# anonymous kibana read access by default, while still allowing users to authenticate when needed

**URL:** <https://forum.search-guard.com/t/anonymous-kibana-read-access-by-default-while-still-allowing-users-to-authenticate-when-needed/1316>\
**Category:** Search Guard\
**Created:** [February 5, 2019, 8:16pm UTC](https://forum.search-guard.com/t/anonymous-kibana-read-access-by-default-while-still-allowing-users-to-authenticate-when-needed/1316 "2019-02-05T20:16:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![euphxenos](https://avatars.discourse-cdn.com/v4/letter/e/a6a055/32.png) [@euphxenos](https://forum.search-guard.com/u/euphxenos)\
**Post date:** [February 5, 2019, 8:16pm UTC](https://forum.search-guard.com/t/anonymous-kibana-read-access-by-default-while-still-allowing-users-to-authenticate-when-needed/1316/1 "2019-02-05T20:16:38Z")

</div>

I’d like to set up anonymous access to Kibana such that users can go to [http://myhost.mydomain.com:5601](http://myhost.mydomain.com:5601) and anonymously look at our Kibana dashboards, but they have to click on the login item in the left side menu to log in as the administrator to make changes (and updating the indexes is similarly restricted to a non-anonymous user). I’ve seen a couple of past threads about this:

[https://groups.google.com/forum/#!topic/search-guard/S0Ad5nyVfE4](https://groups.google.com/forum/#!topic/search-guard/S0Ad5nyVfE4)

[https://groups.google.com/forum/?utm\_medium=email&utm\_source=footer#!msg/search-guard/XSaPsyBCl6w/YXENtrrgBwAJ](https://groups.google.com/forum/?utm_medium=email&utm_source=footer#!msg/search-guard/XSaPsyBCl6w/YXENtrrgBwAJ)

And see that this related issue in github is now resolved:

[https://github.com/floragunncom/search-guard-kibana-plugin/issues/88](https://github.com/floragunncom/search-guard-kibana-plugin/issues/88)

But I don’t see anything in the documentation about how to configure anonymous read to not require a login while still allowing users to authenticate. I’ve tried a few variations on what other users tried in the past threads without success. Now that this is supported, what do I need to set in the configuration to enable this?

thanks,

–Andrew

When asking questions, please provide the following information:

- Search Guard and Elasticsearch version

elasticsearch 6.5.3-1

searchguard elasticsearch plugin 6.5.3-23.2

searchguard kibana plugin 6.5.3-17

- Installed and used enterprise modules, if any

none

- JVM version and operating system version

Oracle JVM 1.8.0\_191

CentOS 7

- Search Guard configuration files

- Elasticsearch log messages on debug level

- Other installed Elasticsearch or Kibana plugins, if any

none

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [February 6, 2019, 7:16pm UTC](https://forum.search-guard.com/t/anonymous-kibana-read-access-by-default-while-still-allowing-users-to-authenticate-when-needed/1316/2 "2019-02-06T19:16:17Z")

</div>

Hi,

there are two pages in the docs, the first one is for enabling anon auth in Search Guard:

> **[Search Guard Documentation 404](https://docs.search-guard.com/latest/404.html)**
>
> Seems like the page you are looking for does not exist. We deeply and humbly apologize.

And this one here describes how to enable it in Kibana:

> **[Anonymous authentication](https://docs.search-guard.com/latest/kibana-authentication-anonymous)**
>
> How to configure Kibana to allow anonymous access to indices, dashboards, and visualization

If you want to restrict your anon users to see the “Dashboards” nav entry only, you should add the anonymous backend role described in the first doc to the readonly/dashboards only users in Kibana:

> **[Read Only mode](https://docs.search-guard.com/latest/kibana-read-only)**
>
> Use the Kibana read only mode to give users access to dashboards, but prevent them from accessing anything else.

> **···**
>
> On Tuesday, February 5, 2019 at 9:16:38 PM UTC+1, euphxenos wrote:
> 
> > I’d like to set up anonymous access to Kibana such that users can go to [http://myhost.mydomain.com:5601](http://myhost.mydomain.com:5601) and anonymously look at our Kibana dashboards, but they have to click on the login item in the left side menu to log in as the administrator to make changes (and updating the indexes is similarly restricted to a non-anonymous user). I’ve seen a couple of past threads about this:
> 
> > 
> 
> > [https://groups.google.com/forum/#!topic/search-guard/S0Ad5nyVfE4](https://groups.google.com/forum/#!topic/search-guard/S0Ad5nyVfE4)
> 
> > [https://groups.google.com/forum/?utm\_medium=email&utm\_source=footer#!msg/search-guard/XSaPsyBCl6w/YXENtrrgBwAJ](https://groups.google.com/forum/?utm_medium=email&utm_source=footer#!msg/search-guard/XSaPsyBCl6w/YXENtrrgBwAJ)
> 
> > 
> 
> > And see that this related issue in github is now resolved:
> 
> > 
> 
> > [https://github.com/floragunncom/search-guard-kibana-plugin/issues/88](https://github.com/floragunncom/search-guard-kibana-plugin/issues/88)
> 
> > 
> 
> > But I don’t see anything in the documentation about how to configure anonymous read to not require a login while still allowing users to authenticate. I’ve tried a few variations on what other users tried in the past threads without success. Now that this is supported, what do I need to set in the configuration to enable this?
> 
> > 
> 
> > 
> 
> > thanks,
> 
> > –Andrew
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version
> 
> > elasticsearch 6.5.3-1
> 
> > searchguard elasticsearch plugin 6.5.3-23.2
> 
> > searchguard kibana plugin 6.5.3-17
> 
> > - Installed and used enterprise modules, if any
> 
> > none
> 
> > - JVM version and operating system version
> 
> > Oracle JVM 1.8.0\_191
> 
> > CentOS 7
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > none
