# How to give read only privileges in the Index management module?

**URL:** <https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 2, 2020, 12:54am UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155 "2020-09-02T00:54:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [September 2, 2020, 12:54am UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/1 "2020-09-02T00:54:37Z")

</div>

Hello,  
How can I give read-only permissions to the "Index Management" module?  
So users can search for indices, but not delete, freeze, flush, etc.

The use case is, that I want to give users permission to create index patterns. But in the index patterns module, not all indices are exposed. I believe it is only first 100 indices?!

 ![2020-09-02 10_47_46-Window](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b0b1caaf5af056baa08f10a38a8ccec738068d4a.png)

Thanks

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 14, 2020, 11:58am UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/2 "2020-09-14T11:58:39Z")

</div>

For now this isn't possible straightforward. Once this PR [https://github.com/elastic/kibana/pull/67791](https://github.com/elastic/kibana/pull/67791) gets merged, you will be able to configure it more. For now, the workaround would be to set custom cluster privileges for the roles of the users, from this list:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html)

At first glance I'm thinking of giving them only: read, view\_index\_metadata, monitor but not manage or maintenance.  
Look over the list and it's description to see if they give them a permission that you don't want them to have.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 14, 2020, 1:50pm UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/3 "2020-09-14T13:50:37Z")

</div>

FYI: i created an enhancement request for this exact use case. You can find it and track it here: [https://github.com/elastic/kibana/issues/77347](https://github.com/elastic/kibana/issues/77347)

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [September 14, 2020, 11:15pm UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/4 "2020-09-14T23:15:20Z")

</div>

@Marius_Dragomir  
Thanks for the advice and reference.  
The article says

```auto
Read-only access to actions (count, explain, get, mget, get indexed scripts, more like this, multi percolate/search/termvector, percolate, scroll, clear_scroll, search, suggest, tv).

```

I understood it is via DEV tools?  
Will it be available also in Kibana UI?

Cheers!

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [September 14, 2020, 11:17pm UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/5 "2020-09-14T23:17:39Z")

</div>

> [@Marius\_Dragomir](#):
>
> FYI: i created an enhancement request for this exact use case. You can find it and track it here: [Read-only mode for Index management · Issue #77347 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/77347)

That's great.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 15, 2020, 1:10pm UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/6 "2020-09-15T13:10:43Z")

</div>

> [@AClerk](#):
>
> Will it be available also in Kibana UI?

Yes, this will apply to all requests made from within Kibana by the user that's logged in. For now they will still be able to see the DELETE, FREEZE and so on options in the UI for index management, but the action will throw an error and won't allow them to complete the action.  
This user experience will be improved once that enhancement is solved.

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [September 16, 2020, 7:05am UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/7 "2020-09-16T07:05:05Z")

</div>

Thanks for clarifying.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 7:05am UTC](https://discuss.elastic.co/t/how-to-give-read-only-privileges-in-the-index-management-module/247155/8 "2020-10-14T07:05:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
