# Roles to support lowest privilege

**URL:** <https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 15, 2021, 3:26pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216 "2021-11-15T15:26:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [November 15, 2021, 3:26pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/1 "2021-11-15T15:26:13Z")

</div>

Hi,

I'd like to have a user configured in kibana/elastic that has limited permissions. In this case the user should be able to insert data into elastic.

I believe that this will require a role. What I do not understand, cannot find are the permissions to attach to the role to give the required permissions?

Thanks

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [November 15, 2021, 4:52pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/2 "2021-11-15T16:52:47Z")

</div>

If you open the "Create role" UI (stack management \> roles the "create role" button, you can attach Elasticsearch and Kibana privileges to the role:

 ![Screenshot 2021-11-15 at 17.50.37](https://us1.discourse-cdn.com/elastic/original/3X/e/d/eda31f55696a95897cdd54d3ee15e0d3e20f9f27.png)

The you will need to attach this role to a user to give them the privileges. Keep in mind that they are always additive, this means if a user has two roles, one with all privileges and one without any, they will be able to do everything because the two sets of privileges are merged.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [November 16, 2021, 10:54am UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/3 "2021-11-16T10:54:43Z")

</div>

> [@tractor\_boy](#):
>
> What I do not understand, cannot find are the permissions to attach to the role to give the required permissions?

Is this documented anywhere? or can someone define what the minimum required permissions are?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [November 16, 2021, 1:57pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/4 "2021-11-16T13:57:42Z")

</div>

There are no "minimum permissions" - you can freely configure what parts of Kibana and Elasticsearch are accessible for a user. The documentation can be found here: [Security | Kibana Guide [7.15] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-security.html)

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [November 16, 2021, 2:58pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/5 "2021-11-16T14:58:30Z")

</div>

maybe I am not being clear. I need to know what the minimum permission requirements are such that the user that uses that role would be able to insert data into elastic but nothing more.

So consider an empty elastic data store.

I add some metrics in metricbeat, the user configured in metricbeat then connects into elastic and inserts that data without error. I however cannot use that user to query those metrics. Ie least privilege.

What I do not understand and cannot find as the permissions that I add to a role that would meet this scenario.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 16, 2021, 3:04pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/6 "2021-11-16T15:04:52Z")

</div>

> **[Grant privileges and roles needed for publishing | Metricbeat Reference \[7.15\]...](https://www.elastic.co/guide/en/beats/metricbeat/current/privileges-to-publish-events.html)**

> **[Grant privileges and roles needed to read Metricbeat data from Kibana |...](https://www.elastic.co/guide/en/beats/metricbeat/current/kibana-user-privileges.html)**

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [November 17, 2021, 12:11pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/7 "2021-11-17T12:11:14Z")

</div>

I didn't understand the setup section in the docs but created a role and a user and it seems to be happily populating elastic, so thanks for the link. I can now do the same for the other beats, and I assume logstash.

---

<div class="post-metadata">

**Author:** ![tractor\_boy](https://avatars.discourse-cdn.com/v4/letter/t/278dde/32.png) [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Post date:** [November 18, 2021, 11:25am UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/8 "2021-11-18T11:25:06Z")

</div>

This morning I am getting an error  
[publisher\_pipeline\_output] pipeline/output.go:154 Failed to connect to backoff(Elasticsearch(...): Connection marked as failed because the onConnect callback failed: error loading template: failed to load template: couldn't load template: 403 Forbidden:...... this action is granted by the cluster privileges manage\_index\_templates,manage,all]"}]

This wasn't in your instructions, so what am I missing/mis understanding?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 18, 2021, 4:55pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/9 "2021-11-18T16:55:58Z")

</div>

> [@tractor\_boy](#):
>
> [publisher\_pipeline\_output] pipeline/output.go:154 Failed to connect to backoff(Elasticsearch(...): Connection marked as failed because the onConnect callback failed: error loading template: failed to load template: couldn't load template: 403 Forbidden:...... this action is granted by the cluster privileges manage\_index\_templates,manage,all]"}]

What does your filebeat config look like?

Did you run setup again, that error says that it could not load the template.  
Which if you wanted to be very explicit would be the setup role.

> **[Grant privileges and roles needed for setup | Metricbeat Reference \[8.11\] |...](https://www.elastic.co/guide/en/beats/metricbeat/current/privileges-to-setup-beats.html)**

But I suspect you still have template loading enabled (which after you run setup once you could disable) or you could disable template loading which many do for the actual beats running .. this prevents accidental overwriting of the template...

`setup.template.enabled : false`

> **[Configure Elasticsearch index template loading | Metricbeat Reference \[8.11\]...](https://www.elastic.co/guide/en/beats/metricbeat/current/configuration-template.html#configuration-template)**

So the Meta Process  
Assuming you want all the least privelege

Intall Metricbeat  
Configure for setup  
Run Setup With The Setup User Roles on 1 host

Deploy to other host with template loading disable  
`setup.template.enabled : false`  
Run these with the publishing role.

Right think of setup as Admin

Then all the others will run as publisher... but you need to turn off the template loading.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2021, 4:56pm UTC](https://discuss.elastic.co/t/roles-to-support-lowest-privilege/289216/10 "2021-12-16T16:56:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
