# Can we use index pattern if we allow only alias in roles

**URL:** <https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 2, 2021, 9:16am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725 "2021-06-02T09:16:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kannan\_raj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kannan_raj/32/63201_2.png) [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Post date:** [June 2, 2021, 9:16am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/1 "2021-06-02T09:16:58Z")

</div>

unable to query the data by using index patterns. just assume the index name is **test-20210602-00001** and the alias is **testing**. role is

```
GET /_xpack/security/role/test?pretty
{
    "cluster": [],
    "indices": [
        {
            "names": ["testing"],
            "privileges": ["read","view_index_metadata"]
        }
    ]
}

```

able to search the document by using the **alias name**

```
curl http://hostname:9200/testing/_search?pretty

```

getting no documents when searching the doc by using **index pattern**

```
curl http://hostname:9200/test*/_search?pretty

```

is this expected behavior?

Elasticsearch version is 7.9.0 and created the role using role API.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 3, 2021, 3:45am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/2 "2021-06-03T03:45:22Z")

</div>

That is not the expected behaviour, and I can't reproduce it.

Can you provide more details?

---

<div class="post-metadata">

**Author:** ![kannan\_raj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kannan_raj/32/63201_2.png) [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Post date:** [June 3, 2021, 4:44am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/3 "2021-06-03T04:44:12Z")

</div>

@TimV you can follow the steps to reproduce

Create the ROLE

```
curl -XPUT -H 'Content-Type: application/json' -k -u user:password 
https://hostname:9200/_xpack/security/role/test 
-d'{
"cluster": [],
"indices": [
    {"names": ["testing"],
    "privileges": ["read","view_index_metadata"]
    }
 ]
}'

```

Create the user

```
curl -XPUT -H 'Content-Type: application/json' -k -u user:password 
https://hostname:9200/_xpack/security/user/user_name 
-d'{
    "password": "password",
    "roles" : ["kibana_user","test"],
}'

```

Create index with alias

```
curl -XPUT -H 'Content-Type: application/json' -k -u user:password 
https://hostname:9200/failed-000001 
-d'{
"aliases": {
    "testing":{
        "is_write_index": true 
        }
    }
}'

```

Posting the doc

```
curl -XPOST -H 'Content-Type: application/json' -k -u user:password 
https://hostname:9200/testing/_doc 
-d'{
   "name": "test"
}'

```

able to search the data with alias name

```
GET testing/_search

```

but unable to query the data with index or index pattern

```
GET failed-000001/_search
Error is 
"reason" : "action [indices:data/read/search] is unauthorized..."

```

with index pattern getting no doc

```
GET failed*/_search
{
 "took" : 0,
 "timed_out" : false,
 "_shards" : {
  "total" : 0,
  "successful" : 0,
  "skipped" : 0,
  "failed" : 0
 },
 "hits" : {
  "total" : {
  "value" : 0,
  "relation" : "eq"
},
"max_score" : 0.0,
"hits" : []
}

```

}

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 3, 2021, 7:03am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/4 "2021-06-03T07:03:43Z")

</div>

> [@kannan\_raj](#):
>
> but unable to query the data with index or index pattern

OK. That's expected behaviour (but it's not what your original post described).

If you grant access via an alias, then the user may only access the documents via that alias, they cannot access the index itself.

---

<div class="post-metadata">

**Author:** ![kannan\_raj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kannan_raj/32/63201_2.png) [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Post date:** [June 3, 2021, 7:11am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/5 "2021-06-03T07:11:27Z")

</div>

@TimV Thank you for the confirmation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 1, 2021, 7:12am UTC](https://discuss.elastic.co/t/can-we-use-index-pattern-if-we-allow-only-alias-in-roles/274725/6 "2021-07-01T07:12:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
