# Security roles

**URL:** <https://discuss.elastic.co/t/security-roles/221981>\
**Category:** Elasticsearch\
**Created:** [March 4, 2020, 5:03am UTC](https://discuss.elastic.co/t/security-roles/221981 "2020-03-04T05:03:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sentient](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sentient/32/34996_2.png) [@sentient](https://discuss.elastic.co/u/sentient)\
**Post date:** [March 4, 2020, 5:03am UTC](https://discuss.elastic.co/t/security-roles/221981/1 "2020-03-04T05:03:28Z")

</div>

what is the minimal security role permission a user would need to access the  
\_cluster/health api

when I just look at the documentation [https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-roles.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-roles.html)  
I find it difficult to digest what is, and what is not exactly covered.

My initial thought was 'monitoring\_user' but that did not work.

Using 'superuser' worked, but that seems a bit too much.

Is there some better documentation on the permissions? If it is not in a standard role, what would I have to grant access on a custom role to achieve this

Thanks

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [March 4, 2020, 6:53am UTC](https://discuss.elastic.co/t/security-roles/221981/2 "2020-03-04T06:53:32Z")

</div>

Hi,

I guess you were looking for the privilege monitor:

> All cluster read-only operations, like cluster health and state, hot threads, node info, node and cluster stats, and pending cluster tasks.

So you would have to create a new role which has the cluster privilege of **monitor**.

More details here: [Security privileges | Elasticsearch Guide [7.6] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/security-privileges.html)

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![sentient](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sentient/32/34996_2.png) [@sentient](https://discuss.elastic.co/u/sentient)\
**Post date:** [March 4, 2020, 3:48pm UTC](https://discuss.elastic.co/t/security-roles/221981/3 "2020-03-04T15:48:29Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2020, 3:48pm UTC](https://discuss.elastic.co/t/security-roles/221981/4 "2020-04-01T15:48:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
