# Errors with accessing the kibana

**URL:** <https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198>\
**Category:** Search Guard\
**Created:** [June 16, 2016, 9:31am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198 "2016-06-16T09:31:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 16, 2016, 9:31am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/1 "2016-06-16T09:31:00Z")

</div>

I have changed the config file sg\_roles.yml

**sg\_apache\_tomcat:**

**indices:**

**‘apache-tomcat-\*’:**

**‘\*’:**

**- ALL**

and the sg\_roles\_mapping.yml:

sg\_apache\_tomcat:

users:

- kirk

and in the kibana.yml, i added the entries

elasticsearch.username: “kibanaserver”

**elasticsearch.password: “kibanaserver”**

And with the command curl -XGET -u kirk:kirk “[http://192.25.97.128:9200/apache-\*?pretty](http://192.25.97.128:9200/apache-*?pretty)” , i can get what i want.

But when i access the kibana with the “kirk”, i got the errors as follow:

```
               Courier Fetch Error: unhandled courier request error: unknown error

```

```auto
    Error: unhandled courier request error: unknown error
at handleError ([http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23) )
at DocRequest.AbstractReqProvider.AbstractReq.handleFailure ([http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15) )
at [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18)
    at Array.forEach (native)
at [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19)
    at processQueue ([http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29) )
at [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28)
    at Scope.$eval ([http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29) )
at Scope.$digest ([http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32) )
at Scope.$apply ([http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25))

```

What’t more, i can access the kibana with the “admin”.

Can you tell me where did i miss?

---

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 16, 2016, 10:53am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/2 "2016-06-16T10:53:33Z")

</div>

the elasticsearch debug is here:

\_closed=false, allow\_alisases\_to\_multiple\_indices=true, forbid\_closed\_indices=true]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] raw indices [.kibana]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] Resolved [.kibana] to {}

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] requested resolved aliases and indices: [.kibana]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] requested resolved types: [config]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] mapped roles: [sg\_kibana4\_server, sg\_public]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] ---------- evaluate sg\_role: sg\_kibana4\_server

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] Try wildcard match for ?kibana

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] Wildcard match for ?kibana: [.kibana]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] matches for ?kibana, will check now types [\*]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] resolvedActions for ?kibana/_: [indices:_]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] match requested action indices:data/read/search against ?kibana/_: [indices:_]

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] remaining requested aliases and indices:

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] remaining requested resolved types:

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] found a match for ‘sg\_kibana4\_server’, evaluate other roles for fls/dls purposes

[2016-06-16 17:26:05,666][DEBUG][com.floragunn.searchguard.configuration.PrivilegesEvaluator] sg\_role sg\_public is empty

---

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 17, 2016, 2:34am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/3 "2016-06-17T02:34:17Z")

</div>

Who can help me solve the problem？ Thanks！

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [June 17, 2016, 7:08pm UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/4 "2016-06-17T19:08:02Z")

</div>

does this work?

sg\_apache\_tomcat:  
&nbsp;&nbsp;cluster:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- cluster:monitor/nodes/info  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- cluster:monitor/health  
&nbsp;&nbsp;indices:  
&nbsp;&nbsp;&nbsp;&nbsp;'apache-tomcat-\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- ALL  
&nbsp;&nbsp;&nbsp;&nbsp;'?kibana':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- READ  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/exists\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/refresh\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/mget\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/search\*

