# Role that would allow a user to create index in ES

**URL:** <https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 31, 2021, 4:20pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534 "2021-05-31T16:20:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [May 31, 2021, 4:20pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/1 "2021-05-31T16:20:48Z")

</div>

Hi,

I am looking for a role that would allow a user to create indices in ES.

Basically I want to avoid assigning "superuser" role.

Please guide on what role can I assign? My configuration for ELK7.6.2 stack looks like below:

```auto
 elasticsearch {
     hosts => ["xx-xx-xxx:23045"]
     user => "pwatcher"
     password => "xxxxxxxx"
     index => "abcd.pwatcher_events-%{+YYYY.MM.dd}"
     manage_template => true
     template_overwrite => true
     template => "/opt/tal/ptal/elasticsearch/app/logstash/config/pwatcher_template.json"
     template_name => "pwatcher"
  }

```

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [May 31, 2021, 4:28pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/2 "2021-05-31T16:28:44Z")

</div>

Hi,

Were you looking for something like [this](https://www.elastic.co/guide/en/logstash/current/ls-security.html#ls-http-auth-basic)?

```auto
POST _xpack/security/role/logstash_writer
{
  "cluster": ["manage_index_templates", "monitor", "manage_ilm"], 
  "indices": [
    {
      "names": ["abcd.pwatcher_events-*"], 
      "privileges": ["write","create","create_index","manage","manage_ilm"]  
    }
  ]
}

```

This will allow LogStash to write an index

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [May 31, 2021, 5:28pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/3 "2021-05-31T17:28:30Z")

</div>

Thanks. How about reading an index in ES?

is there a read\_index privilege too?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [May 31, 2021, 5:30pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/4 "2021-05-31T17:30:21Z")

</div>

Yes, the privilege is called `read` (see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html) for details

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [May 31, 2021, 9:05pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/5 "2021-05-31T21:05:02Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 9:05pm UTC](https://discuss.elastic.co/t/role-that-would-allow-a-user-to-create-index-in-es/274534/6 "2021-06-28T21:05:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
