# XPACK -Security

**URL:** <https://discuss.elastic.co/t/xpack-security/80967>\
**Category:** Elasticsearch\
**Created:** [April 3, 2017, 8:37am UTC](https://discuss.elastic.co/t/xpack-security/80967 "2017-04-03T08:37:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [April 3, 2017, 8:37am UTC](https://discuss.elastic.co/t/xpack-security/80967/1 "2017-04-03T08:37:30Z")

</div>

Hi All,

We have purchased Xpack and we have upgraded to new version to 5.3 ,Just want to know if there is any way to restrict dashboard users like read only access to the dashboards created in the kibana. So that they could play around but they cant edit or delete the visualisations created.

Please let me know if anyone has suggestion on it .

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [April 3, 2017, 2:25pm UTC](https://discuss.elastic.co/t/xpack-security/80967/2 "2017-04-03T14:25:56Z")

</div>

Hi Raj,

Yes, you can create a role that is similar to the `kibana_user` role, but only grants read (not write) access to the `.kibana` index. That will allow the user to access KIbana and see visualizations/dashboards, but not save them.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [April 4, 2017, 11:19am UTC](https://discuss.elastic.co/t/xpack-security/80967/3 "2017-04-04T11:19:04Z")

</div>

Thank you for the response , before I do that i just logged in to kibana user to confirm if am able to see dashboard in the kibana user , but all the dashboard values are zero

![](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af73f5c4656e9466b48e85db7e544f650530a073.png)

only if iam using superuser am able to see the dashboard

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [April 4, 2017, 11:33am UTC](https://discuss.elastic.co/t/xpack-security/80967/4 "2017-04-04T11:33:29Z")

</div>

Hi Raj,

Your non-super-user account must have the `kibana_user` role (or the read-only version of this that I described above), _and_ another role that grants read access to the actual indexes that contain the data.

From your screenshot, it looks like your current user doesn't have access to any data.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [April 4, 2017, 11:48am UTC](https://discuss.elastic.co/t/xpack-security/80967/5 "2017-04-04T11:48:34Z")

</div>

Hi Skearn,

Thank alot for the very quick response,

I created a new role naming New1

it looks like this

 ![](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7f42c7457b760a23c8c0c04547d83997f0c7513.png)

I copied the same from the kibana user which looks like the same except delete option which i removed it

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2b91e8f6383f11663f291d36aeda7c7be84e440d.png)

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [April 4, 2017, 11:59am UTC](https://discuss.elastic.co/t/xpack-security/80967/6 "2017-04-04T11:59:33Z")

</div>

Am i doing any mistakes ,please do let me know 🙂

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [April 4, 2017, 9:45pm UTC](https://discuss.elastic.co/t/xpack-security/80967/7 "2017-04-04T21:45:27Z")

</div>

Hi Raj,

As I mentioned, your user will need to be assigned 2 roles:

1. The read-only version of the `kibana_user` role, which it looks like you successfully created and called `New1`.
2. A new role that grants permission to the indexes that contain the data you want that user to be able to see. In your case, this is the data that is being displayed on the dashboard you showed the screenshot of earlier.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [April 5, 2017, 12:30pm UTC](https://discuss.elastic.co/t/xpack-security/80967/8 "2017-04-05T12:30:55Z")

</div>

Hi Steve,

Thank you for being patience with me ,since we are new to Xpack its taking some time to learn

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/0/3068e3b13771fcb3c685587a907967eb5035e30a.png)

So Now we created a user (test) - he has two roles added one is New 1 and New 2

New 1 looks like this

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/f/efc9f3dbe61c6fe25b2ce10fbc5adcfff5b1e564.png)

New 2 looks like this

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/1/319107d1e521d1558d1c5f22852d881cf131bd1a.png)

i nead test user to see the data in logstash\_netflow indexes

Are we good to go?

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2017, 12:31pm UTC](https://discuss.elastic.co/t/xpack-security/80967/9 "2017-05-03T12:31:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
