# Problems configuring Field Level Security and Kibana

**URL:** <https://discuss.elastic.co/t/problems-configuring-field-level-security-and-kibana/51068>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 26, 2016, 2:35pm UTC](https://discuss.elastic.co/t/problems-configuring-field-level-security-and-kibana/51068 "2016-05-26T14:35:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![olorasde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/olorasde/32/40103_2.png) [@olorasde](https://discuss.elastic.co/u/olorasde)\
**Post date:** [May 26, 2016, 2:35pm UTC](https://discuss.elastic.co/t/problems-configuring-field-level-security-and-kibana/51068/1 "2016-05-26T14:35:50Z")

</div>

I have the following setup:

- 4.4.1 Kibana
- EN 2.2.0
- Plugin shield (2.3.1)

I have the shield configuration activated with internal realm. I have created several roles and one of them has set the security shield fields.

The configuration I have is this:

```
kibana4_role1:
  cluster:
      - cluster:monitor/nodes/info
      - cluster:monitor/health
  indices:
    '.kibana*':
      privileges: indices:admin/create, indices:admin/exists, indices:admin/mapping/put, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search, indices:data/write/delete, indices:data/write/index, indices:data/write/update
    'logstash-indice-a':
      privileges: all
      fields: 
        - ip
        - url

```

With it, I can not access Kibana, I get an error:

_**ElasticsearchSecurityException [action [indices: data / read / msearch] is unauthorized for user [agent1]]**_

If I remove security settings and fields based on the active document, I have no problem. Works and access.

If I remove the security settings in general (or by fields or by documents) I can also access Kiabana smoothly.

NOTE: The basic index information is this:

```
"_index" : "logstash-indice-a",
"_type" : "logs",
"_id" : "AVToKq_7GEzUiOV5W_7z",
"_score" : 1.0,
"_source" : {
  "message" : "127.0.0.1 - - [25/May/2016:15:46:30 +0200] \"GET /manual/images/left.gif HTTP/1.1\" 304 -\r",
  "@version" : "1",
  "@timestamp" : "2016-05-25T13:46:31.558Z",
  "path" : "C:\\Program Files (x86)\\Apache Group\\Apache2\\logs\\access.log",
  "host" : "BCN-83T55S1",
  "ip" : "127.0.0.1",
  "timestamp" : "25/May/2016:15:46:30",
  "timezone" : "+0200",
  "method" : "GET",
  "url" : "/manual/images/left.gif HTTP/1.1\" 304 -\r"
}

```

I think when fields based security is enabled, so that Kibana can show indexes, you must put all the indices metadata, but I have tried different configurations without result.

this configuration should work but it is not so...

```
kibana4_role1:
  cluster:
      - cluster:monitor/nodes/info
      - cluster:monitor/health
  indices:
    '.kibana*':
      privileges: indices:admin/create, indices:admin/exists, indices:admin/mapping/put, indices:admin/mappings/fields/get, indices:admin/refresh, indices:admin/validate/query, indices:data/read/get, indices:data/read/mget, indices:data/read/search, indices:data/write/delete, indices:data/write/index, indices:data/write/update
    'logstash-indice-a':
      privileges: all
      fields: 
        - message
        - \@version
        - \@timestamp
        - path
        - host
        - ip
        - timestamp
        - timezone
        - method
        - url

```

You can Kibana show indices having an associated security fields?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [May 27, 2016, 3:15pm UTC](https://discuss.elastic.co/t/problems-configuring-field-level-security-and-kibana/51068/2 "2016-05-27T15:15:47Z")

</div>

It appears as though you are missing the `indices:data/read/msearch` for the `.kibana*` indices in both roles

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/problems-configuring-field-level-security-and-kibana/51068/3 "2017-07-06T13:44:32Z")

</div>


