# Kibana Role Mapping

**URL:** <https://discuss.elastic.co/t/kibana-role-mapping/244374>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 10, 2020, 9:07am UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374 "2020-08-10T09:07:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [August 10, 2020, 9:07am UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374/1 "2020-08-10T09:07:14Z")

</div>

Hello All,

I am trying to map a kibana role with active directory users. The ad users assigned to the role can see the index but cannot see any data within the index itself.

I have mirrored a working role with the exact same settings in kibana management role like so:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/7/679d425d4c0daf5f26c7cfb4e522c133b4b36730.png)

And on elasticsearch master, I added it to role mapping.yml as so:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1ffb2b73d6e71ec9367feb7d1d5fadad9eca8343.png)

The security group is added within Active directory as well and active directory users added to that security group. When these users sign into Kibana, they can see the index name but they cant see any data. Again it is setup as exactly as the same as other working roles

Am I missing something? Do I need to restart elasticsearch service after changes to the role\_mapping.yml file?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 10, 2020, 1:14pm UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374/2 "2020-08-10T13:14:37Z")

</div>

> [@Kevin\_f](#):
>
> When these users sign into Kibana, they can see the index name but they cant see any data.

I suspect you simply mean that they can see the Kibana index pattern. There is no security about index patterns (except within Kibana spaces), so this probably means that your users are not being granted the role you expect.

> [@](#):
>
> Do I need to restart elasticsearch service after changes to the role\_mapping.yml file?

No, if it is correctly configured, it will be loaded automatically after it is modified. You do need to change it on every node though...

> [@](#):
>
> on elasticsearch master, I added it to role mapping.yml

I suspect this is the problem. You cannot simply edit the file on the master node, it needs to exist on every node that can perform authentication (which is most clusters is every node).

---

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [August 10, 2020, 2:43pm UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374/3 "2020-08-10T14:43:01Z")

</div>

Hi Tim,

Thank you for your response.

I can see the index pattern with log data but other users cant.

ahhh okay in this case I only made the change in the master nodes and not data nodes. That would probably explain it. I will make the change there and see. Thanks.

---

<div class="post-metadata">

**Author:** ![Kevin\_f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_f/32/72456_2.png) [@Kevin\_f](https://discuss.elastic.co/u/Kevin_f)\
**Post date:** [August 10, 2020, 3:27pm UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374/4 "2020-08-10T15:27:21Z")

</div>

Hi Tim,

Awesome that worked. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 3:27pm UTC](https://discuss.elastic.co/t/kibana-role-mapping/244374/5 "2020-09-07T15:27:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
