# Business user cannot view any data in Kibana

**URL:** https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164
**Category:** Kibana
**Created:** [November 26, 2018, 11:23am UTC](https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164 "2018-11-26T11:23:01Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![cawoodm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cawoodm/32/14083_2.png) [@cawoodm](https://discuss.elastic.co/u/cawoodm)
#### Post date: [November 26, 2018, 11:23am UTC](https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164/1 "2018-11-26T11:23:01Z")

</div>

We enabled XPack Security today to see how it works and created a role "business\_user" (see below) with read access to 2 indices "logs-test" and "logs-prod". However, when users log in they are asked to create an index pattern without which they can view no data. This is a bit of a strange request for a user but when they try to create an index pattern it fails with HTTP status 403:

`{"statusCode":403,"error":"Forbidden","message":"Unable to create index-pattern, missing action:saved_objects/index-pattern/create"}`

Under dev tools they are able to `GET _search` and view documents.

What access rights are we missing here?

Why do users even need to define an index template? It seems unnecessary given we define the indices they can access in the role.

```
"business_user": {
        "cluster": [
            "manage_index_templates"
        ],
        "indices": [
            {
                "names": [
                    "logs-test",
                    "logs-prod"
                ],
                "privileges": [
                    "read",
                    "create"
                ],
                "field_security": {
                    "grant": [
                        "*"
                    ]
                }
            }
        ],
        "applications": [
            {
                "application": "kibana-.kibana",
                "privileges": [
                    "space_read"
                ],
                "resources": [
                    "space:business"
                ]
            }
        ],
        "run_as": [],
        "metadata": {},
        "transient_metadata": {
            "enabled": true
        }
    }
```

---

<div class="post-metadata">

### Author: ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)
#### Post date: [November 26, 2018, 9:26pm UTC](https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164/2 "2018-11-26T21:26:51Z")

</div>

You'll also need to give them the Kibana user role:

 ![03%20PM](https://us1.discourse-cdn.com/elastic/original/3X/6/2/624892b61ee68c7ddea234cecf434b2da9fca472.png)

---

<div class="post-metadata">

### Author: ![cawoodm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cawoodm/32/14083_2.png) [@cawoodm](https://discuss.elastic.co/u/cawoodm)
#### Post date: [November 27, 2018, 7:04am UTC](https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164/3 "2018-11-27T07:04:10Z")

</div>

Your answer is basically correct. However, adding the kibana\_user role meant they saw the Default space as well so I copied across the following access rights to the business\_user role (from kibana\_user) and it works as expected:  
Index `.kibana*`: manage, read, index, deleted

Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 25, 2018, 7:04am UTC](https://discuss.elastic.co/t/business-user-cannot-view-any-data-in-kibana/158164/4 "2018-12-25T07:04:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
