# Es 5.2.2 X-pack index permission error

**URL:** <https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187>\
**Category:** Elasticsearch\
**Created:** [March 10, 2017, 10:51pm UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187 "2017-03-10T22:51:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cfuhriman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cfuhriman/32/23800_2.png) [@cfuhriman](https://discuss.elastic.co/u/cfuhriman)\
**Post date:** [March 10, 2017, 10:51pm UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187/1 "2017-03-10T22:51:58Z")

</div>

I am trying to create a user account who only has accesses to specific indexes when they log into Kibana, but when I log in I am getting just the navigation bar and a blank screen. The following error shows up in the browser console:

Error: [security\_exception] action [indices:data/read/search] is unauthorized for user [mo]

The role has read and write access to an index that exists in elasticsearch and has been added as a pattern in Kibana, so the expected behavior is that they would have access to view and create charts only on that index. If I add "\*" to the Index Privileges then everything works fine, but that kind of defeats the whole purpose.

Here are the specifics

Environment:  
Elasticsearch v. 5.2.2  
Kibana v. 5.2.2

Privileges  
Role: Missouri

- Index Privileges: events.logins
- Privileges: read, write

User:

- Username mo
- Roles: Missouri

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2017, 3:52am UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187/2 "2017-03-12T03:52:45Z")

</div>

Hi there,  
The issue here is that you need to add the "kibana\_user" role to the "mo" user as well (along with the "Missouri" one). That role gives the user access to read and modify the .kibana index which is needed by Kibana in order to function properly.

---

<div class="post-metadata">

**Author:** ![cfuhriman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cfuhriman/32/23800_2.png) [@cfuhriman](https://discuss.elastic.co/u/cfuhriman)\
**Post date:** [March 13, 2017, 4:47pm UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187/3 "2017-03-13T16:47:46Z")

</div>

Hello Marius,

I added the "kibana user" role, however the user gained access to other indices. For example, the mo user can now see the .kibana index. I cleared the cache and restarted the browser just to make sure that permissions weren't leaking over.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 13, 2017, 5:29pm UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187/4 "2017-03-13T17:29:08Z")

</div>

The user is supposed to have acces to that index as that is the index where Kibana stores it's settings and other objects (like saved searches, dashboards or visualizations). And yes, the permission for that index is given by the "kibana user" role.  
You can see this on the docs: [https://www.elastic.co/guide/en/kibana/current/settings.html](https://www.elastic.co/guide/en/kibana/current/settings.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2017, 5:29pm UTC](https://discuss.elastic.co/t/es-5-2-2-x-pack-index-permission-error/78187/5 "2017-04-10T17:29:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
