# Unable to choose Elasticsearch Query as Alert Type

**URL:** https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132
**Category:** Kibana
**Tags:** elastic-stack-security, elastic-stack-alerting
**Created:** [August 12, 2021, 12:30am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132 "2021-08-12T00:30:45Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![andrewgodwinB](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@andrewgodwinB](https://discuss.elastic.co/u/andrewgodwinB)
#### Post date: [August 12, 2021, 12:30am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/1 "2021-08-12T00:30:45Z")

</div>

Hi,

I'm trying to grant a role access to use Elasticsearch Query as an alert type. The users with that role are unable to see the Elasticsearch Query when they go to create a new alert in Kibana.

I can see it but I have the super user role. The role has the following permissions:

 ![Screenshot 2021-08-11 at 5.28.22 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf7d096ba85fc7bb4b8de9a633b6629679b3eb3a.png)

 ![Screenshot 2021-08-11 at 5.28.51 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd44029f53f13aee0826b6985db4122663d104db.png)

Does anyone know how I can grant the role access to the Elasticsearch Query as an alert type without giving it keys to the kingdom?

Thanks alot  
Andrew

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [August 12, 2021, 1:51am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/2 "2021-08-12T01:51:19Z")

</div>

Hi @andrewgodwinB Welcome to the community.

Interesting question I poked a couple people on that team see if we can get an answer I don't know the answer right off hand.

I suspect there's a couple system indexes that you need to provide read / write on.

---

<div class="post-metadata">

### Author: ![gmmorris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmorris/32/72624_2.png) [@gmmorris](https://discuss.elastic.co/u/gmmorris)
#### Post date: [August 12, 2021, 8:59am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/3 "2021-08-12T08:59:56Z")

</div>

Hi Andrew,  
Welcome to the community.

Might you be running 7.12.0 by any chance?  
There was [a bug](https://github.com/elastic/kibana/issues/95221) in that version which we fixed in 7.12.1 which would have caused this.  
Upgrading to that patch version (or ideally, if you can, the latest) should ensure this behaves correctly.

For the record - all the user would need is the "all" privilege to the "Stack Alerts" feature, as that would allow them to create ES Query rule types.  
Their rule types (alerts) will be able to query any ES index you grant them access to.

---

<div class="post-metadata">

### Author: ![andrewgodwinB](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@andrewgodwinB](https://discuss.elastic.co/u/andrewgodwinB)
#### Post date: [August 13, 2021, 3:39am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/4 "2021-08-13T03:39:10Z")

</div>

Hi @stephenb and @gmmorris

Thanks so much for the quick response. We were running 7.12.0 in ES Cloud and have now bumped up to 7.14 and the users in the role can now see Elasticsearch Query as an alert type.

Thanks again!

---

<div class="post-metadata">

### Author: ![gmmorris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmorris/32/72624_2.png) [@gmmorris](https://discuss.elastic.co/u/gmmorris)
#### Post date: [August 13, 2021, 8:40am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/5 "2021-08-13T08:40:24Z")

</div>

That's awesome, welcome to the edge 😉

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 10, 2021, 8:40am UTC](https://discuss.elastic.co/t/unable-to-choose-elasticsearch-query-as-alert-type/281132/6 "2021-09-10T08:40:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
