# Kibana permissions

**URL:** <https://forum.search-guard.com/t/kibana-permissions/1987>\
**Category:** Search Guard\
**Created:** [October 8, 2020, 1:35pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987 "2020-10-08T13:35:30Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 8, 2020, 1:35pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/1 "2020-10-08T13:35:30Z")

</div>

It’s unclear to me what exactly needs to be done to give a user access to kibana.  
What minimum permissions are needed for the following 2 roles:

1. full read access for tenant `foo`
2. read/write access for tenant ‘foo’

cheers

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [October 8, 2020, 2:24pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/2 "2020-10-08T14:24:38Z")

</div>

Use [the built-in roles](https://docs.search-guard.com/latest/roles-permissions#built-in-roles).

A minimal set of roles for a Kibana user:

1. Full read access: SGS\_KIBANA\_USER and SGS\_READALL.
2. Full read/write access: SGS\_KIBANA\_USER and SGS\_ALL\_ACCESS.

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [October 8, 2020, 2:28pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/3 "2020-10-08T14:28:51Z")

</div>

If you want to check what set of permissions defines these roles, switch the System items in SG UI.

 ![Screenshot 2020-10-08 at 16.25.15](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/d6f2d97bab3b91951c61afd4169dd07a0428b29d.png)

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 8, 2020, 5:21pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/4 "2020-10-08T17:21:49Z")

</div>

sounds a bit too much. I gave the SGS\_KIBANA\_USER role and specific access to some indices, but that’s not enough because index-pattern management seems not possible

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [October 9, 2020, 3:15pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/5 "2020-10-09T15:15:14Z")

</div>

There should be an error in the Elasticsearch log then. Show me it.

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 15, 2020, 12:07pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/6 "2020-10-15T12:07:14Z")

</div>

```auto
[2020-10-15T14:05:42,175][INFO][c.f.s.p.PrivilegesEvaluator] [node01] No index-level perm match for User [name=fwernli, backend_roles=[], requestedTenant=null] Resolved [aliases=[*], indices=[*], allIndices=[*], types=[*], originalRequested=[], remoteIndices=[]] [Action [indices:admin/resolve/index]] [RolesChecked [site, cta_query_human, grafana_admin, SGS_KIBANA_USER]]
[2020-10-15T14:05:42,176][INFO][c.f.s.p.PrivilegesEvaluator] [node01] No permissions for [indices:admin/resolve/index]

```

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 15, 2020, 1:11pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/7 "2020-10-15T13:11:14Z")

</div>

it is also unclear to me what role or privilege is needed for allowing read/write to private kibana tenant

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [October 16, 2020, 7:21am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/8 "2020-10-16T07:21:09Z")

</div>

An important thing to keep in mind with multi tenancy is that Kibana tenants and ES access permissions are orthogonal concepts.

The tenant defines which “buckets” of Kibana saved objects (i.e., index patterns, visualisations, …) you are allowed to use. By default, the private tenant is enabled (see `searchguard.multitenancy.tenants.enable_private` on [Kibana Multitenancy | Security for Elasticsearch | Search Guard](https://docs.search-guard.com/latest/kibana-multi-tenancy) ). Thus, any authenticated user is allowed to save index patterns in their private tenant/bucket without any further privilege.

The question which indexes a user is allowed to access and which operations a user is allowed to perform is - on the other hand - completely independent of the selected tenant. This is only governed by the `index_permissions` and `cluster_permissions` of a user.

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 19, 2020, 8:56am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/9 "2020-10-19T08:56:48Z")

</div>

Thanks for this clarification.  
That also means that I probably hit a bug : I do have the private tenant implicitly enabled, but can’t create any index pattern. Oddly, I don’t see any security log message in ES, and kibana only logs the following:

```auto
Oct 19 10:54:14 kibana01 kibana[29728]: {"type":"response","@timestamp":"2020-10-19T08:54:14Z","tags":[],"pid":29728,"method":"post","statusCode":403,"req":{"url":"/api/saved_objects/index-pattern","method":"post","headers":{"host":"example.com","user-agent":"Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0","accept":"*/*","accept-language":"en,en-US;q=0.8,fr;q=0.5,de;q=0.3","accept-encoding":"gzip, deflate, br","referer":"https://example.com/app/management/kibana/indexPatterns/create","content-type":"application/json","kbn-version":"7.9.1","origin":"https://example.com","content-length":"78","dnt":"1","connection":"keep-alive","sgtenant":" __user__"},"remoteAddress":"1.1.1.1","userAgent":"1.1.1.1","referer":"https://example.com/app/management/kibana/indexPatterns/create"},"res":{"statusCode":403,"responseTime":31,"contentLength":9},"message":"POST /api/saved_objects/index-pattern 403 31ms - 9.0B"}

```

The kibana interface merely says `Error: Forbidden`

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [October 20, 2020, 8:07am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/10 "2020-10-20T08:07:07Z")

</div>

On which versions of ES/SG does this error occur?

