I'm trying to grant a role access to use Elasticsearch Query as an alert type. The users with that role are unable to see the Elasticsearch Query when they go to create a new alert in Kibana.
I can see it but I have the super user role. The role has the following permissions:
Might you be running 7.12.0 by any chance?
There was a bug in that version which we fixed in 7.12.1 which would have caused this.
Upgrading to that patch version (or ideally, if you can, the latest) should ensure this behaves correctly.
For the record - all the user would need is the "all" privilege to the "Stack Alerts" feature, as that would allow them to create ES Query rule types.
Their rule types (alerts) will be able to query any ES index you grant them access to.
Thanks so much for the quick response. We were running 7.12.0 in ES Cloud and have now bumped up to 7.14 and the users in the role can now see Elasticsearch Query as an alert type.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.