# Readonly dashboard user in elastic cloud not working

**URL:** <https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514>\
**Category:** Elasticsearch\
**Created:** [August 15, 2018, 12:09pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514 "2018-08-15T12:09:48Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![hugohendriks](https://avatars.discourse-cdn.com/v4/letter/h/a6a055/32.png) [@hugohendriks](https://discuss.elastic.co/u/hugohendriks)\
**Post date:** [August 15, 2018, 12:09pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/1 "2018-08-15T12:09:48Z")

</div>

Hi, I'm using the trail version of an Cloud instance( 6.3.2) and I'm trying to create a user which only has dashboard rights to my dashboard. I've created a user and a specific dashboard role as I read here: [https://www.elastic.co/blog/kibana-dashboard-only-mode](https://www.elastic.co/blog/kibana-dashboard-only-mode) but when I log in with the user I see all the buttons on the left but for every page I get the message:

Error Config: Request failed with status code: 403.

best regards,  
hugo

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 16, 2018, 7:34am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/2 "2018-08-16T07:34:37Z")

</div>

Hi Hugo,

It looks like either your user has additional roles or that you have created a custom dashboard only role and something is amiss with that. Can you share your role definition and specific configuration with us?

---

<div class="post-metadata">

**Author:** ![hugohendriks](https://avatars.discourse-cdn.com/v4/letter/h/a6a055/32.png) [@hugohendriks](https://discuss.elastic.co/u/hugohendriks)\
**Post date:** [August 16, 2018, 8:25am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/3 "2018-08-16T08:25:28Z")

</div>

Hi,

I created a custom role.....My\_dasboard\_only\_user. As indices I added the index my dasboard uses. As priviliges i added Read and View\_index\_metadata.

I created a new user with this role.

And I added the custom role to the xpackDashboardMode:roles.

Thats it.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 17, 2018, 6:30am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/4 "2018-08-17T06:30:19Z")

</div>

Hi again,

I missed the `Cloud` part of your original email and made invalid assumptions. Creating a custom dashboard only role is usually only necessary when you are using a custom `.kibana` index , which is not the case for your Cloud trial instance.  
You need to add two roles to your user:

- One that gives them read access to the index your dashboard uses. The one you already have, `read` privileges should be enough.
- The built-in `kibana_dashboard_only_user` role.

---

<div class="post-metadata">

**Author:** ![hugohendriks](https://avatars.discourse-cdn.com/v4/letter/h/a6a055/32.png) [@hugohendriks](https://discuss.elastic.co/u/hugohendriks)\
**Post date:** [August 20, 2018, 9:02am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/5 "2018-08-20T09:02:44Z")

</div>

Hi,

I added the 2 roles to my readonly account and now the login works and I can see only my 2 dashboards. The only problem is now that there is no data. It seems it cannot access my index or so?

I gave my custom role read access to my index.

Any idea?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [August 20, 2018, 9:52am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/6 "2018-08-20T09:52:29Z")

</div>

Unless you actually provide the role definition then we're just guessing.

Does your role provide read access to the`.kibana` index?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 20, 2018, 10:15am UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/7 "2018-08-20T10:15:56Z")

</div>

@hugohendriks I assume that when you say that you added two roles, you mean the `kibana_dashboard_only_user` and a second one? Is that second one the one that gives read access to the index you use in your dasboard?

> [@TimV](#):
>
> Does your role provide read access to the `.kibana` index?

I reas the above as @hugohendriks reverted from trying to define a custom dashboard only role to using `kibana_dashboard_only_user` instead, so that wouldn't be necessary.

> Unless you actually provide the role definition then we're just guessing.

I couldn't agree more. Please help us assist you in a productive manner.

---

<div class="post-metadata">

**Author:** ![hugohendriks](https://avatars.discourse-cdn.com/v4/letter/h/a6a055/32.png) [@hugohendriks](https://discuss.elastic.co/u/hugohendriks)\
**Post date:** [August 20, 2018, 12:58pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/8 "2018-08-20T12:58:46Z")

</div>

Hi,

not trying to be rude...I'm just new to Kibana. My role definition looks like:

 ![dasboard_role](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75e84acbb54b802c22939f040828d4d4d3e12c8e.jpeg)

As you can see, i dont have rights added to acces .kibana index.

My readonly user now has 2 roles, kibana\_dashboard\_only\_user and vgz\_dashboard\_only\_user

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [August 20, 2018, 1:13pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/9 "2018-08-20T13:13:12Z")

</div>

The issue is that you're missing the value for `Granted Fields`. The default value is a wildcard `*` matching all fields. If you take this away (as you've done above), your role doesn't grant read access to any fields, and your dashboard will remain empty.

Add `*` to the `Granted Fields` and login again as the user with the `vgz_dashboard_only_user_role`

> [@hugohendriks](#):
>
> not trying to be rude...I'm just new to Kibana. My role definition looks like:

No worries 🙂 It's just that it's so much easier to offer meaningful feedback when we get all the necessary information as was perfectly showcased in your last message !

---

<div class="post-metadata">

**Author:** ![hugohendriks](https://avatars.discourse-cdn.com/v4/letter/h/a6a055/32.png) [@hugohendriks](https://discuss.elastic.co/u/hugohendriks)\
**Post date:** [August 20, 2018, 1:21pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/10 "2018-08-20T13:21:18Z")

</div>

Check....adding the \* to the Granted Fields did the trick. Much appreciated 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2018, 1:21pm UTC](https://discuss.elastic.co/t/readonly-dashboard-user-in-elastic-cloud-not-working/144514/11 "2018-09-17T13:21:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
