# Elastic Detections permissions issues

**URL:** <https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751>\
**Category:** Elastic Security\
**Tags:** elastic-stack-security, elastic-stack-alerting\
**Created:** [December 5, 2020, 8:04pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751 "2020-12-05T20:04:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![yarooski](https://avatars.discourse-cdn.com/v4/letter/y/ea5d25/32.png) [@yarooski](https://discuss.elastic.co/u/yarooski)\
**Post date:** [December 5, 2020, 8:04pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/1 "2020-12-05T20:04:26Z")

</div>

We are new to elastic and are working to get detections up and running. I created a role with all the required permissions according to the documentation and assigned it to my user, but when going to the detections page I still get the error message "To use the detection engine, a user with the required cluster and index privileges must first access this page. You need permissions for the signals index. For more help, contact your Elastic Stack administrator.". We also have TLS setup. What are we missing? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Kevin\_Logan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_logan/32/74427_2.png) [@Kevin\_Logan](https://discuss.elastic.co/u/Kevin_Logan)\
**Post date:** [December 8, 2020, 5:51pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/2 "2020-12-08T17:51:35Z")

</div>

Hi @yarooski - thank you for using Elastic Security!

You will need to ensure that you are logging in as a user who has all of the required permissions for the signals index. After logged in as a user with the required permissions, you need to visit the detections page to enable the engine.

Take a look at this documentation: [https://www.elastic.co/guide/en/security/current/detections-permissions-section.html](https://www.elastic.co/guide/en/security/current/detections-permissions-section.html)  
Especially, take a look at the "Enable Detections" section as it has details on the permissions you must have when you visit the detections page.

Additionally, take a look at this discussion thread which troubleshoots some similar issues. [SIEM detection engine is not getting started](https://discuss.elastic.co/t/siem-detection-engine-is-not-getting-started/248910/8)

Let me know if that helps, thanks!

- Kevin

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [December 10, 2020, 3:12pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/3 "2020-12-10T15:12:42Z")

</div>

@yarooski

Have you carried out this bit from the link Kevin\_Logan sent?  
It was the bit i missed when setting up the first time

- In the `kibana.yml` [configuration file](https://www.elastic.co/guide/en/kibana/7.10/settings.html), add the `xpack.encryptedSavedObjects.encryptionKey` setting with any alphanumeric value of at least 32 characters. For example: `xpack.encryptedSavedObjects.encryptionKey: 'fhjskloppd678ehkdfdlliverpoolfcr'`

After changing the `xpack.encryptedSavedObjects.encryptionKey` value and restarting Kibana, you must restart all detection rules.

---

<div class="post-metadata">

**Author:** ![yarooski](https://avatars.discourse-cdn.com/v4/letter/y/ea5d25/32.png) [@yarooski](https://discuss.elastic.co/u/yarooski)\
**Post date:** [January 16, 2021, 6:35pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/4 "2021-01-16T18:35:24Z")

</div>

Thanks for your guys' suggestions, after meddling with it for a few weeks we keep running into the same issue where we get a "permissions denied" to start the Kibana service after enabling TLS. I'm going to make a new post because the issue is a little different than the one initially posted. Thanks again.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 18, 2021, 4:37pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/5 "2021-01-18T16:37:00Z")

</div>

Hi @yarooski,

I think you posted your other problem here:

> [@Can't start elasticsearch service after enabling TLS for Detections/Alerts - Permission Denied](https://discuss.elastic.co/t/cant-start-elasticsearch-service-after-enabling-tls-for-detections-alerts-permission-denied/261330):
>
> After following these instructions meticulously: [How To Install Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu 20.04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-20-04) And then enabling TLS and setting up user permissions here: [Detections prerequisites and requirements](https://www.elastic.co/guide/en/security/current/detections-permissions-section.html#enable-detections-ui) We repeatedly run into a permissions issue when trying to start the elasticsearch service: ./elasticsearch-env: line 81: /etc/default/elasticsearch: Permission denied After doing an ls -l on the directory, all files are owned by the elasticsearch user created du…

And I think you also posted on reddit too, no? 😉 We try to track a lot of these problems and help people across multiple social platforms.  
[https://www.reddit.com/r/elasticsearch/comments/kyowf2/cant\_start\_elasticsearch\_service\_after\_enabling/](https://www.reddit.com/r/elasticsearch/comments/kyowf2/cant_start_elasticsearch_service_after_enabling/)

Getting TLS setup is the first step for sure and there are hiccups with how operating systems work with security that are inherently tricky. Once you sleuth out and get TLS setup again, if you run into problems with the instructions on how to get detection engine setup there is a more in-depth trouble shooting guide here that might help you out with any gotcha's fwiw:

> [@Detections will not setup](https://discuss.elastic.co/t/detections-will-not-setup/227297/3):
>
> Hello Frank, thank you for your feedback. This is a really helpful to check / debug the permissions. You are right, i have a elastic on prem setup as a cluster. Its for my company. I have check what you tell me, but the permissions looks good.But i notice the encryption key part. I have one in my config, but i check it again. Thank you very much!

---

<div class="post-metadata">

**Author:** ![yarooski](https://avatars.discourse-cdn.com/v4/letter/y/ea5d25/32.png) [@yarooski](https://discuss.elastic.co/u/yarooski)\
**Post date:** [January 18, 2021, 6:44pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/6 "2021-01-18T18:44:55Z")

</div>

Thanks for the reply Frank, yes that's all me haha. I made a new post here because the initial issue on this post was not even being able to get to the detections page-- we ARE able to get to the detections page after setting up the role and enabling security but after setting up TLS we run into that permissions issue.

We'll go ahead and run through setting up TLS again and see if we run into the same issue. Quick side question here: We are currently on the open-source (free) license and the goal of this project was to use ELK as a SIEM and send alerts to a Slack connector. Is this possible with the free license? When I go to edit detection rule settings and try to add an Action, it says all the actions require a gold license. Is this also going to be the case once we get TLS working and go to Stack Management \> Alerts and create alerts there..?

Thanks again for your help.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [January 18, 2021, 6:59pm UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/7 "2021-01-18T18:59:29Z")

</div>

> try to add an Action, it says all the actions require a gold license.

Check out this page for the latest info on that:

> **[Subscriptions | Elastic Stack Products & Support | Elastic](https://www.elastic.co/subscriptions)**
>
> See subscription levels, pricing, and tiered features for on-prem deployments of the Elastic Stack (Elasticsearch Kibana, Beats, and Logstash), Elastic Cloud, and Elastic Cloud Enterprise.

The builtins look like it:

 ![Screen Shot 2021-01-18 at 11.58.53 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/3/23e350a07bfcd2e70f41406a3d04e8545426be52.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:19am UTC](https://discuss.elastic.co/t/elastic-detections-permissions-issues/257751/8 "2022-11-04T08:19:07Z")

</div>


