# "Security Exception for APM Viewer Role in Kibana Spaces - ELK 8.18.0"

**URL:** <https://discuss.elastic.co/t/security-exception-for-apm-viewer-role-in-kibana-spaces-elk-8-18-0/378885>\
**Category:** APM\
**Tags:** ui\
**Created:** [June 5, 2025, 4:04am UTC](https://discuss.elastic.co/t/security-exception-for-apm-viewer-role-in-kibana-spaces-elk-8-18-0/378885 "2025-06-05T04:04:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![flukee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flukee/32/143498_2.png) [@flukee](https://discuss.elastic.co/u/flukee)\
**Post date:** [June 5, 2025, 4:04am UTC](https://discuss.elastic.co/t/security-exception-for-apm-viewer-role-in-kibana-spaces-elk-8-18-0/378885/1 "2025-06-05T04:04:27Z")

</div>

Hi everyone,

I'm using ELK 8.18.0 with a Remote Cluster setup **(APM\_O)** and trying to create a **viewer role** for **APM Service Inventory** , restricted to 1-2 Kibana Spaces. However, I'm facing a **security\_exception error** with my user **test**. I need help resolving this issue.

#### **Problem Details**

**Setup:**

- ELK version: 8.18.0
- Remote Cluster: APM\_O (Connected)
- Data streams on APM\_O: traces-apm\*,logs-apm\*,metrics-apm\*,_:apm-_
- Index example: APM\_O:.ds-traces-apm-default-2025.06.04-000028
- Using Kibana Spaces: Want to limit access to "Space A" and "Space B"

**Goal:**  
I want to create a user **test** with a viewer role to access APM Service Inventory (under Observability \> Applications \> Service Inventory & Traces), but only in "Space A" and "Space B".

**Steps Taken:**

1. Created a Data View:

- Index pattern: APM\_O:traces-apm\*,_:apm-_,APM\_O:logs-apm\*,_:apm-_,APM\_O:metrics-apm\*,_:apm-_ (fine matching sources)
- Timestamp field: @timestamp

1. Created a Role **apm\_O\_viewer** :

- Index Privileges: read, view\_index\_metadata for APM\_O:traces-apm\*,_:apm-_,APM\_O:logs-apm\*,APM\_O:metrics-apm\*,:apm-\*
- Kibana Privileges: Read for "Space A" and "Space B"

1. Created user **test** and assigned the role **apm\_O\_viewer**

**Issue:**

When logging in as **test** and accessing **Service Inventory** & **Traces** , I get the following error:

- _security\_exception: action [indices:data/read/search] is unauthorized for user [test] with effective roles []_
- _`security_exception: action [indices:data/read/field_caps] is unauthorized for user [test] with effective roles []`_

The user was initially assigned roles like Space\_A\_viewer, Space\_B\_viewer, and apm\_O\_viewer, but they seem invalid as the effective roles are empty ().

#### **Specific Questions**

1. Why does the user show "effective roles " even though roles are assigned?
2. How can I properly restrict APM access ( **Service Inventory** & **Traces** ) to specific Kibana Spaces ("Space A" and "Space B") for a viewer role?
3. Are there additional privileges needed for cross-cluster search with APM\_O in ELK 8.18.0?  
_( I've tried created a same **apm\_O\_viewer** role on remote-cluster APM\_O but it's not worked)_

#### **Additional Context**

- Local and remote clusters (APM\_O) use the same security realm.
- Remote Cluster APM\_O is connected (status: Connected, mode: default/proxy).

#### **Closing**

Any help or insights would be greatly appreciated! Thanks in advance for your support.

---

<div class="post-metadata">

**Author:** ![Kate\_Patticha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kate_patticha/32/100078_2.png) [@Kate\_Patticha](https://discuss.elastic.co/u/Kate_Patticha)\
**Post date:** [July 10, 2025, 10:52am UTC](https://discuss.elastic.co/t/security-exception-for-apm-viewer-role-in-kibana-spaces-elk-8-18-0/378885/2 "2025-07-10T10:52:16Z")

</div>

Hello,

To better understand the issue and provide a solution, could you please share a screenshot of the following items? (Feel free to blur any sensitive information.)

- _ **apm\_O\_viewer** _ roles config
- **test** user config page

Can you try to add cross\_cluster\_search privilege to apm\_O\_viewer and check again

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5b97b1bc45456bf724fa936c1b14a6308fe3dde.png)
