# What role should I attach to anonymous user?

**URL:** <https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 17, 2022, 10:35am UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919 "2022-05-17T10:35:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rachit\_upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rachit_upadhyay/32/102263_2.png) [@rachit\_upadhyay](https://discuss.elastic.co/u/rachit_upadhyay)\
**Post date:** [May 17, 2022, 10:35am UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919/1 "2022-05-17T10:35:22Z")

</div>

So, I am using the Elasticsearch and have the **xpack.security.enabled** as **true**. When I try to open the IP:Port and check the status of Elasticsearch node, I have to authorize myself. I wanted to know is it possible to have this authorization removed with anonymous user feature of xpack?

If it is indeed possible I would like to know what kind of role would I need to provide to the anonymous user so that I wouldn't need to enter the credential and I am able to see the status without any issues.

[Built-in roles | Elasticsearch Guide [7.16] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/built-in-roles.html)  
These are the built-in-roles that I think would be considered but if I have to create a new role do let me know along with it's configuration.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [May 18, 2022, 4:24am UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919/2 "2022-05-18T04:24:18Z")

</div>

This depends what you mean by "check the status of Elasticseaerch node". Exactly what are the APIs you need to call with the anonymous user? You want a role that is tightly scoped for your need for security reasons.

---

<div class="post-metadata">

**Author:** ![rachit\_upadhyay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rachit_upadhyay/32/102263_2.png) [@rachit\_upadhyay](https://discuss.elastic.co/u/rachit_upadhyay)\
**Post date:** [June 2, 2022, 11:05am UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919/3 "2022-06-02T11:05:07Z")

</div>

I am not using any API. I just need to get 200 status code for when I try to call :9200. Nothing else. This is required for the ALB target group setup in aws platform.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [June 2, 2022, 12:48pm UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919/4 "2022-06-02T12:48:23Z")

</div>

> [@rachit\_upadhyay](#):
>
> I am not using any API. I just need to get 200 status code for when I try to call :9200.

Technically that's an API by itself. You need the `monitor` [cluster privilege](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-privileges.html#privileges-list-cluster) for it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2022, 12:48pm UTC](https://discuss.elastic.co/t/what-role-should-i-attach-to-anonymous-user/304919/5 "2022-06-30T12:48:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
