# How create a role for creating index and ingest on it

**URL:** <https://discuss.elastic.co/t/how-create-a-role-for-creating-index-and-ingest-on-it/359144>\
**Category:** Kibana\
**Created:** [May 9, 2024, 7:36am UTC](https://discuss.elastic.co/t/how-create-a-role-for-creating-index-and-ingest-on-it/359144 "2024-05-09T07:36:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sandra\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_a/32/126560_2.png) [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Post date:** [May 9, 2024, 7:36am UTC](https://discuss.elastic.co/t/how-create-a-role-for-creating-index-and-ingest-on-it/359144/1 "2024-05-09T07:36:46Z")

</div>

Hi;  
I want to create a role with these privileges in "Index privileges" section:  
[create\_index , create, create\_doc, index]

There is a box to select which index the role can have access:

 ![Screenshot from 2024-05-09 03-30-59](https://us1.discourse-cdn.com/elastic/original/3X/8/7/87d475fe19ba4108466a68664c8255671d97bf3e.png)

I have some agents with this role which create and add docs to new\_index.  
I should choose \* for index section so agent can create and ingest. in this situation the agent can access to all Indices. But i want agent can create an index and just access to that index, not other indices.

How can I do it?

---

<div class="post-metadata">

**Author:** ![sandra\_a](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_a/32/126560_2.png) [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Post date:** [November 20, 2024, 7:35am UTC](https://discuss.elastic.co/t/how-create-a-role-for-creating-index-and-ingest-on-it/359144/2 "2024-11-20T07:35:50Z")

</div>

# Step 1: Create the role

```auto
PUT /_security/role/reindex_role
{
  "cluster": ["manage"],
  "indices": [
    {
      "names": ["*"],
      "privileges": ["read", "create_index"]
    }
  ]
}

```

# Step 2: Create the user and assign the role

```auto
PUT /_security/user/reindex_user
{
  "password" : "dsads$dasdd$",
  "roles" : ["reindex_role"],
  "full_name" : "Reindex User",
  "email" : "reindex_user@example.com"
}

```
