# Can't access Detections from a different space

**URL:** <https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118>\
**Category:** SIEM\
**Created:** [May 4, 2021, 9:34pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118 "2021-05-04T21:34:21Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 4, 2021, 9:34pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/1 "2021-05-04T21:34:21Z")

</div>

Hi,

\*Running ELK 7.11.2 Standalone

I am trying to setup a user to have access to `Security` in a separate space. I have been following all directions from the [official documentation](https://www.elastic.co/guide/en/security/7.11/detections-permissions-section.html), but the user can't access the "`Detections`" section. Every time I try to access `Detections`, it shows message "Let’s set up your detection engine" and send me to the link above.

What could I be missing here?

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 5, 2021, 3:20pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/2 "2021-05-05T15:20:01Z")

</div>

Update:

I have been playing with the different permissions. Now I am getting the following error, when trying to access `Detections` with the secondary user, from the other space:

```
Error: Forbidden
    at _callee3$ (https://172.30.99.80:5601/38015/bundles/core/core.entry.js:6:44939)
    at l (https://172.30.99.80:5601/38015/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:321:968615)
    at Generator._invoke (https://172.30.99.80:5601/38015/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:321:968368)
    at Generator.forEach.e.<computed> [as next] (https://172.30.99.80:5601/38015/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:321:968972)
    at fetch_asyncGeneratorStep (https://172.30.99.80:5601/38015/bundles/core/core.entry.js:6:39045)
    at _next (https://172.30.99.80:5601/38015/bundles/core/core.entry.js:6:39361)
```

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 5, 2021, 3:35pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/3 "2021-05-05T15:35:27Z")

</div>

All I need is help to define the right access permissions for a user, who is not an admin, to access all features, including `Detections`, under `Security`, from a secondary `Space`. Below the current permissions:

- Role has privileges `All` under `Kibana privileges` for `Security`
- I have not specified any `Cluster privileges` nor `Run As privileges`, but only index privileges

 ![role_access_permissions](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef247a083eb605b1ae90e6ee6869e931381734ed.png)

Thank you

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 5, 2021, 3:59pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/4 "2021-05-05T15:59:07Z")

</div>

Hey there @ManuelF! 👋

Thanks for all the follow-up details! Let's see what we can do to get you up and running 🙂

So for each space you want to use Detections, you'll need to visit the Security Solution app _at least once_ while logged in as a user with the privileges outlined in the [Enable Detections](https://www.elastic.co/guide/en/security/7.11/detections-permissions-section.html#enable-detections-ui) section of those docs. This is necessary as it is on behalf that user that we create the `.siem-signals` index and setup the index templates and ILM policy. Once that's done, any user with the [Access and use Detections](https://www.elastic.co/guide/en/security/7.11/detections-permissions-section.html#access-detections-ui) privileges should be able to use Detections within that space.

From your follow-up posts, looks like you managed to get past this first part, so now it's just figuring out why your secondary user still doesn't have access. Those privileges you have configured look correct for the `it-dpt` space, but that `Forbidden` you're getting makes it seem like your Kibana Feature Privileges may be off.

When you're seeing that `Forbidden` error, is it just a toast within the Security Solution app, or is it a full-page error?

Also, when you say:

> - Role has privileges `All` under `Kibana privileges` for `Security`

Can you verify that it's indeed for the `it-dpt` space?

 ![Roles_-_Elastic](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1d0e21bdedad5882d1937517d3367608cd38c6f.png)

Thanks!

Garrett

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 5, 2021, 4:18pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/5 "2021-05-05T16:18:35Z")

</div>

> [@spong](#):
>
> is it just a toast within the Security Solution app

Hi Garret and thank you for your prompt response. As you noticed, I have full access to all Security features with my full admin user, so the index the app may need, should have been created already. Now I am trying to set a secondary user to have access to the Security app, from space it-dpt.

The error I got, it's just a pop-up alert message from the right bottom.

Below you can see the Space config and the role Kibana privileges I have set for this user. Also if you could check the index privileges, I think that I have set more than required for this task. For instance, I don't want users under this role can see the Management app, which is disabled, but still showing when that user logs in. I would like to clean up a bit and leave only the minimum privileges needed.

 ![space_config](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf2ee66820e5775b277065c7f7889a6f8a1b2337.png)

 ![role_access_permissions](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fcf30fb77c23daeb5e2ded499f8c86024cbc5763.png)

Thank you

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 5, 2021, 11:41pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/6 "2021-05-05T23:41:06Z")

</div>

> The error I got, it's just a pop-up alert message from the right bottom.

What does the main Detections page display at this point? Is it still the 'need to setup your detection engine' splash screen? Are you seeing any other errors within the Security Solution app with this user/role?

> Also if you could check the index privileges, I think that I have set more than required for this task.

Yeah, you had a few extra privileges in there (`manage` & `monitor`), so you can remove those. Note though, that `maintenance` is necessary -- the docs call this out, but it appears to be missing from the screenshot (working with the docs folks on updating this :).

At this point, all your privileges look good, so time to start deducing from the errors shown. Can you please share the requests and any errors via your browser dev tools when you first land on the Detection page with this secondary user?

