I would like to create a role that allows creating new users and manage them. But, it must not be able to change the password / manage some specific users.
Is this possible?.
The idea is 2 layers of administration:
super admin: It manages all the users (built-in, logstash, kibana, etc).
admin: It manages new users, but it shouldn't be able to modify the users created by the super admin user.
You can have a role which allows you to create / modify users but not change their passwords. However you cannot segment your users, and place limits on which users can be modified by which role.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.