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 20, 2020, 11:50am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/11 "2020-10-20T11:50:48Z")

</div>

search-guard-7 7.9.1-45.0.0

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [October 20, 2020, 2:06pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/12 "2020-10-20T14:06:12Z")

</div>

Did you enable `do_not_fail_on_forbidden`? If not, could you enable it and try again?

> **[Installing the Plugin](https://docs.search-guard.com/latest/kibana-plugin-installation#configuring-elasticsearch-enable-do-not-fail-on-forbidden)**
>
> How to install the Search Guard Kibana plugin which adds authentication, multi-tenancy and the configuration UI.

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [October 20, 2020, 2:27pm UTC](https://forum.search-guard.com/t/kibana-permissions/1987/13 "2020-10-20T14:27:08Z")

</div>

The option is enabled, yes

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [February 3, 2021, 11:43am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/15 "2021-02-03T11:43:29Z")

</div>



---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [June 28, 2021, 7:02am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/16 "2021-06-28T07:02:04Z")

</div>

Hi again, I still have this problem on 7.9.1-45.0.0  
There is nothing in the ES logs, I only get a “Error forbidden” message in kibana when trying to save an index-pattern:

```auto
{
  "type": "response",
  "@timestamp": "2021-06-28T06:59:56Z",
  "tags": [],
  "pid": 5457,
  "method": "post",
  "statusCode": 403,
  "req": {
    "url": "/api/saved_objects/index-pattern",
    "method": "post",
    "headers": {
      "host": "sg.example.com",
      "user-agent": "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0",
      "accept": "*/*",
      "accept-language": "en,en-US;q=0.8,fr;q=0.5,de;q=0.3",
      "accept-encoding": "gzip, deflate, br",
      "referer": "https://sg.example.com/app/management/kibana/indexPatterns/create",
      "content-type": "application/json",
      "kbn-version": "7.9.1",
      "origin": "https://sg.example.com",
      "content-length": "82",
      "dnt": "1",
      "connection": "keep-alive",
      "sgtenant": " __user__"
    },
    "remoteAddress": "1.1.2.4",
    "userAgent": "1.1.2.4",
    "referer": "https://sg.example.com/app/management/kibana/indexPatterns/create"
  },
  "res": {
    "statusCode": 403,
    "responseTime": 24,
    "contentLength": 9
  },
  "message": "POST /api/saved_objects/index-pattern 403 24ms - 9.0B"
}

```

The user has `SGS_KIBANA_USER` permissions, I just checked using the kibana account info page

---

<div class="post-metadata">

**Author:** ![faxmodem](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/faxmodem/32/22_2.png) [@faxmodem](https://forum.search-guard.com/u/faxmodem)\
**Post date:** [June 28, 2021, 7:06am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/17 "2021-06-28T07:06:38Z")

</div>

Maybe this can be useful : I tried importing the index pattern in kibana using the import feature, and here’s what I get:

```auto
no permissions for [indices:admin/mapping/auto_put] and User [name=fwernli, backend_roles=[], requestedTenant= __user__ ]

```

---

<div class="post-metadata">

**Author:** ![nils](https://avatars.discourse-cdn.com/v4/letter/n/d6d6ee/32.png) [@nils](https://forum.search-guard.com/u/nils)\
**Post date:** [June 29, 2021, 6:57am UTC](https://forum.search-guard.com/t/kibana-permissions/1987/18 "2021-06-29T06:57:34Z")

</div>

Have you tried upgrading to SG 7.9.1-45.1.0?

From the release notes:

> Creating index patterns with Kibana 7.9.1 and Search Guard 45.0.0 was not possible. Fixed.

> **[Search Guard Documentation 404](https://docs.search-guard.com/latest/404.html)**
>
> Seems like the page you are looking for does not exist. We deeply and humbly apologize.
