# Ldap groups within Kibana

**URL:** https://discuss.elastic.co/t/ldap-groups-within-kibana/74364
**Category:** Elasticsearch
**Created:** [February 8, 2017, 12:48pm UTC](https://discuss.elastic.co/t/ldap-groups-within-kibana/74364 "2017-02-08T12:48:30Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)
#### Post date: [February 8, 2017, 12:48pm UTC](https://discuss.elastic.co/t/ldap-groups-within-kibana/74364/1 "2017-02-08T12:48:30Z")

</div>

Hello friends, and first of all sorry for my english.

I use a trial license of ELK (5.1) and many functions are working great.

With X-Pack Security, native accounts and role are working.

I tried an ldap integration of ELK. Here is the ldap part of code of my elastic.yml :

(I have a group of users in LDAP named ELK\_Users)

xpack:  
security:  
authc:  
realms:  
ldap1:  
type: ldap  
order: 0  
url: "ldaps://xxxxxx1.company.org:636"  
bind\_dn: "cn=Svc\_ElasticSearch, ou=ElasticSearch, ou=Applications, dc=company, dc=com"  
bind\_password: xxxxxxxxxxxxxxxxxx  
user\_search:  
base\_dn: "dc=company,dc=com"  
attribute: cn  
group\_search:  
base\_dn: "cn=ELK\_Users,ou=ElasticSearch,ou=Applications,dc=company,dc=com"  
files:  
role\_mapping: "CONFIG\_DIR/x-pack/role\_mapping.yml"  
unmapped\_groups\_as\_roles: false  
ssl.verification\_mode: none  
ssl.keystore.path: ["CONFIG\_DIR/x-pack/Node01.jks"]  
ssl.keystore.password: xxxxxxxx  
ssl.keystore.key\_password: xxxxxxxxxxxxxx

Ldap authentification works, but any account of my company could connect to Kibana, not only members of the group ELK\_Users.

But in Kibana, Discover page, visualize page or management are blank. Monitoring page display an access denied page :

_You are not authorized to access Monitoring. To use Monitoring, you need the privileges granted by both the `kibana_user` and `monitoring_user` roles._

_If you are attempting to access a dedicated monitoring cluster, this might be because you are logged in as a user that is not configured on the monitoring cluster_.

I don't know how to match in kibana the monitoring role with my ldap group _ELK\_Users_.  
I tried this setting in role\_mapping.yml but it failed :

monitoring\_user:

- "cn=ELK\_Users,ou=ElasticSearch,ou=Applications,dc=company,dc=com"  
kibana\_user:
- "cn=ELK\_Users,ou=ElasticSearch,ou=Applications,dc=company,dc=com"

A big thanks for your help and advice 🙂

---

<div class="post-metadata">

### Author: ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)
#### Post date: [February 9, 2017, 6:48pm UTC](https://discuss.elastic.co/t/ldap-groups-within-kibana/74364/2 "2017-02-09T18:48:35Z")

</div>

I'm moving your post over to the Elasticsearch forum since Kibana only checks roles with Elasticsearch.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 9, 2017, 6:48pm UTC](https://discuss.elastic.co/t/ldap-groups-within-kibana/74364/3 "2017-03-09T18:48:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
