# Is there a way to change the default security roles?

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [October 9, 2019, 1:27am UTC](https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749 "2019-10-09T01:27:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [October 9, 2019, 1:27am UTC](https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749/1 "2019-10-09T01:27:47Z")

</div>

I'm using the ODBC driver to connect Tableau to Elasticsearch and ran into this. Through trial and error, the user connected to the driver needs to have the `manage` role in order to pull in the "tables" from ES. I tried by giving only `read` and `monitor` privs for the indices, but Tableau couldn't find the names of the indices I needed with only those two.

Under the `manage` priv, it says it has:

```auto
All monitor privileges plus index administration (aliases, analyze, cache clear, close, delete, exists, flush, mapping, open, force merge, refresh, settings, search shards, templates, validate).

```

I'd love it if I could exclude the `delete` priv and keep the other ones open. Is there any way to do a custom one?

This is definitely a problem for anyone using the Tableau connector to ES and has users with different permission levels because they need to have this priv in order to make the connection to indices happen at all.

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [October 9, 2019, 12:45pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749/2 "2019-10-09T12:45:09Z")

</div>

Hi @seanziee,

Have you seen this section of the docs [https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-security.html#sql-security-permissions](https://www.elastic.co/guide/en/elasticsearch/reference/current/sql-security.html#sql-security-permissions) ? It details the minimal role the user requires to use SQL/ODBC features.

Can you please try creating the following role:

```auto
curl -X POST "localhost:9200/_security/role/my_tableau_role?pretty" -H 'Content-Type: application/json' -d'
{
  "cluster": ["cluster:monitor/main"],
  "indices": [
    {
      "names": ["indices-tableau-is-pulling-*"],
      "privileges": ["read", "indices:admin/get"]
    }
  ]
}
'

```

And let us know if that worked for you?

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [October 10, 2019, 12:04am UTC](https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749/3 "2019-10-10T00:04:18Z")

</div>

No it didn't work, but I just got it to work with "read" and "view\_index\_metadata" for the index privs. Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2019, 12:04am UTC](https://discuss.elastic.co/t/is-there-a-way-to-change-the-default-security-roles/202749/4 "2019-11-07T00:04:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
