# Permission Rules for CSV Export on Basic License

**URL:** <https://discuss.elastic.co/t/permission-rules-for-csv-export-on-basic-license/303979>\
**Category:** Kibana\
**Tags:** elastic-stack-reporting\
**Created:** [May 4, 2022, 10:58pm UTC](https://discuss.elastic.co/t/permission-rules-for-csv-export-on-basic-license/303979 "2022-05-04T22:58:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tadgh](https://avatars.discourse-cdn.com/v4/letter/t/9f8e36/32.png) [@tadgh](https://discuss.elastic.co/u/tadgh)\
**Post date:** [May 4, 2022, 10:58pm UTC](https://discuss.elastic.co/t/permission-rules-for-csv-export-on-basic-license/303979/1 "2022-05-04T22:58:00Z")

</div>

Hey there, we run an ECK instance, which runs ES 7.16.2 However recently, users who were previously able to generate CSV reports are no longer able to generate CSV reports. We didn't upgade the stack or anything, just suddenly... permission denied. I found this article: [Configure reporting in Kibana | Kibana Guide [8.2] | Elastic](https://www.elastic.co/guide/en/kibana/current/secure-reporting.html#grant-user-access-basic) which indicates that I should setup a user with a role that contains roughly this permission:

```auto

PUT localhost:5601/api/security/role/custom_reporting_user
{
  "elasticsearch": { "cluster": [], "indices": [], "run_as": [] },
  "kibana": [
    {
      "base": [],
      "feature": {
        "dashboard": ["all"], 
        "discover": ["all"], 
      },
      "spaces": ["*"]
    }
  ],
  "metadata": {} // optional
}

```

I have done this, and also fixed it after so that it points to the correct spaces and indexes. However, any user which has this role _still_ cannot generate a CSV from a saved search in discover. Am I missing something obvious? I am using ECK 1.9.1 with ES version 7.16.2.

It's worth noting that superusers can still do this, just other users..cannot.

Thanks!

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [May 5, 2022, 3:47pm UTC](https://discuss.elastic.co/t/permission-rules-for-csv-export-on-basic-license/303979/2 "2022-05-05T15:47:25Z")

</div>

Do you have this setting disabled as per documentation?

```auto
xpack.reporting.roles.enabled: false

```

Worth also noting you should check your version documentation just in case there are changes

> **[Configure reporting in Kibana | Kibana Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/kibana/7.16/secure-reporting.html#grant-user-access)**
>
> A list of the supported authentication mechanisms in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 3:47pm UTC](https://discuss.elastic.co/t/permission-rules-for-csv-export-on-basic-license/303979/3 "2022-06-02T15:47:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
