# Kibana multiple user problem

**URL:** <https://discuss.elastic.co/t/kibana-multiple-user-problem/266351>\
**Category:** Kibana\
**Tags:** elastic-stack-security, ilm-index-lifecycle-management\
**Created:** [March 5, 2021, 11:03am UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351 "2021-03-05T11:03:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [March 5, 2021, 11:03am UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/1 "2021-03-05T11:03:28Z")

</div>

I have setup two users one user is super and other one is non superuser  
**for non superuser**  
i have a custom role for user user2(non superuser)

```auto
GET /_security/role/pb_log
{
  "pb_log" : {
    "cluster" : [
      "manage",
      "manage_index_templates"
    ],
    "indices" : [
      {
        "names" : [
          "log-pb-*"
        ],
        "privileges" : [
          "read",
          "manage",
          "manage_ilm"
        ],
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [
      {
        "application" : "kibana-.kibana",
        "privileges" : [
          "feature_dashboard.all",
          "feature_discover.all",
          "feature_canvas.all",
          "feature_maps.all",
          "feature_ml.all",
          "feature_visualize.all",
          "feature_logs.all",
          "feature_infrastructure.all",
          "feature_apm.all",
          "feature_uptime.all",
          "feature_dev_tools.all",
          "feature_advancedSettings.all",
          "feature_indexPatterns.all",
          "feature_savedObjectsManagement.all"
        ],
        "resources" : [
          "space:default"
        ]
      }
    ],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

user2 information

```auto
GET /_security/user/user2
{
 "user2" : {
    "username" : "user2",
    "roles" : [
      "pb_log",
      "monitoring_user"
    ],
    "full_name" : "USER2",
    "email" : "",
    "metadata" : { },
    "enabled" : true
  }

```

user2 can access only log-pb-\* indices and user1 can access all  
but i am facing some issue  
in elasticsearch logs

```auto

[2021-03-05T16:19:16,148][INFO][o.e.x.i.IndexLifecycleRunner] [em1] policy [winlogbeat_sysmon_policy] for index [log-wlb-sysmon-2021.03.02-000023] on an error step due to a transient error, moving back to the failed step [check-rollover-ready] for execution. retry attempt [28]
security_exception: action [indices:admin/rollover] is unauthorized for user [user2]

```

i am using winlogbeat and packetbeat logs.user2 can use packetbeat and user1 can use both so i have setup another role for logstash  
role name is pb\_logstash

```auto
{
  "pb_logstash" : {
    "cluster" : [
      "manage",
      "manage_index_templates",
      "monitor",
      "manage_ilm"
    ],
    "indices" : [
      {
        "names" : [
          "log-pb-*"
        ],
        "privileges" : [
          "write",
          "manage",
          "manage_ilm",
          "read",
          "create_index",
          "create"
        ],
        "allow_restricted_indices" : false
      }
    ],
    "applications" : [],
    "run_as" : [],
    "metadata" : { },
    "transient_metadata" : {
      "enabled" : true
    }
  }
}

```

but when i login with user1 there is an error showing in kibana stack management

 ![ha3](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d4c5c55896a2061dc5633f2efda7a657936f224e.jpeg)

The question is that user2 can access only packetbeat indices but cannot winlogbeat but why it is showing user2 is unauthorised

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 5, 2021, 1:34pm UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/2 "2021-03-05T13:34:45Z")

</div>

from what i see in the role definitions for user2 (which I assume is the one from the screenshots) doesn't have any permissions for the `log-wlb*` indices. I only see `log-pb-*` there.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [March 5, 2021, 2:19pm UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/3 "2021-03-05T14:19:37Z")

</div>

user1 is superuser that means it can access any index and user2 can access log-plb-\*

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 5, 2021, 2:40pm UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/4 "2021-03-05T14:40:37Z")

</div>

Ok, and user 2 is showing unauthorized on "log-wlb-sysmon....", which seems to be as intended, right?

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [March 5, 2021, 4:10pm UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/5 "2021-03-05T16:10:14Z")

</div>

> [@Marius\_Dragomir](#):
>
> Ok, and user 2 is showing unauthorized on "log-wlb-sysmon....", which seems to be as intended, righ

Yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2021, 4:10pm UTC](https://discuss.elastic.co/t/kibana-multiple-user-problem/266351/6 "2021-04-02T16:10:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
