# How to restrict user to access tab on kibana

**URL:** <https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 10, 2018, 12:59pm UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137 "2018-11-10T12:59:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [November 10, 2018, 12:59pm UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/1 "2018-11-10T12:59:28Z")

</div>

Hi,  
I want to restrict management,apm,graph to access by user. I'm using xpack. It contain default roles in that i could see one role 'kibana\_dashboard\_only' like this i want to provide some role.

Anyone can help me on this.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 12, 2018, 10:22pm UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/2 "2018-11-12T22:22:58Z")

</div>

Exactly, you would have to define your roles for example : There are some in-built roles like :

`machine_learning_admin`

Grants `manage_ml` cluster privileges and read access to the `.ml-*` indices.

`machine_learning_user`

Grants the minimum privileges required to view X-Pack machine learning configuration, status, and results. This role grants `monitor_ml` cluster privileges and read access to the `.ml-notifications` and `.ml-anomalies*` indices, which store machine learning results.

`monitoring_user`

Grants the minimum privileges required for any user of X-Pack monitoring other than those required to use Kibana. This role grants access to the monitoring indices. Monitoring users should also be assigned the `kibana_user` role.

`remote_monitoring_agent`

Grants the minimum privileges required for a remote monitoring agent to write data into this cluster.

`reporting_user`

Grants the specific privileges required for users of X-Pack reporting other than those required to use Kibana. This role grants access to the reporting indices. Reporting users should also be assigned the `kibana_user` role and a role that grants them access to the data that will be used to generate reports with.

`superuser`

Grants full access to the cluster, including all indices and data. A user with the `superuser` role can also manage users and roles and [impersonate](https://www.elastic.co/guide/en/x-pack/current/run-as-privilege.html) any other user in the system. Due to the permissive nature of this role, take extra care when assigning it to a user.

more ref: [https://www.elastic.co/guide/en/x-pack/current/built-in-roles.html](https://www.elastic.co/guide/en/x-pack/current/built-in-roles.html)

However, There's no built-in way to restrict or turn off the Management tab in Kibana currently.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [November 13, 2018, 5:42am UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/3 "2018-11-13T05:42:04Z")

</div>

Thanks Rashmi. its very helpful.

But i need to create my own rule in that i want to restrict user to read alone and user should not have any write or delete operation how could i achieve that.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 13, 2018, 5:58pm UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/4 "2018-11-13T17:58:14Z")

</div>

> [@Ganesh2303](#):
>
> e my own rule in that i want to restrict user to read alone and user should not have any write or delete operation how could i achieve that.

HI ganesh,  
Yes that can be achieved very easily. So I think what you want is for a readonly user (with a readonly role) to Not be allowed to create/update/delete index patterns, saved searches, visualizations, or dashboards. Those things are all in the .kibana index, so below I've ONLY changed the privileges for the .kibana index.

That way they can Read everything and run queries, even create new visualizations and dashboards (on any existing index pattern) but not save any changes.

If that's correct, in this example below I

```auto
readonly:
      cluster: 
          - cluster:monitor/nodes/info
          - cluster:monitor/health 
      indices:
        '*':
          privileges: indices:admin/mappings/fields/get, indices:admin/validate/query, indices:data/read/search, indices:data/read/msearch, indices:data/read/field_stats, indices:admin/get
        '.kibana':
          privileges: indices:admin/exists, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search

```

I removed these privs;

- indices:admin/mapping/put,
- indices:data/write/delete
- indices:data/write/index
- indices:data/write/update

Or did you only want the user to not be able to change the index pattern but still be able to create/modify/save Saved searches, Visualizations, and Dashboards?

Hope this helps,  
Rashmi

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [November 14, 2018, 3:48am UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/5 "2018-11-14T03:48:52Z")

</div>

> [@rashmi](#):
>
> readonly: cluster: - cluster:monitor/nodes/info - cluster:monitor/health indices: '\*': privileges: indices:admin/mappings/fields/get, indices:admin/validate/query, indices:data/read/search, indices:data/read/msearch, indices:data/read/field\_stats, indices:admin/get '.kibana': privileges: indices:admin/exists, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search

Thank you for your elaborate reply and may i know where i have put this change. whether i have to paste it on elasticsearch.yml

> [@rashmi](#):
>
> did you only want the user to not be able to change the index pattern but still be able to create/modify/save Saved searches, Visualizations, and Dashboards?

User which im creating, they need to look discover for events and they dont need to create/delete/update

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2018, 3:48am UTC](https://discuss.elastic.co/t/how-to-restrict-user-to-access-tab-on-kibana/156137/6 "2018-12-12T03:48:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