If you can, please share (with the preview tab selected and object expanded so we can debug the response):

- Any failed requests
- The `api/detection_engine/index` request (will show the configured signals index for that space for us to cross-ref with privileges)
- The `api/detection_engine/privileges` request

 ![Detections_-_Kibana](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c386da47c2cf267e75c89173710923814e846be3.png)

 ![Detections_-_Kibana](https://us1.discourse-cdn.com/elastic/original/3X/7/3/73e973fa48ea30af3fae1e490be6a3a68763ffc2.png)

Thanks for your cooperation here @ManuelF -- hopefully we can get this sorted out with the above information! 🙂

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 6, 2021, 2:55pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/7 "2021-05-06T14:55:43Z")

</div>

Hi Garret,

I have adjusted the `Index privileges` according to your recommendations. Please find below the screenshots and reports that you requested. I hope this can help you narrow the root cause of this issue, although I think, after reading the error messages, that for some reason, the secondary user " **sectest**", can't find the required indexes to operate `Detections`, from secondary space **it-dpt**. Please do not hesitate and ask any other feedback you may need.

Thank you

 ![elk_space_error_console](https://us1.discourse-cdn.com/elastic/original/3X/9/6/960d8383c4ab8fcdf7918ece36da7f5cab4868ff.png)

`/s/it-dpt/api/detection_engine/privileges`

```
1. {username: "sectest", has_all_requested: false,…}

  1. application: {}
  2. cluster: {monitor_ml: false, manage_ccr: false, manage_index_templates: false, monitor_watcher: false,…}

    1. all: false
    2. create_snapshot: false
    3. manage: false
    4. manage_api_key: false
    5. manage_ccr: false
    6. manage_ilm: false
    7. manage_index_templates: false
    8. manage_ingest_pipelines: false
    9. manage_ml: false
    10. manage_own_api_key: false
    11. manage_pipeline: false
    12. manage_rollup: false
    13. manage_saml: false
    14. manage_security: false
    15. manage_token: false
    16. manage_transform: false
    17. manage_watcher: false
    18. monitor: false
    19. monitor_ml: false
    20. monitor_rollup: false
    21. monitor_transform: false
    22. monitor_watcher: false
    23. read_ccr: false
    24. read_ilm: false
    25. transport_client: false

  3. has_all_requested: false
  4. has_encryption_key: true
  5. index: {,…}

    1. .siem-signals-it-dpt: {all: false, manage_ilm: false, read: true, create_index: false, read_cross_cluster: false,…}

      1. all: false
      2. create: true
      3. create_doc: true
      4. create_index: false
      5. delete: true
      6. delete_index: false
      7. index: true
      8. maintenance: true
      9. manage: false
      10. manage_follow_index: false
      11. manage_ilm: false
      12. manage_leader_index: false
      13. monitor: false
      14. read: true
      15. read_cross_cluster: false
      16. view_index_metadata: true
      17. write: true

  6. is_authenticated: true
  7. username: "sectest"
```

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 6, 2021, 8:23pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/8 "2021-05-06T20:23:46Z")

</div>

Alrighty, perfect! Thanks for the added details @ManuelF! 🙂

So from those errors we can see that the `siem-signals` and `.lists`/`.items` (for exceptions/value-lists) indices haven't been created yet for the `it-dpt` space, so there must be something afoot with the privileges on the initial user you used to try and set it up.

You had mentioned that you had full access to all Security features with your admin user before:

> As you noticed, I have full access to all Security features with my full admin user, so the index the app may need, should have been created already

Is there a chance you didn't visit the Security app _at least once_ with your admin user? Perhaps you were on the `default` space instead of `it-dpt`? Perhaps the `.siem-signals-*` ES index privileges were too specific?

* * *

Either way, next steps here are going to be to see what the responses are for those same requests when visiting with your `admin` user. It's of course easiest if your admin has the `superuser` role, but you'll really only need the privileges outlined in the first part of the [docs](https://www.elastic.co/guide/en/security/7.11/detections-permissions-section.html#enable-detections-ui) you linked to in your original post ( `cluster manage`, and `.siem-signals-* manage` being key).

My next guess here is that perhaps your admin user had `.siem-signals-default` instead of `.siem-signals-*`, and so when visiting the the `it-dept` space there weren't sufficient privileges to create the index. Though we'll know for sure by inspecting those same requests when visiting with your admin user.

We're almost there -- hopefully this takes care of it for you! 🤞

-Garrett

---

<div class="post-metadata">

**Author:** ![ManuelF](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Post date:** [May 6, 2021, 8:49pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/9 "2021-05-06T20:49:29Z")

</div>

Hi @spong ,

You are a genius!! 🥳 Solution provided worked as expected. Initially I visited the `Security` app with Superuser "`elastic`", but from `Default` space only. I never thought that I would have to go through all the different apps for each space with a Superuser, for the indexes to be created. Now I know 😉.

Thank you very much!! 😄 ✌

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [May 6, 2021, 8:55pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/10 "2021-05-06T20:55:49Z")

</div>

Awesome -- you're welcome! Glad you're up and running now!

We've [got some changes in play](https://github.com/elastic/security-docs/pull/634) to revise the docs and make them a bit clearer, so appreciate all the feedback here to help us make things better 🙂

Have fun using Elastic Security and let us know any feedback/issues -- happy to help!

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 8:56pm UTC](https://discuss.elastic.co/t/cant-access-detections-from-a-different-space/272118/11 "2021-06-03T20:56:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
