# Creating grroup in Elasticsearch

**URL:** <https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 24, 2019, 3:37pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693 "2019-05-24T15:37:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [May 24, 2019, 3:37pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/1 "2019-05-24T15:37:12Z")

</div>

Hi  
Anybody could help me describing how to group multiple users in Elastic  
I have an xpack enabled elasticsearch,and created multiple user.  
i have group users who all belongs to one group.How could i achieve this please help me in this.

Thanks

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 24, 2019, 3:40pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/2 "2019-05-24T15:40:33Z")

</div>

Hi,

There is no notion of `Groups` in the native realm of Elasticsearch. Could you explain what you want to achieve? We might be able to help you do this in a different way.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 24, 2019, 3:41pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/3 "2019-05-24T15:41:17Z")

</div>

A group is kind of like a role, in that you assign common privileges to the role and then users to that.

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [May 24, 2019, 3:49pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/4 "2019-05-24T15:49:06Z")

</div>

Hi @warkolm and @ikakavas  
[https://www.elastic.co/guide/en/elastic-stack-overview/current/authorization.html](https://www.elastic.co/guide/en/elastic-stack-overview/current/authorization.html)

By seeing the picture in the above document i am getting confused

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 24, 2019, 4:11pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/5 "2019-05-24T16:11:49Z")

</div>

If you read through this page you can see we reference:

> Group  
> One or more groups to which a user belongs. Groups are not supported in some realms, such as native, file, or PKI realms.

The native realm has no notion of realms. The LDAP realm, the AD realm , the SAML realm do , on the other hand. These groups are defined in LDAP/AD and Elasticsearch just reads them.

Is it any clearer now?

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [May 24, 2019, 4:43pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/6 "2019-05-24T16:43:33Z")

</div>

Okay,Then could we make roles as groups by assigning different users and privileges?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 24, 2019, 4:46pm UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/7 "2019-05-24T16:46:59Z")

</div>

Yes, for all intents and purposes in simple use cases, it is safe to assume that users having the same role is the equivalent of users belonging to the same group.

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [May 27, 2019, 4:09am UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/8 "2019-05-27T04:09:02Z")

</div>

Hi @ikakavas

Thanks for the Response!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2019, 4:09am UTC](https://discuss.elastic.co/t/creating-grroup-in-elasticsearch/182693/9 "2019-06-24T04:09:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
