# Way aren't Event details under security using the same query as you put in Elasticsearch indices

**URL:** <https://discuss.elastic.co/t/way-arent-event-details-under-security-using-the-same-query-as-you-put-in-elasticsearch-indices/265044>\
**Category:** Kibana\
**Created:** [February 22, 2021, 9:04am UTC](https://discuss.elastic.co/t/way-arent-event-details-under-security-using-the-same-query-as-you-put-in-elasticsearch-indices/265044 "2021-02-22T09:04:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tellus83](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@tellus83](https://discuss.elastic.co/u/tellus83)\
**Post date:** [February 22, 2021, 9:04am UTC](https://discuss.elastic.co/t/way-arent-event-details-under-security-using-the-same-query-as-you-put-in-elasticsearch-indices/265044/1 "2021-02-22T09:04:01Z")

</div>

I have a soc-filebeat alias whit filter on filebeat-7.11.1-\* and use soc-\* for Elasticsearch indices in settings. And have created a user that have full access to soc-_.  
All dashboards are OK under Security network and security host. But if you click on a event to get event details its blank. if i give access to filebeat-_ to the user you get all the event details.

Way cant the event details use the same soc-\* ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2021, 9:04am UTC](https://discuss.elastic.co/t/way-arent-event-details-under-security-using-the-same-query-as-you-put-in-elasticsearch-indices/265044/2 "2021-03-22T09:04:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
