# Privilege issue : opening dashboard always requests the default index pattern

**URL:** <https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [July 9, 2021, 11:03am UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274 "2021-07-09T11:03:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![duc00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duc00/32/68773_2.png) [@duc00](https://discuss.elastic.co/u/duc00)\
**Post date:** [July 9, 2021, 11:03am UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/1 "2021-07-09T11:03:24Z")

</div>

Hello,

I have a user having only privilege to interact with the index pattern `pattern-b-*`. Default index pattern is `pattern-a-*`. The user is accessing a dashboard with visualisations only requesting `pattern-b-*` indexes, which I verified in the dashboard and visualisations exports.

The problem is that no matter which dashboard is opened, he would get the alert

```auto
No matching indices found: No indices match pattern "pattern-a-*"

```

I solved this by giving the `view_index_metadata` privilege to the default index. But it still triggers me. My question is why would any dashboard make a request to the default index pattern even if no visualisation is requesting it?

Thank you for your help,  
duc00

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [July 9, 2021, 11:45am UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/2 "2021-07-09T11:45:35Z")

</div>

Hi Mathieu,

what kind of visualizations are on that dashboard? It can be that if all those visualizations are of a type that don't report their index pattern (which e.g. TSVB and Vega didn't do in earlier versions), that the dashboard doesn't know which index patterns are present on in, in which case it will try to load the default for showing the field list in the filter UI. Could you maybe click the "Add filter" button on such a dashboard and share a screenshot of it, that might help seeing this.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![duc00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duc00/32/68773_2.png) [@duc00](https://discuss.elastic.co/u/duc00)\
**Post date:** [July 9, 2021, 1:55pm UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/3 "2021-07-09T13:55:00Z")

</div>

Hi Tim,

I found out that the issue appears even on an empty dashboard. I really don't know what's happening there.. Attached are screenshots of the role privileges and empty screenshot view. The index pattern on the error window is the default pattern. Kibana version is 7.13.0.

Thanks,  
duc00

 ![Screenshot 2021-07-09 at 14.43.54](https://us1.discourse-cdn.com/elastic/original/3X/a/f/afdb883e8417c47889d94c9022151ba235ccbdac.png)  
 ![Screenshot 2021-07-09 at 14.44.55](https://us1.discourse-cdn.com/elastic/original/3X/5/8/583cba6863b311f501de3b4c09dc98b0b95bc075.png)

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [July 9, 2021, 2:20pm UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/4 "2021-07-09T14:20:31Z")

</div>

Hi,

yes that def makes sense on an empty dashboard. So we need to populate fields in the "Add filter" dialog in the filter bar. When you're not having any specific index patterns on the dashboard (e.g. because it's empty) we're filling in the fields of the default index pattern. So if a user won't have access to that, they'll see this error message.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![duc00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/duc00/32/68773_2.png) [@duc00](https://discuss.elastic.co/u/duc00)\
**Post date:** [July 9, 2021, 5:12pm UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/5 "2021-07-09T17:12:44Z")

</div>

So I checked the non-empty dashboard and filter terms are from `pattern-b-*` and not the default index. Error still happens here too. All visualisations are linked to `pattern-b-*` even the TSVB. I exported the dashboard and associated visualisations to ndjson, but can't really see something wrong.

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [July 12, 2021, 8:30am UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/6 "2021-07-12T08:30:53Z")

</div>

Hi,

you're right I was able to reproduce it, and this is a bug. I've logged [TSVB requests wrongly default index pattern on dashboard · Issue #105182 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/105182) for it.

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2021, 8:31am UTC](https://discuss.elastic.co/t/privilege-issue-opening-dashboard-always-requests-the-default-index-pattern/278274/7 "2021-08-09T08:31:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
