# Role Management - Access to 1 index only

**URL:** <https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763>\
**Category:** Elasticsearch\
**Created:** [May 29, 2018, 10:55pm UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763 "2018-05-29T22:55:09Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tiagoverissimo](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@tiagoverissimo](https://discuss.elastic.co/u/tiagoverissimo)\
**Post date:** [May 29, 2018, 10:55pm UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/1 "2018-05-29T22:55:09Z")

</div>

Hello,

I'm using Elastic in a PoC and we are tying the 14-day period of X-Pack. One thing that we want to test is the ability to create users/roles and give them access only to the one index, for example.

But I'm facing an issue:

- I'm creating a role with no cluster privileges, access to only 1 index with all privileges to that specific index;
- I create an user called testing with that role only;
- When I try to login, I'm having the following error:

Error 403 Forbidden: action [indices:data/write/update] is unauthorized for user [testing]: [security\_exception] action [indices:data/write/update] is unauthorized for user [testing]

Now - If I add the kibana\_user role I'm able to see all the index that exists on the cluster.

Thanks in advance! 🙂

KR

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [May 30, 2018, 1:41am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/2 "2018-05-30T01:41:53Z")

</div>

Hi @tiagoverissimo,

Could you please show us the config or output of GET `/_xpack/security/role/<rolename>` for the role that you created?

Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 30, 2018, 4:29am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/3 "2018-05-30T04:29:10Z")

</div>

You should be able to query the index if you access Elasticsearch directly through the APIs. If you however want to access the data through Kibana the user also need access to the privileges the kibana\_user role provides.

---

<div class="post-metadata">

**Author:** ![tiagoverissimo](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@tiagoverissimo](https://discuss.elastic.co/u/tiagoverissimo)\
**Post date:** [May 30, 2018, 7:39am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/4 "2018-05-30T07:39:22Z")

</div>

Here it is:

```
{ 
"testing": {
"cluster": [],
"indices": [
  {
    "names": [
      "demo*"
    ],
    "privileges": [
      "all"
    ]
  }
],
"run_as": [],
"metadata": {},
"transient_metadata": {
  "enabled": true
}
}
}

```

Thanks! 😃

---

<div class="post-metadata">

**Author:** ![tiagoverissimo](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@tiagoverissimo](https://discuss.elastic.co/u/tiagoverissimo)\
**Post date:** [May 30, 2018, 7:40am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/5 "2018-05-30T07:40:43Z")

</div>

Hello!

Yeah - I want the user to access through Kibana but with the ability to check only the index that is allowed. Is this possible?

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 30, 2018, 8:04am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/6 "2018-05-30T08:04:16Z")

</div>

The objects that Kibana manages - visualisations, dashboard, index-patterns, etc - are stored in an index in Elasticsearch. You cannot use Kibana unless you have access to that index.

The `kibana_user` role is a predefined role that grants the necessarily permissions to that index, and nothing else.

When you grant that role to the test user, what behaviour are you seeing that is a problem for you?

---

<div class="post-metadata">

**Author:** ![tiagoverissimo](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@tiagoverissimo](https://discuss.elastic.co/u/tiagoverissimo)\
**Post date:** [May 30, 2018, 8:06am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/7 "2018-05-30T08:06:28Z")

</div>

Hello Tim!

Thanks for you answer. Now it is a bit more clear.  
The issue is that I just want that one type of users see one index only - but able to create visualizations on it.

I'm not sure was clear enough, please let me know.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [May 30, 2018, 8:48am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/8 "2018-05-30T08:48:44Z")

</div>

> I just want that one type of users see one index only

Ok, but please answer the question I asked:

- _what behaviour are you seeing that is a problem for you?_

---

<div class="post-metadata">

**Author:** ![tiagoverissimo](https://avatars.discourse-cdn.com/v4/letter/t/df788c/32.png) [@tiagoverissimo](https://discuss.elastic.co/u/tiagoverissimo)\
**Post date:** [May 30, 2018, 9:16am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/9 "2018-05-30T09:16:05Z")

</div>

When I assignate the kibana\_user role to the user I'm able to login and see all the dashboards, visualizations and indexes - all of them.

My goal is allow that user to check and see only the index that I assigned it.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2018, 9:24am UTC](https://discuss.elastic.co/t/role-management-access-to-1-index-only/133763/10 "2018-06-27T09:24:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
