It is not clear how to grant "Stack Monitoring" and "Machine Learning" privileges to an AD group (unmapped_groups_as_roles: true), which already has access to all indices and has all cluster privileges.
There is a message in Kibana "you should also assign the monitoring_user role", but it's not clear how to do that.
Is it something for role_mapping?
Note: a user from that AD group can access all monitoring data, when querying ES directly. Why does Kibana refuse to show the Monitoring page?
as I wrote, I'm using an unmaped AD group as a role, and the role has full index and cluster access.
Are there some restrictions on Kibana 7.x when using unmapped_groups_as_roles: true?
Thanks!
P.S. It's always disappointing, when an upgrade breaks something, that used to work with the previous version
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.