> **···**
>
> > Am 16.06.2016 um 11:31 schrieb Wei Hong \<fzuerhw@gmail.com\>:
> > 
> > I have changed the config file sg\_roles.yml
> > 
> > sg\_apache\_tomcat:  
> > &nbsp;&nbsp;indices:  
> > &nbsp;&nbsp;&nbsp;&nbsp;'apache-tomcat-\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- ALL
> > 
> > and the sg\_roles\_mapping.yml:
> > 
> > sg\_apache\_tomcat:  
> > &nbsp;&nbsp;users:  
> > &nbsp;&nbsp;&nbsp;&nbsp;- kirk
> > 
> > and in the kibana.yml, i added the entries
> > 
> > elasticsearch.username: "kibanaserver"  
> > elasticsearch.password: "kibanaserver"
> > 
> > And with the command curl -XGET -u kirk:kirk "[http://192.25.97.128:9200/apache-\*?pretty&quot](http://192.25.97.128:9200/apache-*?pretty&quot); , i can get what i want.
> > 
> > But when i access the kibana with the "kirk", i got the errors as follow:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Courier Fetch Error: unhandled courier request error: unknown error  
> > Error: unhandled courier request error: unknown error  
> > &nbsp;&nbsp;&nbsp;&nbsp;at handleError (  
> > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23)  
> > )  
> > &nbsp;&nbsp;&nbsp;&nbsp;at DocRequest.  
> > AbstractReqProvider.AbstractReq.handleFailure ([http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15)  
> > )  
> > &nbsp;&nbsp;&nbsp;&nbsp;at  
> > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18)
> > 
> > &nbsp;&nbsp;&nbsp;&nbsp;at Array.forEach (native)  
> > &nbsp;&nbsp;&nbsp;&nbsp;at  
> > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19)
> > 
> > &nbsp;&nbsp;&nbsp;&nbsp;at processQueue (  
> > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29)  
> > )  
> > &nbsp;&nbsp;&nbsp;&nbsp;at  
> > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28)
> > 
> > &nbsp;&nbsp;&nbsp;&nbsp;at Scope.$eval (  
> > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29)  
> > )  
> > &nbsp;&nbsp;&nbsp;&nbsp;at Scope.$digest (  
> > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32)  
> > )  
> > &nbsp;&nbsp;&nbsp;&nbsp;at Scope.$apply (  
> > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25\](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25%5C))
> > 
> > What't more, i can access the kibana with the "admin".
> > 
> > Can you tell me where did i miss?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 20, 2016, 1:24am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/5 "2016-06-20T01:24:13Z")

</div>

Sorry, I added these to the role, it still not work. The errors is

“no permissions for indices:data/read/field\_stats”

then i added the " indices:data/read/field\_stats" behind the “?kibana”

it still not work.

Is there something wrong?

