# Report on user and the role

**URL:** <https://discuss.elastic.co/t/report-on-user-and-the-role/253531>\
**Category:** Kibana\
**Created:** [October 28, 2020, 8:41am UTC](https://discuss.elastic.co/t/report-on-user-and-the-role/253531 "2020-10-28T08:41:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nameisnotimportant](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@nameisnotimportant](https://discuss.elastic.co/u/nameisnotimportant)\
**Post date:** [October 28, 2020, 8:41am UTC](https://discuss.elastic.co/t/report-on-user-and-the-role/253531/1 "2020-10-28T08:41:20Z")

</div>

Hi,

I am thinking to create a report about user and the role granted.

I know I can run following script in Console to get the list of role mapping, but is there a way to index it so that i can create a Discover or Visualize report ?  
`GET _security/role_mapping`

Or does the audit log keep track of:

1. the person who grant role / access to user? What role being granted ?
2. list of user and the role granted?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 28, 2020, 12:03pm UTC](https://discuss.elastic.co/t/report-on-user-and-the-role/253531/2 "2020-10-28T12:03:04Z")

</div>

Hi,

You could create a LogStash pipeline to ingest the data. Unfortunately, I don't think the elasticsearch input would work as this uses the Search API of Elasticsearch. But you could use the [http\_poller](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-http_poller.html) to poll the role\_mapping API.  
You could even enhance that data by using the [http filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-http.html) to add the role definition to the document before storing it in ElasticSearch.  
Also, you might have internal users which are managed within Kibana so you might want to add the internal users with this role to the document using a separate http filter.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![nameisnotimportant](https://avatars.discourse-cdn.com/v4/letter/n/ea5d25/32.png) [@nameisnotimportant](https://discuss.elastic.co/u/nameisnotimportant)\
**Post date:** [October 30, 2020, 12:22am UTC](https://discuss.elastic.co/t/report-on-user-and-the-role/253531/3 "2020-10-30T00:22:01Z")

</div>

Thanks to Wolfram. That's what i am looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2020, 12:22am UTC](https://discuss.elastic.co/t/report-on-user-and-the-role/253531/4 "2020-11-27T00:22:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
