# Kibana "error fetching fields" forbidden

**URL:** <https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851>\
**Category:** Kibana\
**Created:** [January 21, 2020, 9:40am UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851 "2020-01-21T09:40:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerard1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard1/32/53507_2.png) [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Post date:** [January 21, 2020, 9:40am UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/1 "2020-01-21T09:40:52Z")

</div>

I'm using version 7.5 on Elastic Cloud, and I've created a new user & role, to use instead of global admin "elastic" account, setting the permissions to read from the desired indexes.

If that non-admin user access Kibana \> Discovery BEFORE the admin "elastic" user, that error is triggered. Once the "elastic" user access Kibana \> Discovery, the error goes away. This happens every 24h hours.

I assume that some action is performed when accessing Discovery after a while, and the normal user doesn't have enough permissions to perform it, but I can't figure out what is it.

I've also seen this error was reported here: [Error fetching fields](https://discuss.elastic.co/t/error-fetching-fields/200008), but the solution doesn't make much sense to me.

---

<div class="post-metadata">

**Author:** ![bvanhaute](https://avatars.discourse-cdn.com/v4/letter/b/7feea3/32.png) [@bvanhaute](https://discuss.elastic.co/u/bvanhaute)\
**Post date:** [January 27, 2020, 9:55am UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/2 "2020-01-27T09:55:09Z")

</div>

I'm having the same issue with an on prem 7.5.2 deployment.

---

<div class="post-metadata">

**Author:** ![Loek\_van\_Gool](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loek_van_gool/32/59627_2.png) [@Loek\_van\_Gool](https://discuss.elastic.co/u/Loek_van_Gool)\
**Post date:** [January 27, 2020, 2:44pm UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/3 "2020-01-27T14:44:44Z")

</div>

Does the non-elastic user have the `kibana_user` role? If not, I suspect that might fix it.

Otherwise, please post:

- The roles of the non-elastic user
- The definition of any of the roles of the non-elastic user, that are not built-in

You can do this with:

`GET _security/user/<username>`  
`GET _security/role/<role>`

---

<div class="post-metadata">

**Author:** ![gerard1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard1/32/53507_2.png) [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Post date:** [January 27, 2020, 3:01pm UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/4 "2020-01-27T15:01:11Z")

</div>

I've created a specific role for the user.

GET \_security/user/test

```auto
{
  "test" : {
    "username" : "test",
    "roles" : [
      "User"
    ],
    "full_name" : "Test",
    "email" : "",
    "metadata" : { },
    "enabled" : true
  }
}

```

GET \_security/user/User

```auto
{
  "User" : {
    "cluster" : [],
    "indices" : [
      {
        "names" : [
          "filebeat-*"
        ],
        "privileges" : [
          "read"
        ],
        "field_security" : {
          "grant" : [
            "*"
          ],
          "except" : []
        },
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [
      {
        "application" : "kibana-.kibana",
        "privileges" : [
          "feature_discover.all",
          "feature_visualize.all",
          "feature_dashboard.all",
          "feature_siem.read",
          "feature_maps.read",
          "feature_canvas.read",
          "feature_graph.read"
        ],
        "resources" : [
          "space:default"
        ]
      }
    ],
    "run_as" : [
      "test"
    ],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Loek\_van\_Gool](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/loek_van_gool/32/59627_2.png) [@Loek\_van\_Gool](https://discuss.elastic.co/u/Loek_van_Gool)\
**Post date:** [January 27, 2020, 3:22pm UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/5 "2020-01-27T15:22:00Z")

</div>

Please add the `kibana_user` role to the user, so that it reads:

```auto
{
  "test" : {
    "username" : "test",
    "roles" : [
      "User",
      "kibana_user"
    ],
    "full_name" : "Test",
    "email" : "",
    "metadata" : { },
    "enabled" : true
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2020, 3:22pm UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-forbidden/215851/6 "2020-02-24T15:22:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