在 2016年6月18日星期六 UTC+8上午3:08:02，SG写道：

> **···**
>
> > does this work?
> > 
> > sg\_apache\_tomcat:
> > 
> > cluster:  
> > - cluster:monitor/nodes/info
> > 
> > ```
> > - cluster:monitor/health
> > 
> > ```
> > 
> > indices:
> > 
> > ```
> > 'apache-tomcat-*':
> > 
> > '*':
> > 
> > - ALL
> > 
> > '?kibana':
> > 
> > '*':
> > 
> > - READ
> > 
> > - indices:admin/mappings/fields/get*
> > 
> > - indices:admin/validate/query*
> > 
> > - indices:admin/get*
> > 
> > - indices:admin/exists*
> > 
> > - indices:admin/mappings/fields/get*
> > 
> > - indices:admin/refresh*
> > 
> > - indices:admin/validate/query*
> > 
> > - indices:data/read/get*
> > 
> > - indices:data/read/mget*
> > 
> > - indices:data/read/search*
> > 
> > ```
> > 
> > > Am 16.06.2016 um 11:31 schrieb Wei Hong [fzu...@gmail.com](mailto:fzu...@gmail.com):
> > 
> > > I have changed the config file sg\_roles.yml
> > 
> > > sg\_apache\_tomcat:
> > 
> > > indices:
> > 
> > > ```
> > > 'apache-tomcat-*':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - ALL
> > > 
> > > ```
> > 
> > > and the sg\_roles\_mapping.yml:
> > 
> > > sg\_apache\_tomcat:
> > 
> > > users:
> > 
> > > ```
> > > - kirk
> > > 
> > > ```
> > 
> > > and in the kibana.yml, i added the entries
> > 
> > > elasticsearch.username: “kibanaserver”
> > 
> > > elasticsearch.password: “kibanaserver”
> > 
> > > And with the command curl -XGET -u kirk:kirk “[http://192.25.97.128:9200/apache-\*?pretty](http://192.25.97.128:9200/apache-*?pretty)” , i can get what i want.
> > 
> > > But when i access the kibana with the “kirk”, i got the errors as follow:
> > 
> > > ```
> > > Courier Fetch Error: unhandled courier request error: unknown error
> > > 
> > > ```
> > > 
> > > Error: unhandled courier request error: unknown error
> > 
> > > ```
> > > at handleError (
> > > 
> > > ```
> > 
> > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23)
> > 
> > > )
> > 
> > > ```
> > > at DocRequest.
> > > 
> > > ```
> > 
> > > AbstractReqProvider.AbstractReq.handleFailure ([http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15)
> > 
> > > )
> > 
> > > ```
> > > at
> > > 
> > > ```
> > > 
> > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18)
> > 
> > > ```
> > > at Array.forEach (native)
> > > 
> > > ```
> > 
> > > ```
> > > at
> > > 
> > > ```
> > > 
> > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19)
> > 
> > > ```
> > > at processQueue (
> > > 
> > > ```
> > 
> > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29)
> > 
> > > )
> > 
> > > ```
> > > at
> > > 
> > > ```
> > > 
> > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28)
> > 
> > > ```
> > > at Scope.$eval (
> > > 
> > > ```
> > 
> > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29)
> > 
> > > )
> > 
> > > ```
> > > at Scope.$digest (
> > > 
> > > ```
> > 
> > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32)
> > 
> > > )
> > 
> > > ```
> > > at Scope.$apply (
> > > 
> > > ```
> > 
> > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25))
> > 
> > > What’t more, i can access the kibana with the “admin”.
> > 
> > > Can you tell me where did i miss?
> > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![1114](https://avatars.discourse-cdn.com/v4/letter/1/77aa72/32.png) [@1114](https://forum.search-guard.com/u/1114)\
**Post date:** [October 16, 2016, 9:06am UTC](https://forum.search-guard.com/t/errors-with-accessing-the-kibana/198/6 "2016-10-16T09:06:07Z")

</div>

I met the same problem , if you add the “indices:data/read/field\_stats” , it will notice “indieces:data/read/mget”  
the config should like this:

sg\_apache\_tomcat:  
cluster:  
- cluster:monitor/nodes/info  
- cluster:monitor/health  
indices:  
‘apache-tomcat-_':  
'_’:  
- ALL

‘?kibana’:  
'_':  
- READ  
- indices:admin/mappings/fields/get_  
- indices:admin/validate/query\*  
- indices:admin/get\*  
- indices:admin/exists\*  
- indices:admin/mappings/fields/get\*  
- indices:admin/refresh\*  
- indices:admin/validate/query\*  
- indices:data/read/get\*  
- indices:data/read/mget\*  
- indices:data/read/search\*

‘\*’:

‘\*’:

