# XpackSecurity

**URL:** <https://discuss.elastic.co/t/xpacksecurity/87917>\
**Category:** Elasticsearch\
**Created:** [June 1, 2017, 1:55pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917 "2017-06-01T13:55:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 1, 2017, 1:55pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917/1 "2017-06-01T13:55:43Z")

</div>

Hi All,  
I registered for Xpack security Elearning video ,I followed exactly how they demonstrated and I created a same regular use for testing purpose to check if it works for me

I created a regular role with only index and read access to one index,and then i created a regular user, added this regular role to it.

To confirm if works,i logged out from elastic user and I logged in to regular user.

Iam able to login but when i clicked on dev tools to see if i can get or read that index but am getting this error

Config: Error 403 Forbidden: [security\_exception] action [indices:data/write/update] is unauthorized for user [regular]

and am not even tried to delete , i know if I delete the documents in indexes I will get 403 exception error but am not even able to get in dev tools .

Please anyone let me know what has to be done

Thanks in advance,  
Raj

---

<div class="post-metadata">

**Author:** ![Mike.Barretta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike.barretta/32/16688_2.png) [@Mike.Barretta](https://discuss.elastic.co/u/Mike.Barretta)\
**Post date:** [June 1, 2017, 3:15pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917/2 "2017-06-01T15:15:45Z")

</div>

Can you share the output of:

```auto
GET /_xpack/security/role

```

and

```auto
GET /_xpack/security/user

```

?

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 1, 2017, 4:45pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917/3 "2017-06-01T16:45:36Z")

</div>

GET /\_xpack/security/role

Sorry its bit long 🙂

{  
"watcher\_admin": {  
"cluster": [  
"manage\_watcher"  
],  
"indices": [  
{  
"names": [  
".watches",  
".triggered\_watches",  
".watcher-history-_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"logstash\_system": {  
"cluster": [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"kibana\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".kibana_"  
],  
"privileges": [  
"manage",  
"read",  
"index",  
"delete"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"machine\_learning\_user": {  
"cluster": [  
"monitor\_ml"  
],  
"indices": [  
{  
"names": [  
".ml-anomalies\*",  
".ml-notifications"  
],  
"privileges": [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"remote\_monitoring\_agent": {  
"cluster": [  
"manage\_index\_templates",  
"manage\_ingest\_pipelines",  
"monitor",  
"cluster:admin/xpack/watcher/watch/get",  
"cluster:admin/xpack/watcher/watch/put",  
"cluster:admin/xpack/watcher/watch/delete"  
],  
"indices": [  
{  
"names": [  
".marvel-es-_",  
".monitoring-_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"machine\_learning\_admin": {  
"cluster": [  
"manage\_ml"  
],  
"indices": [  
{  
"names": [  
".ml-_"  
],  
"privileges": [  
"view\_index\_metadata",  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"watcher\_user": {  
"cluster": [  
"monitor\_watcher"  
],  
"indices": [  
{  
"names": [  
".watches",  
".watcher-history-_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"monitoring\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".marvel-es-_",  
".monitoring-_"  
],  
"privileges": [  
"read"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"reporting\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
".reporting-_"  
],  
"privileges": [  
"read",  
"write"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"kibana\_system": {  
"cluster": [  
"monitor",  
"cluster:admin/xpack/monitoring/bulk"  
],  
"indices": [  
{  
"names": [  
".kibana_",  
".reporting-_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"transport\_client": {  
"cluster": [  
"transport\_client"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"superuser": {  
"cluster": [  
"all"  
],  
"indices": [  
{  
"names": [  
"_"  
],  
"privileges": [  
"all"  
]  
}  
],  
"run\_as": [  
"_"  
],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"ingest\_admin": {  
"cluster": [  
"manage\_index\_templates",  
"manage\_pipeline"  
],  
"indices": [],  
"run\_as": [],  
"metadata": {  
"\_reserved": true  
},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"regular\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
"logstash\_netflow-_"  
],  
"privileges": [  
"index",  
"read"  
],  
"field\_security": {  
"grant": [  
"_"  
]  
}  
}  
],  
"run\_as": [],  
"metadata": {},  
"transient\_metadata": {  
"enabled": true  
}  
},  
"advanced\_user": {  
"cluster": [],  
"indices": [  
{  
"names": [  
"logstash\_netflow-_"  
],  
"privileges": [  
"write"  
],  
"field\_security": {  
"grant": [  
"\*"  
]  
}  
}  
],  
"run\_as": [],  
"metadata": {},  
"transient\_metadata": {  
"enabled": true  
}  
}  
}

GET /\_xpack/security/user

{  
"elastic": {  
"username": "elastic",  
"roles": [  
"superuser"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
},  
"kibana": {  
"username": "kibana",  
"roles": [  
"kibana\_system"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
},  
"logstash\_system": {  
"username": "logstash\_system",  
"roles": [  
"logstash\_system"  
],  
"full\_name": null,  
"email": null,  
"metadata": {  
"\_reserved": true  
},  
"enabled": true  
},  
"regular": {  
"username": "regular",  
"roles": [  
"regular\_user"  
],  
"full\_name": "Regular User",  
"email": "regular@company.net",  
"metadata": {},  
"enabled": true  
},  
"advanced": {  
"username": "advanced",  
"roles": [  
"advanced\_user",  
"regular\_user"  
],  
"full\_name": "Advanced User",  
"email": "advanced@company.net",  
"metadata": {},  
"enabled": true  
}  
}

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [June 1, 2017, 5:55pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917/4 "2017-06-01T17:55:59Z")

</div>

Hi Raj,

Are you trying to use the `regular` user in Kibana? If yes, you will need to also assign that user the `kibana_user` role.

Thanks,  
Steve

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 1, 2017, 8:04pm UTC](https://discuss.elastic.co/t/xpacksecurity/87917/5 "2017-06-01T20:04:34Z")

</div>

Hi Skearns,

Thanks for the quick and fast info and sorry for the confusion ,actually in the video it was not mentioned to add kibana\_user

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/a/daa05b51e65107b531270a7e66597672812bdcd2.jpg)

Now after adding kibana\_user role to regular user am able to access Dev tools, now I was trying to PUT a new index to test  
but am getting this message

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e2b7293640832172c504b8dc13e3019ab8554bd0.png)

and then I tried to add to one more privilege to it create\_index

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/9/d9afc92adb2b04a7a90a9407e907b1f21c496d1c.png)

still when I PUT new index same error message.

Please do let me know what has to be done.

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [June 2, 2017, 1:29am UTC](https://discuss.elastic.co/t/xpacksecurity/87917/6 "2017-06-02T01:29:21Z")

</div>

Hi Raj,

The create\_index privilege is an index-level privilege (meaning you have to create a role that grants you `create_index` privileges on the index you want to create).

From your role definition there, you have granted privileges to create indexes that begin with `logstash_netflow`, because you added the `create_index` privilege to the `logstash_netflow*` index.

So if you want the ability to create an index called `course_index`, you will need to click the blue `+` button next to Granted Fields, to add another "Index Privilege" section, where you can enter `course_index` as the index name (don't worry that the index name type-ahead doesn't find it - it hasn't yet been created!), then add the read/write/create\_index privileges.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [June 2, 2017, 8:34am UTC](https://discuss.elastic.co/t/xpacksecurity/87917/7 "2017-06-02T08:34:02Z")

</div>

Hi Skearns,

Thank you so much for the info and it works 🙂

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2017, 8:34am UTC](https://discuss.elastic.co/t/xpacksecurity/87917/8 "2017-06-30T08:34:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
