# User can view reports created by other users

**URL:** <https://discuss.elastic.co/t/user-can-view-reports-created-by-other-users/372778>\
**Category:** Kibana\
**Created:** [January 3, 2025, 10:47pm UTC](https://discuss.elastic.co/t/user-can-view-reports-created-by-other-users/372778 "2025-01-03T22:47:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JesusGM](https://avatars.discourse-cdn.com/v4/letter/j/c4cdca/32.png) [@JesusGM](https://discuss.elastic.co/u/JesusGM)\
**Post date:** [January 3, 2025, 10:47pm UTC](https://discuss.elastic.co/t/user-can-view-reports-created-by-other-users/372778/1 "2025-01-03T22:47:14Z")

</div>

Hi,

I've noticed that I can only view the reports I've created. Is there a way to access reports created by other users in Kibana?

---

<div class="post-metadata">

**Author:** ![Musab\_Dogan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/musab_dogan/32/70691_2.png) [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Post date:** [January 4, 2025, 3:54pm UTC](https://discuss.elastic.co/t/user-can-view-reports-created-by-other-users/372778/2 "2025-01-04T15:54:26Z")

</div>

In self-managed and Cloud hosted deployments, reports are stored in Elasticsearch.

> **[Reporting and sharing | Kibana Guide \[8.17\] | Elastic](https://www.elastic.co/guide/en/kibana/current/reporting-getting-started.html)**

To check who created the reports you can use the following API call.

```auto
GET .reporting-*/_search
{
  "size": 0,
  "aggs": {
    "NAME": {
      "terms": {
        "field": "created_by"
      }
    }
  }
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c8458e7a35abcde8a0335777c20380dd8f20b0c.jpeg)

Each user can access their own reports. It's controlled by `created_by` field value in the `reporting.*` indices. Because `reporting.*` are the system indices you can't edit them by default users and roles.

> **You can create a role to access system indices, but this is definitely not recommended**. If you still want to use it, I am sharing the method below.

```auto
#create user to access system indices
PUT _security/role/super_duper_user
{
  "indices": [
    {
      "names": ["*"],
      "privileges": ["all"],
      "allow_restricted_indices": true
    }
  ]
}

PUT _security/user/musab
{
  "password": "REDACTED",
  "roles": ["superuser", "super_duper_user"]
}

```

```auto
#create an ingest pipeline to update created_by value.
PUT _ingest/pipeline/add_user_to_created_by
{
  "description": "Add musab to created_by field using a script",
  "processors": [
    {
      "script": {
        "source": """
          if (ctx.created_by == null) {
            ctx.created_by = ['musab'];
          } else if (ctx.created_by instanceof String) {
            ctx.created_by = [ctx.created_by, 'musab'];
          } else if (!ctx.created_by.contains('musab')) {
            ctx.created_by.add('musab');
          }
        """
      }
    }
  ]
}

#login with musab user and run the below command. Make sure that `"updated": X` has some value except 0.
POST .reporting-*/_update_by_query?pipeline=add_user_to_created_by

```

After run the `update_by_query` command the `musab` user can access any reports.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c26544a763a5e631514b434c0794a361ba43ada.jpeg)