- indices:data/read/field\_stats

在 2016年6月20日星期一 UTC+8上午9:24:14，Wei Hong写道：

> **···**
>
> > Sorry, I added these to the role, it still not work. The errors is
> > 
> > “no permissions for indices:data/read/field\_stats”
> 
> > 
> 
> > then i added the " indices:data/read/field\_stats" behind the “?kibana”
> 
> > it still not work.
> 
> > 
> 
> > Is there something wrong?
> 
> > 在 2016年6月18日星期六 UTC+8上午3:08:02，SG写道：
> > 
> > > does this work?
> > > 
> > > sg\_apache\_tomcat:
> > > 
> > > cluster:  
> > > - cluster:monitor/nodes/info
> > > 
> > > ```
> > > - cluster:monitor/health
> > > 
> > > ```
> > > 
> > > indices:
> > > 
> > > ```
> > > 'apache-tomcat-*':
> > > 
> > > '*':
> > > 
> > > - ALL
> > > 
> > > '?kibana':
> > > 
> > > '*':
> > > 
> > > - READ
> > > 
> > > - indices:admin/mappings/fields/get*
> > > 
> > > - indices:admin/validate/query*
> > > 
> > > - indices:admin/get*
> > > 
> > > - indices:admin/exists*
> > > 
> > > - indices:admin/mappings/fields/get*
> > > 
> > > - indices:admin/refresh*
> > > 
> > > - indices:admin/validate/query*
> > > 
> > > - indices:data/read/get*
> > > 
> > > - indices:data/read/mget*
> > > 
> > > - indices:data/read/search*
> > > 
> > > ```
> > > 
> > > > Am 16.06.2016 um 11:31 schrieb Wei Hong [fzu...@gmail.com](mailto:fzu...@gmail.com):
> > > 
> > > > I have changed the config file sg\_roles.yml
> > > 
> > > > sg\_apache\_tomcat:
> > > 
> > > > indices:
> > > 
> > > > ```
> > > > 'apache-tomcat-*':
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > '*':
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > - ALL
> > > > 
> > > > ```
> > > 
> > > > and the sg\_roles\_mapping.yml:
> > > 
> > > > sg\_apache\_tomcat:
> > > 
> > > > users:
> > > 
> > > > ```
> > > > - kirk
> > > > 
> > > > ```
> > > 
> > > > and in the kibana.yml, i added the entries
> > > 
> > > > elasticsearch.username: “kibanaserver”
> > > 
> > > > elasticsearch.password: “kibanaserver”
> > > 
> > > > And with the command curl -XGET -u kirk:kirk “[http://192.25.97.128:9200/apache-\*?pretty](http://192.25.97.128:9200/apache-*?pretty)” , i can get what i want.
> > > 
> > > > But when i access the kibana with the “kirk”, i got the errors as follow:
> > > 
> > > > ```
> > > > Courier Fetch Error: unhandled courier request error: unknown error
> > > > 
> > > > ```
> > > > 
> > > > Error: unhandled courier request error: unknown error
> > > 
> > > > ```
> > > > at handleError (
> > > > 
> > > > ```
> > > 
> > > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78871:23)
> > > 
> > > > )
> > > 
> > > > ```
> > > > at DocRequest.
> > > > 
> > > > ```
> > > 
> > > > AbstractReqProvider.AbstractReq.handleFailure ([http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78791:15)
> > > 
> > > > )
> > > 
> > > > ```
> > > > at
> > > > 
> > > > ```
> > > > 
> > > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78685:18)
> > > 
> > > > ```
> > > > at Array.forEach (native)
> > > > 
> > > > ```
> > > 
> > > > ```
> > > > at
> > > > 
> > > > ```
> > > > 
> > > > [http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19](http://192.25.97.128:5601/bundles/kibana.bundle.js?v=9732:78683:19)
> > > 
> > > > ```
> > > > at processQueue (
> > > > 
> > > > ```
> > > 
> > > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42357:29)
> > > 
> > > > )
> > > 
> > > > ```
> > > > at
> > > > 
> > > > ```
> > > > 
> > > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:42373:28)
> > > 
> > > > ```
> > > > at Scope.$eval (
> > > > 
> > > > ```
> > > 
> > > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43601:29)
> > > 
> > > > )
> > > 
> > > > ```
> > > > at Scope.$digest (
> > > > 
> > > > ```
> > > 
> > > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43412:32)
> > > 
> > > > )
> > > 
> > > > ```
> > > > at Scope.$apply (
> > > > 
> > > > ```
> > > 
> > > > [http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25](http://192.25.97.128:5601/bundles/commons.bundle.js?v=9732:43709:25))
> > > 
> > > > What’t more, i can access the kibana with the “admin”.
> > > 
> > > > Can you tell me where did i miss?
> > > 
> > > > –  
> > > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > > 
> > > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > > 
> > > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > > 
> > > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/039b0253-f9bf-4bd2-a9bf-0ab1fecaccb1%40googlegroups.com).
> > > 
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
