# Using Kibana 4 with Shield: Auth problem

**URL:** <https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 5, 2015, 3:38am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841 "2015-08-05T03:38:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [August 5, 2015, 3:38am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/1 "2015-08-05T03:38:57Z")

</div>

Hi All,

I refer to 'using kibana 4 with shield steps ([Using Kibana with Shield | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/kibana.html#kibana4-user-role))' to practice kibana with shield, but got some error log after I restart Kibana

**MY ENV (Elasticsearch Cluster: 1 master (140.92.25.126) 1 node (140.92.25.161) ; (Kibana 140.92.25.95)**

> {"name":"Kibana","hostname":"kibana","pid":53218,"level":60,"err":{"message":"RemoteTransportException[[enode1][inet[/140.92.25.161:9301]][cluster:monitor/health]]; nested: AuthorizationException[action [cluster:monitor/health] is unauthorized for user [franky]]; ","name":"Error","stack":"Error: RemoteTransportException[[enode1][inet[/140.92.25.161:9301]][cluster:monitor/health]]; nested: AuthorizationException[action [cluster:monitor/health] is unauthorized for user [franky]]; \n at respond (/var/www/html/kibana/src/node\_modules/elasticsearch/src/lib/transport.js:235:15)\n at checkRespForFailure (/var/www/html/kibana/src/node\_modules/elasticsearch/src/lib/transport.js:203:7)\n at HttpConnector. (/var/www/html/kibana/src/node\_modules/elasticsearch/src/lib/connectors/http.js:156:7)\n at IncomingMessage.bound (/var/www/html/kibana/src/node\_modules/elasticsearch/node\_modules/lodash-node/modern/internals/baseBind.js:56:17)\n at IncomingMessage.emit (events.js:117:20)\n at \_stream\_readable.js:944:16\n at process.\_tickCallback (node.js:442:13)"},"msg":"","time":"2015-08-05T03:19:19.586Z","v":0}

@ Elasticsearch Master I did  
$/usr/share/elasticsearch/bin/shield/esusers useradd franky -r kibana4\_monitoring -p password

@ Elasticsearch Master I added following content to roles.yml

```
kibana4_monitoring:
  cluster:
      - cluster:monitor/nodes/info
      - cluster:monitor/health
  indices:
    'logstash-*':
      - indices:admin/mappings/fields/get
      - indices:admin/validate/query
      - indices:data/read/search
      - indices:data/read/msearch
      - indices:admin/get
    '.kibana':
      - indices:admin/create
      - indices:admin/exists
      - indices:admin/mapping/put
      - indices:admin/mappings/fields/get
      - indices:admin/refresh
      - indices:admin/validate/query
      - indices:data/read/get
      - indices:data/read/mget
      - indices:data/read/search
      - indices:data/write/delete
      - indices:data/write/index
      - indices:data/write/update

```

@ Kibana, I modify kibana.yml

```
kibana_elasticsearch_username: franky
kibana_elasticsearch_password: password

```

Seems I missing something to configure?

Jason

---

<div class="post-metadata">

**Author:** ![PatrickKik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrickkik/32/619_2.png) [@PatrickKik](https://discuss.elastic.co/u/PatrickKik)\
**Post date:** [August 5, 2015, 4:49am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/2 "2015-08-05T04:49:56Z")

</div>

Looks good, actually. Some things that come to mind:  
Do you have more than one nodes in your cluster? Shield (and its config) should be installed on every node in your cluster.  
Did you restart your node after installing Shield?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [August 5, 2015, 5:34am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/3 "2015-08-05T05:34:45Z")

</div>

Hi Jason,

What versions of ES and Shield are you using?

It looks like you have installed ES using the RPM or Deb package.. Sometimes, when installing this way, people run into issues with setting the correct ES config directory path or file permissions when running the esusers utility. You should make sure that you have the ES config directory set correctly for the linux user you are running the esusers script with, and that the ES service (usually running as the `elasticsearch` user) has access to the files. Also see:

[https://www.elastic.co/guide/en/shield/current/installing-shield.html#deb-rpm-install](https://www.elastic.co/guide/en/shield/current/installing-shield.html#deb-rpm-install)

Hope that helps!  
Steve

---

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [August 5, 2015, 6:01am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/4 "2015-08-05T06:01:28Z")

</div>

Hi Patrick,

thanks for your replying, after restarting elasticsearch master and node, the user franky can be used

---

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [August 5, 2015, 6:08am UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/5 "2015-08-05T06:08:14Z")

</div>

Hi Steve,

ES- 1.6  
Shield- 1.3.1

After restarting all nodes of elasticsearch cluster, the new user franky can be used normally, thanks.

As the document ([Using Kibana with Shield | Shield [2.4] | Elastic](https://www.elastic.co/guide/en/shield/current/kibana.html#kibana4-server-role)) said

> For example, the following kibana4\_monitoring role only allows users to discover and visualize data in the logstash-\* indices.

there are two indices "logstash-_" and "franky-_", **both two the user franky can access normally** , it shall be not correct?

Jason

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/using-kibana-4-with-shield-auth-problem/26841/6 "2017-07-06T13:48:38Z")

</div>


