# Kibana Indices Privilege query

**URL:** <https://discuss.elastic.co/t/kibana-indices-privilege-query/77928>\
**Category:** Kibana\
**Created:** [March 9, 2017, 3:25am UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928 "2017-03-09T03:25:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [March 9, 2017, 3:25am UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/1 "2017-03-09T03:25:17Z")

</div>

Hi,

I have created a user to be used for creating the monthly logs in Elasticsearch cluster we have.

I just want this user to create a new index every month and push data into it. I do not want it to update or delete index and documents.

Keeping this in mind I gave this user **[create\_index](https://www.elastic.co/guide/en/x-pack/current/security-privileges.html#privileges-list-indices)** (for creating indices) and **create** privilege (to index documents). I skipped **index** privilege because it also allows user to update documents.

This is not working. It is not creating index and putting data into the cluster.

However when I give it **write** privilege along with create\_index and create privilege, it works !!!  
I do not want to give it write privilege because it includes permission to index, update, and delete documents as well as performing bulk operations.

I think I am making some silly mistake here. Can experts point out what privilege i should give?

\_ **Additional information:** The data is sent from the application by the serilog elasticsearch sink. And it looks like that it invokes[Bulk API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-bulk.html) to push data.

This is old [link](https://www.elastic.co/guide/en/shield/current/shield-privileges.html) but here is what it says:

```
Write : Privilege to perform all write operations on documents, including the ability to index, update, and delete documents as well as perform bulk operations. If write is granted on the .scripts index, it includes the ability to put and delete indexed scripts.

```

Looks like Bulk API operations does come with Write privilege only. Will like experts to chip in.

More information:  
I am able to put an index into the cluster via curl:

```
curl -u TonyStark:Pepper143 -XPUT 'http://StarkServer9200/TopSecret-01-2017.09/Coffee/1?pretty' -H 'Content-Type: application/json' -d' {"user" : "kimchy","post_date" : "2009-11-15T14:12:12","message" : "Blah"}'

```

Elasticsearch version: 5.2.1  
Kibana : 5.2.1

I am using serilog elasticsearch sink to push data from my application to the elasticsearch instance.

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [March 9, 2017, 5:43am UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/2 "2017-03-09T05:43:16Z")

</div>

I think I found why !!  
As per this [link](https://www.elastic.co/guide/en/elasticsearch/guide/current/distrib-write.html) : "Create, index, and delete requests are write operations".

So does that mean if **write** privilege is not given then **create\_index** and **create** privilege do not hold?

And the issue remains. This user can create indexes, push documents in. This user cannot delete indexes but can delete documents in them. 😱

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 9, 2017, 2:15pm UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/3 "2017-03-09T14:15:05Z")

</div>

@pk.241011 you were initially correct in assigning the `create_index` and `create` privileges, and I've verified that those two privileges allow the user to create an index and index documents. Are you able to verify the behavior you're seeing using `curl`?

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [March 9, 2017, 10:56pm UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/4 "2017-03-09T22:56:37Z")

</div>

Hi @Brandon_Kobel,

I just confirmed. I kept the permissions to create and create\_index. Through the application it failed. But on command line via curl it succeeded.

```
curl -u tony:pepper123 -XPUT 'http://starkindustry:9200/ironman-01-2017.03/today/2?pretty' -H 'Content-Type: application/json' -d' {"user" : "kimchy","post_date" : "2009-11-15T14:12:12","message" : "trying out Elasticsearch"}'

```

More context (Though not sure if it helps since it works when I add write privilege to the user):  
Our serilog app setting are like this:  
`<add key="serilog:write-to:Elasticsearch.nodeUris" value="http://tony:pepper123@starkindustry:9200">`  
`<add key="serilog:write-to:Elasticsearch.indexFormat" value="ironman-01-{0:yyyy.MM}" />`

This means that depending on the month and year it will keep creating indexes in the format ironman-01-2017.03

This is the regex I have kept in indices field for this particular user to that he does not get access to any system level indices:  
`/.*-20[0-9][0-9]\.[0-1][0-9].*/` to match all the indices like blah-2017.03

---

<div class="post-metadata">

**Author:** ![pk.241011](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pk.241011/32/86285_2.png) [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Post date:** [March 15, 2017, 10:52pm UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/5 "2017-03-15T22:52:56Z")

</div>

@Brandon_Kobel I just added more information to the question. Just to summarise, the sink is sending data to Elasticsearch via Bulk API. Looks like create and create\_index do not include the bulk data upload privileges. Just wanted to know if my guess is right. And if so then are there any workarounds other than giving write privileges.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 16, 2017, 11:16am UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/6 "2017-03-16T11:16:01Z")

</div>

@pk.241011 you are correct that the bulk operations require the `write` privilege, so if serilog is using the bulk apis that user will require the `write` privilege.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 11:16am UTC](https://discuss.elastic.co/t/kibana-indices-privilege-query/77928/7 "2017-04-13T11:16:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
