": ["p1"],  
"privileges": ["all"]  
}  
],  
},  
"kibana": [  
{  
"base": ,  
"feature": {  
"dashboard": ["all"]  
},  
"spaces": ["marketing"]  
}  
]  
}  
req = requests.put('https://my\_node:port/api/security/role/my\_role, data = json.dumps(my\_role) , headers = headers, auth=HTTPBasicAuth('...', '...'))

---

<div class="post-metadata">

**Author:** ![Tennis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tennis/32/47746_2.png) [@Tennis](https://discuss.elastic.co/u/Tennis)\
**Post date:** [January 31, 2020, 3:47am UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123/3 "2020-01-31T03:47:37Z")

</div>

Hi @LizaD

It seems that I request the wrong port with the wrong json contents originally.

for example:

```
my_role_es = '{\
   "applications":[\
       {\
           "application":"kibana-.kibana",\
           "resources":["*"],\
           "privileges":["..."]\
       }\
   ],\
   "indices": [\
    {\
      "names": ["..."],\
      "privileges": ["all"]\
    }\
  ]\
}'

```

my python code:  
`req = requests.post('http://node:9200/_security/role/my_role_es', data = my_role_es , headers = ..., auth=HTTPBasicAuth('...', '...'))`

It worked fine and seems port on 9200 (elasticsearch) can recognize the field term: "applications", "indices", "cluster", but can't "elasticsearch", "kibana".

However, if I want to add field "elasticsearch", "kibana",  
for example:

```
my_role_kibana = '{\
  "kibana": [\
    {\
      "base": [],\
      "feature": {\
        "dashboard": ["all"],\
        "discover": ["all"]\
      }\
    }\
  ]\
}'

```

My post code of python need to toward to 5601(kibana)  
`req = requests.post('http://node:5601/api/security/role/my_role_kibana', data = my_role_kibana , headers = ..., auth=HTTPBasicAuth('...', '...'))`

It will work fine!

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [January 31, 2020, 2:11pm UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123/4 "2020-01-31T14:11:03Z")

</div>

Yay @Tennis! Glad you got it to work 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2020, 2:11pm UTC](https://discuss.elastic.co/t/api-post-role-for-kibana-privileges-unexpected-field-kibana/217123/5 "2020-02-28T14:11:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
