# Unable to Modify Roles for 'kibana' User

**URL:** <https://discuss.elastic.co/t/unable-to-modify-roles-for-kibana-user/79309>\
**Category:** Kibana\
**Created:** [March 20, 2017, 7:30pm UTC](https://discuss.elastic.co/t/unable-to-modify-roles-for-kibana-user/79309 "2017-03-20T19:30:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jt1234](https://avatars.discourse-cdn.com/v4/letter/j/bc8723/32.png) [@jt1234](https://discuss.elastic.co/u/jt1234)\
**Post date:** [March 20, 2017, 7:30pm UTC](https://discuss.elastic.co/t/unable-to-modify-roles-for-kibana-user/79309/1 "2017-03-20T19:30:27Z")

</div>

Hello,

I'm setting up a test cluster for evaluation. I am installing using RPM / yum, using the instructions in the documentation, keeping most settings default, and using the latest versions of the software (ElasticSearch + Kibana + X-Pack). All services run on the same VM, iptables is disabled, and there is no proxy between myself and the VM.

When we login to Kibana and click on Monitoring we receive the following error:

```
You are not authorized to access Monitoring. To use Monitoring, you need the privileges granted by both the `kibana_user` and `monitoring_user` roles.
If you are attempting to access a dedicated monitoring cluster, this might be because you are logged in as a user that is not configured on the monitoring cluster.

```

I created the following JSON file, ran the following CURL command, and entered the password when prompted:

```
{
  "roles" : ["kibana_system", "kibana_user", "monitoring_user"]
}

curl -u elastic --data '@/root/myfile.txt' http://my-host-here:9200/_shield/user/kibana

```

The response I receive is:

```
{"error":{"root_cause":[{"type":"action_request_validation_exception","reason":"Validation Failed: 1: 
Username [kibana] is reserved and may not be 
used.;"}],"type":"action_request_validation_exception","reason":"Validation Failed: 1: Username [kibana] is 
reserved and may not be used.;"},"status":400}

```

According to [the native realm documentation](https://www.elastic.co/guide/en/shield/current/native-realm.html#managing-native-users) it says

```
If you are updating a user, you can omit the password field unless you want to change the user’s password. You must specify the user’s roles. Omitting the optional full_name, email, or metadata fields sets those values to null.

```

I'm not sure why my curl is failing. How do I add 'kibana' to these roles so kibana can talk to ES?

Thanks in advance for your time!

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 21, 2017, 8:31pm UTC](https://discuss.elastic.co/t/unable-to-modify-roles-for-kibana-user/79309/2 "2017-03-21T20:31:30Z")

</div>

The `kibana` user is a reserved system user which cannot be modified. If you choose a different username for your user, it should work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2017, 8:31pm UTC](https://discuss.elastic.co/t/unable-to-modify-roles-for-kibana-user/79309/3 "2017-04-18T20:31:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
