# Kibana Create Role API returns 404

**URL:** <https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 26, 2022, 7:39pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211 "2022-09-26T19:39:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlos](https://avatars.discourse-cdn.com/v4/letter/j/cdc98d/32.png) [@jlos](https://discuss.elastic.co/u/jlos)\
**Post date:** [September 26, 2022, 7:39pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211/1 "2022-09-26T19:39:17Z")

</div>

Hello,

I know this is technically a duplicate of [this discussion right here](https://discuss.elastic.co/t/create-or-update-role-api-returns-404/206066), but I'm not satisfied with the outcome of it.

I'm attempting to use Kibana's create/update role API to create a user role. I'm following [the documentation here](https://www.elastic.co/guide/en/kibana/7.16/role-management-api-put.html#role-management-api-put-prereqs), but when I make this call I get a 404 not found error.

This is the CURL command I'm using:

`curl -X PUT "http://elastic:changeme@localhost:5601/api/security/role/new_role" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d '{<role information>}'`

If I try this command with a role that already exists, such as 'kibana\_user' I get that role's info, so I know that my user has the 'manage security' cluster privilege.

I've tried sending this request with '-X GET' as the user in the previously linked discussion did, but that didn't work.

I'm running out of ideas. Am I missing something here? I'm using Kibana 7.16.2 if that matters at all.

\*edit - added Kibana version

---

<div class="post-metadata">

**Author:** ![jlos](https://avatars.discourse-cdn.com/v4/letter/j/cdc98d/32.png) [@jlos](https://discuss.elastic.co/u/jlos)\
**Post date:** [September 26, 2022, 10:52pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211/2 "2022-09-26T22:52:03Z")

</div>

Welp, it seems I was able to fix this by creating a role with the same name through [the Elasticsearch role API](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-role.html). This is probably why I was getting a 404, the role didn't exist on Elasticsearch.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [September 26, 2022, 11:10pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211/3 "2022-09-26T23:10:42Z")

</div>

@Larry_Gregory whenever you get a chance - can you throw some light on this ? Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 26, 2022, 11:25pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211/4 "2022-09-26T23:25:48Z")

</div>

Perhaps take a look at [this post](https://discuss.elastic.co/t/file-based-roles-for-kibana-access/313040/2) talks a about the difference of creating roles through Kibana and Elasticsearch APIs

Perhaps that will help a bit... Or not i.e they are related but not the same.

Think of role API through Kibana as a higher level abstraction of the lower level elasticsearch API

Hope that makes a little sense.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 11:26pm UTC](https://discuss.elastic.co/t/kibana-create-role-api-returns-404/315211/5 "2022-10-24T23:26:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
