# Kibana: Courier Fetch Error: unhandled error Error: \[security\_exception\] action \[indices:data/read/mget\] is unauthorized for user \[chirag\]

**URL:** <https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226>\
**Category:** Kibana\
**Created:** [January 14, 2016, 11:31am UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226 "2016-01-14T11:31:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Post date:** [January 14, 2016, 11:31am UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/1 "2016-01-14T11:31:19Z")

</div>

I've used shield and protected my elasticsearch indexes.  
It also asks for credentials when I start kibana.  
But when I login using credentials I've configured,  
following error is displayed.

Courier Fetch Error: unhandled error Error: [security\_exception] action [indices:data/read/mget] is unauthorized for user [chirag]

Please suggest a solution.

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 14, 2016, 5:43pm UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/2 "2016-01-14T17:43:31Z")

</div>

Have you configured Kibana to work with Shield per the instructions here?:

[https://www.elastic.co/guide/en/kibana/current/production.html#configuring-kibana-shield](https://www.elastic.co/guide/en/kibana/current/production.html#configuring-kibana-shield)

---

<div class="post-metadata">

**Author:** ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Post date:** [January 18, 2016, 8:06am UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/3 "2016-01-18T08:06:42Z")

</div>

@Bargs I have 2 roles for which I want to set role based access.  
1) Manager 2) Developer

I've **created these two roles along with kibana4-server** role,

Following is my roles.yml file,

```
# All cluster rights
# All operations on all indices
admin:
  cluster: all
  indices:
    '*':
      privileges: all

# monitoring cluster privileges
# All operations on all indices
power_user:
  cluster: monitor
  indices:
    '*':
      privileges: all

# Read-only operations on indices
manager:
  indices:
    '*':
      privileges: all

developer:
  cluster: 
      - cluster:monitor/nodes/info
      - cluster:monitor/health 
  indices:
    'wosiindex2':
      privileges: indices:data/read/mget, indices:admin/mappings/fields/get, indices:admin/validate/query, indices:data/read/search, indices:data/read/msearch, indices:admin/get

# Defines the required permissions for transport clients
transport_client:
  cluster:
      - cluster:monitor/nodes/liveness
      #uncomment the following for sniffing
      #- cluster:monitor/state

# The required permissions for kibana 4 users.
kibana4:
  cluster: 
      - cluster:monitor/nodes/info
      - cluster:monitor/health 
  indices:
    '*':
      privileges: indices:admin/mappings/fields/get, indices:admin/validate/query, indices:data/read/search, indices:data/read/msearch, indices:admin/get
    '.kibana':
      privileges: indices:admin/exists, indices:admin/mapping/put, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search, indices:data/write/delete, indices:data/write/index, indices:data/write/update, indices:admin/create

# The required permissions for the kibana 4 server
kibana4_server:
  cluster:
      - cluster:monitor/nodes/info
      - cluster:monitor/health
  indices:
    '.kibana':
      privileges: indices:admin/create, indices:admin/exists, indices:admin/mapping/put, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search, indices:data/write/delete, indices:data/write/index, indices:data/write/update, indices:admin/create

# The required role for logstash users
logstash:
  cluster: indices:admin/template/get, indices:admin/template/put
  indices:
    'logstash-*':
      privileges: indices:data/write/bulk, indices:data/write/delete, indices:data/write/update, indices:data/read/search, indices:data/read/scroll, create_index
    '*':
      privileges: all

# Marvel user role. Assign to marvel users.
marvel_user:
  indices:
    '.marvel-es-*':
      privileges: read
    '.kibana':
      privileges: indices:admin/exists, indices:admin/mappings/fields/get, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search

# Marvel remote agent role. Assign to the agent user on the remote marvel cluster
# to which the marvel agent will export all its data
remote_marvel_agent:
  cluster: indices:admin/template/put, indices:admin/template/get
  indices:
    '.marvel-es-*':
      privileges: all

```

kibana.yml file is as follows,

```
elasticsearch.username: kibana4-server
elasticsearch.password: abc123
kibana_elasticsearch_username: kibana4-server
kibana_elasticsearch_password: abc123

```

esusers list command shows,

```
D:\Users\elasticsearch-2.1.0\bin> shield\esusers list
aviral : developer
logstash : logstash
chirag : manager
kibana4-server : kibana4_server

```

**I have created two indices namely wosiindex and wosiindex2**

**If I log in as chirag, I can see, read both the indices**

**But If I log in as aviral, the above,** _Courier Fetch Error: unhandled error Error: [security\_exception] action [indices:data/read/mget]_ **error is displayed.**

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 20, 2016, 5:13pm UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/4 "2016-01-20T17:13:53Z")

</div>

The developer role needs permissions on the .kibana index. The easiest thing to do would be to copy the default `kibana4` role, and change `'*'` to `'wosiindex2'` if you want to restrict developer access to only that index. Users with the developer role will still be able to see the list of index patterns configured in Kibana, but they won't be able to access any data in your indices outside of wosiindex2.

---

<div class="post-metadata">

**Author:** ![krushnat\_khawale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krushnat_khawale/32/6652_2.png) [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Post date:** [January 28, 2016, 5:53am UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/5 "2016-01-28T05:53:09Z")

</div>

Yeah @Bargs  
Worked!!!  
Thanks for the help.

**Need to close this. But unfortunately, there is no option to close.**

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [January 28, 2016, 3:47pm UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/6 "2016-01-28T15:47:13Z")

</div>

Awesome! Glad I could help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:04pm UTC](https://discuss.elastic.co/t/kibana-courier-fetch-error-unhandled-error-error-security-exception-action-indices-data-read-mget-is-unauthorized-for-user-chirag/39226/7 "2017-07-06T14:04:02Z")

</div>


