# Elasticsearch aliases not visible in Kibana Dashboard-xpack by normal user

**URL:** <https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 17, 2018, 2:47pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179 "2018-12-17T14:47:44Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 17, 2018, 2:47pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/1 "2018-12-17T14:47:44Z")

</div>

Dear Team,

I have ELK version - 6.3.1 and installed xpack trial version to check rules and privileges for normal user and admin user.

So I have created an user (user1) with only one indices aliases(event\_aliases01), when i tried to login with user1 , i can able to login successfully, but the problem is , when i go Discover section and i choose the index pattern(It is an aliases) and getting below error in the top of the kibana dashboard,

original index name : events\_prabhu  
Aliases name : event\_aliases01  
Kibana Index pattern name : event\_aliases01

* * *

Discover: Failed to derive xcontent

## Error: Request to Elasticsearch failed: {"error":{"root\_cause":[{"type":"x\_content\_parse\_exception","reason":"Failed to derive xcontent"}],"type":"search\_phase\_execution\_exception","reason":"all shards failed","phase":"query","grouped":true,"failed\_shards":[{"shard":0,"index":"events\_prabhu","node":"Auqfigf2SWWqVVWjWPcjGQ","reason":{"type":"x\_content\_parse\_exception","reason":"Failed to derive xcontent"}}],"caused\_by":{"type":"x\_content\_parse\_exception","reason":"Failed to derive xcontent","caused\_by":{"type":"x\_content\_parse\_exception","reason":"Failed to derive xcontent"}}},"status":400} at [http://192.168.4.89:5601/bundles/commons.bundle.js:204:84412](http://192.168.4.89:5601/bundles/commons.bundle.js:204:84412) at Function.Promise.try ([http://192.168.4.89:5601/bundles/commons.bundle.js:3:897645](http://192.168.4.89:5601/bundles/commons.bundle.js:3:897645)) at [http://192.168.4.89:5601/bundles/commons.bundle.js:3:897016](http://192.168.4.89:5601/bundles/commons.bundle.js:3:897016) at Array.map () at Function.Promise.map ([http://192.168.4.89:5601/bundles/commons.bundle.js:3:896974](http://192.168.4.89:5601/bundles/commons.bundle.js:3:896974)) at callResponseHandlers ([http://192.168.4.89:5601/bundles/commons.bundle.js:204:83771](http://192.168.4.89:5601/bundles/commons.bundle.js:204:83771)) at [http://192.168.4.89:5601/bundles/commons.bundle.js:204:69749](http://192.168.4.89:5601/bundles/commons.bundle.js:204:69749) at processQueue ([http://192.168.4.89:5601/bundles/vendors.bundle.js:211:199684](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:199684)) at [http://192.168.4.89:5601/bundles/vendors.bundle.js:211:200647](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:200647) at Scope.$digest ([http://192.168.4.89:5601/bundles/vendors.bundle.js:211:210409](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:210409)) at [http://192.168.4.89:5601/bundles/vendors.bundle.js:211:212941](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:212941) at completeOutstandingRequest ([http://192.168.4.89:5601/bundles/vendors.bundle.js:211:64424](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:64424)) at [http://192.168.4.89:5601/bundles/vendors.bundle.js:211:67265](http://192.168.4.89:5601/bundles/vendors.bundle.js:211:67265)

So when i checked from Elasticsearch error logs i have got below messages,

* * *

[2018-12-17T20:07:05,313][DEBUG][o.e.a.s.TransportSearchAction] [Auqfigf] [events\_prabhu][1], node[Auqfigf2SWWqVVWjWPcjGQ], [P], s[STARTED], a[id=usM6SkFYSbCPeDLZpXh\_qA]: Failed to execute [SearchRequest{searchType=QUERY\_THEN\_FETCH, indices=[event\_aliases01], indicesOptions=IndicesOptions[ignore\_unavailable=true, allow\_no\_indices=true, expand\_wildcards\_open=true, expand\_wildcards\_closed=false, allow\_aliases\_to\_multiple\_indices=true, forbid\_closed\_indices=true, ignore\_aliases=false], types=, routing='null', preference='1545057408841', requestCache=false, scroll=null, maxConcurrentShardRequests=5, batchedReduceSize=512, preFilterShardSize=64, allowPartialSearchResults=true, source={"size":500,"query":{"bool":{"must":[{"match\_all":{"boost":1.0}},{"range":{"@timestamp":{"from":1545056525241,"to":1545057425241,"include\_lower":true,"include\_upper":true,"format":"epoch\_millis","boost":1.0}}}],"adjust\_pure\_negative":true,"boost":1.0}},"version":true,"\_source":{"includes":,"excludes":},"stored\_fields":"_","docvalue\_fields":[{"field":"@timestamp","format":"date\_time"},{"field":"enteredDate","format":"date\_time"}],"script\_fields":{},"sort":[{"@timestamp":{"order":"desc","unmapped\_type":"boolean"}}],"aggregations":{"2":{"date\_histogram":{"field":"@timestamp","time\_zone":"Asia/Kolkata","interval":"30s","offset":0,"order":{"\_key":"asc"},"keyed":false,"min\_doc\_count":1}}},"highlight":{"pre\_tags":["@kibana-highlighted-field@"],"post\_tags":["@/kibana-highlighted-field@"],"fragment\_size":2147483647,"fields":{"_":{}}}}}] lastShard [true]  
org.elasticsearch.transport.RemoteTransportException: [Auqfigf][172.17.0.1:9300][indices:data/read/search[phase/query]]  
Caused by: org.elasticsearch.common.xcontent.XContentParseException: Failed to derive xcontent  
at org.elasticsearch.common.xcontent.XContentFactory.xContent(XContentFactory.java:191) ~[elasticsearch-x-content-6.4.2.jar:6.4.2]  
at org.elasticsearch.xpack.core.security.authz.accesscontrol.SecurityIndexSearcherWrapper.evaluateTemplate(SecurityIndexSearcherWrapper.java:262) ~[?:?]  
at org.elasticsearch.xpack.core.security.authz.accesscontrol.SecurityIndexSearcherWrapper.wrap(SecurityIndexSearcherWrapper.java:135) ~[?:?]  
at org.elasticsearch.index.shard.IndexSearcherWrapper.wrap(IndexSearcherWrapper.java:76) ~[elasticsearch-6.4.2.jar:6.4.2]  
at org.elasticsearch.index.shard.IndexShard.acquireSearcher(IndexShard.java:1199) ~[elasticsearch-6.4.2.jar:6.4.2]  
at org.elasticsearch.index.shard.IndexShard.acquireSearcher(IndexShard.java:1190) ~[elasticsearch-6.4.2.jar:6.4.2]  
at org.elasticsearch.search.SearchService.createSearchContext(SearchService.java:616) ~[elasticsearch-6.4.2.jar:6.4.2

