# Default kibana user does not have access to elastic search indices

**URL:** <https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791>\
**Category:** Kibana\
**Created:** [November 15, 2017, 5:12pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791 "2017-11-15T17:12:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![erich](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@erich](https://discuss.elastic.co/u/erich)\
**Post date:** [November 15, 2017, 5:12pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/1 "2017-11-15T17:12:20Z")

</div>

I'm in the process of evaluating ELK with x-pack. I have logstash inserting log data into ES and I can query ES to fetch the data using the default elastic user.

Kibana is accessing ES with a user called "kibana". This user seems to be restricted and can't be updated to add new permissions/roles in ES. In addition, I can't find a way to change the ES "kibana" user (the one the Kibana app uses to access ES) to a new user. It seems that the evaluation license maybe too restrictive.

Please let me know if you have any suggestions. I'm sure I'm missing something.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2017, 5:22pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/2 "2017-11-15T17:22:40Z")

</div>

A user can be linked to multiple roles, so you can create a new role that provides access to you indices and then grant this and the kibana role to the user. This allows you to give different users access to different data sets with a small number of roles.

---

<div class="post-metadata">

**Author:** ![erich](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@erich](https://discuss.elastic.co/u/erich)\
**Post date:** [November 15, 2017, 6:01pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/3 "2017-11-15T18:01:40Z")

</div>

I created a new role and tried to add it to the kibana user that is used by the "Kibana" application, but it looks like the kibana user is "reserved" and its privileges cannot be changed. I also can't find a way to change the Kibana application to use a user other than "kibana" to access ES.

curl -XPOST 'elastic:changeme@localhost:9200/\_xpack/security/user/kibana?pretty' -H 'Content-Type: application/json' -d'

> {  
> "username" : "kibana",  
> "roles" : [  
> "kibana\_system", "erichs\_admin\_role"  
> ],  
> "full\_name" : null,  
> "email" : null,  
> "enabled" : true  
> }  
> '  
> {  
> "error" : {  
> "root\_cause" : [  
> {  
> "type" : "action\_request\_validation\_exception",  
> "reason" : "Validation Failed: 1: Username [kibana] is reserved and may not be used.;"  
> }  
> ],  
> "type" : "action\_request\_validation\_exception",  
> "reason" : "Validation Failed: 1: Username [kibana] is reserved and may not be used.;"  
> },  
> "status" : 400  
> }

Let me know if you have any suggestions.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2017, 6:18pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/4 "2017-11-15T18:18:45Z")

</div>

Ah, the `kibana_system` role should not be used here. Create a new user and assign the `kibana_user` and `erichs_admin_role` to it. That should solve the problem.

---

<div class="post-metadata">

**Author:** ![erich](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@erich](https://discuss.elastic.co/u/erich)\
**Post date:** [November 15, 2017, 6:24pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/5 "2017-11-15T18:24:53Z")

</div>

How do I change the Kibana application to use a different user? I couldn't find a way to do it. All the admin functions are locked out.

---

<div class="post-metadata">

**Author:** ![erich](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@erich](https://discuss.elastic.co/u/erich)\
**Post date:** [November 15, 2017, 6:33pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/6 "2017-11-15T18:33:18Z")

</div>

Nervermind. Now I just feel silly. I didn't realize I was logging into Kibana with the ES user. I assumed Kibana only had the default kibana user available as a login rather than mapping through to the ES user.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 15, 2017, 6:44pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/7 "2017-11-15T18:44:31Z")

</div>

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats and APM feel left out! 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2017, 6:44pm UTC](https://discuss.elastic.co/t/default-kibana-user-does-not-have-access-to-elastic-search-indices/107791/8 "2017-12-13T18:44:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
