# Role privileges issue in elasticserach

**URL:** <https://discuss.elastic.co/t/role-privileges-issue-in-elasticserach/171673>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 11, 2019, 6:41am UTC](https://discuss.elastic.co/t/role-privileges-issue-in-elasticserach/171673 "2019-03-11T06:41:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![B123](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@B123](https://discuss.elastic.co/u/B123)\
**Post date:** [March 11, 2019, 6:41am UTC](https://discuss.elastic.co/t/role-privileges-issue-in-elasticserach/171673/1 "2019-03-11T06:41:49Z")

</div>

Hi,  
I have assigned the privilege **monitor** to a role in elasticserach . As provided in the documentation of elasticsearch the monitor privilege - Can access all cluster read-only operations, like cluster health and settings etc.  
The **\_cluster/settings** gets the cluster settings. I want to block the user having monitor privilege from accessing the above API. .  
Please let me know how i can block the privilege **monitor** from accessing the details present inside **\_cluster/settings**.

Thanks in Advance.

---

<div class="post-metadata">

**Author:** ![Yogesh\_Gaikwad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yogesh_gaikwad/32/27025_2.png) [@Yogesh\_Gaikwad](https://discuss.elastic.co/u/Yogesh_Gaikwad)\
**Post date:** [March 20, 2019, 1:59am UTC](https://discuss.elastic.co/t/role-privileges-issue-in-elasticserach/171673/2 "2019-03-20T01:59:45Z")

</div>

Hi @B123,

Cluster settings (persistent and transient) are queried from the cluster state.  
So if you want to block user from having a monitor privilege just on `_cluster/settings` but have access to cluster state would not be possible.  
To block user from accessing cluster state (including `cluster/settings`) you can create a custom role:

```auto
POST /_xpack/security/role/custom_role '{ "cluster": ["cluster:monitor/task", "cluster:monitor/health", "cluster:monitor/nodes/*", "cluster:monitor/tasks/*", "cluster:monitor/main", "cluster:monitor/stats", "cluster:monitor/allocation/*", "cluster:monitor/remote/*"] }'

```

Note it does not have privilege: `cluster:monitor/state`

Or you could use pre-built role `monitoring_user`

You will need to see what version of ES you are on and then decide on the privileges list.

Hope this is helpful.

Regards,  
Yogesh Gaikwad

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2019, 2:09am UTC](https://discuss.elastic.co/t/role-privileges-issue-in-elasticserach/171673/3 "2019-04-17T02:09:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