* * *

Below is my xpack user privileges details,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f03de6147e1002d6c353214f7cedcc29ddc55d2.png)

Could you please help me to fix this issue.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 17, 2018, 9:52pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/2 "2018-12-17T21:52:55Z")

</div>

Please don't post images of text as they are hard to read, may not display  
correctly for everyone, and not searchable. Also, please don't post unformatted logs as these are very hard to read.

Instead paste the text and format it with \</\> icon, and check the preview window to make sure it's properly formatted before posting it. Also try and describe your issue clearly with words or using example API calls, in your case the output of `GET /_xpack/security/role/Test-Role2-aliases`

This makes it more likely that your question will receive a useful answer.

It would be great if you could update your post to solve this.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 17, 2018, 11:10pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/3 "2018-12-17T23:10:24Z")

</div>

Your "Granted Documents Query" needs to be an actual Elasticsearch Query in JSON format.

"`events`" is meaningless there.

---

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 18, 2018, 6:06pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/4 "2018-12-18T18:06:24Z")

</div>

Thanks Tim, After removed document type its worked.I have one query,

can we restrict index patterns to particular users, right now all users can see all the index pattern.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [December 19, 2018, 7:41am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/5 "2018-12-19T07:41:23Z")

</div>

Hi @praboosingh,

How many different patterns are you thinking about? You can create a separate role that gives the necessary privileges for each of the index patterns and assign this role to the users that need to access that data. Does this look like something that satisfies your use case?

---

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 19, 2018, 10:29am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/6 "2018-12-19T10:29:35Z")

</div>

I have 4 index patterns(pattern1,pattern2,pattern3,pattern4) and 3 users(user1,user2,user3) are there.

user1 should have access to - pattern1,pattern2  
user2 should have access to - pattern2,pattern3  
user3 should have access to - pattern3,pattern4

But here, if user1 logins to kibana, user1 can see all the 4 index pattern like wise for other users as well.

I do not see any privileges from kibana role management console to restrict for index pattern.

Can you please guide me how to restrict index patterns from kibana user/role management.

One more query, I want to restrict index size for every 25GB, if the index size reached 25GB, it has to create new index.Could you please help.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 19, 2018, 10:36am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/7 "2018-12-19T10:36:39Z")

</div>

> [@praboosingh](#):
>
> Can you please guide me how to restrict index patterns from kibana user/role management.

Create one role per index pattern and then give each user access to the appropriate set off roles.

> [@praboosingh](#):
>
> One more query, I want to restrict index size for every 25GB, if the index size reached 25GB, it has to create new index.Could you please help.

I de not believe this is possible out of the box. You may need to handle this at the application layer.

---

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 19, 2018, 11:09am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/8 "2018-12-19T11:09:38Z")

</div>

Thanks Christian, i have tried but no luck, below screenshot has the details,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adcac8477211087b173a367a2fc8542c2ce3346e.png)

test1 user has restricted to events\_nested1 index pattern, but when loggd in with test1 user we can see three index pattern are visible.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/eff9699bde575d3cdde79b5cb3200a13e6095211.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 19, 2018, 11:16am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/9 "2018-12-19T11:16:35Z")

</div>

If you are looking to restrict access to index patterns and visualisations/dashboards and not just the data in the indices, you should look at [Kibana Spaces](https://www.elastic.co/blog/introducing-kibana-spaces-for-organization-and-security) and how you can use this together with security. This will however require an upgrade to the latest version.

---

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 19, 2018, 12:15pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/10 "2018-12-19T12:15:25Z")

</div>

Thanks Christian, I will upgrade and check it.

Can you help me for how to limit shard data size for an index., do we need to put a parameter in logstash template or somewhere

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 19, 2018, 12:31pm UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/11 "2018-12-19T12:31:28Z")

</div>

I do not think you can do it through Logstash either. You may need to use a custom external process that periodically checks and takes action.

---

<div class="post-metadata">

**Author:** ![praboosingh](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@praboosingh](https://discuss.elastic.co/u/praboosingh)\
**Post date:** [December 20, 2018, 11:43am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/12 "2018-12-20T11:43:58Z")

</div>

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2019, 11:43am UTC](https://discuss.elastic.co/t/elasticsearch-aliases-not-visible-in-kibana-dashboard-xpack-by-normal-user/161179/13 "2019-01-17T11:43:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
