# Left menu links doesn't work in Kibana after login with a user created under internal\_users

**URL:** <https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215>\
**Category:** Search Guard\
**Created:** [November 27, 2018, 10:37am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215 "2018-11-27T10:37:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pankaj\_chand](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pankaj\_chand](https://forum.search-guard.com/u/pankaj_chand)\
**Post date:** [November 27, 2018, 10:37am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/1 "2018-11-27T10:37:16Z")

</div>

Hi,

I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).

I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.

When asking questions, please provide the following information:

- Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2

- Installed and used enterprise modules, if any

- JVM version and operating system version

- Search Guard configuration files

- Elasticsearch log messages on debug level

- Other installed Elasticsearch or Kibana plugins, if any

Regards

Pankaj

 ![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/6d1b74e4325675495cff9aba8fd61775ba86b8e7.png)

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [November 28, 2018, 10:52am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/2 "2018-11-28T10:52:56Z")

</div>

This usually means that the user does not have the required privileges to use Kibana.

Can you check that your users are actually assigned to the s\_kibana\_user role? For that, visit the SG authinfo endpoint:

[https://sgssl-0.example.com:9200/\_searchguard/authinfo](https://sgssl-0.example.com:9200/_searchguard/authinfo)

And in the JSON please check the sg\_roles, it has to contain the sg\_kibnana\_user role.

> **···**
>
> On Tuesday, November 27, 2018 at 11:37:17 AM UTC+1, pankaj chand wrote:
> 
> > Hi,
> 
> > 
> 
> > I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).
> 
> > 
> 
> > 
> 
> > I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.
> 
> > 
> 
> > 
> 
> > 
> 
> > When asking questions, please provide the following information:
> 
> > - Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2
> 
> > - Installed and used enterprise modules, if any
> 
> > - JVM version and operating system version
> 
> > - Search Guard configuration files
> 
> > - Elasticsearch log messages on debug level
> 
> > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > 
> 
> > Regards
> 
> > Pankaj

---

<div class="post-metadata">

**Author:** ![pankaj\_chand](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pankaj\_chand](https://forum.search-guard.com/u/pankaj_chand)\
**Post date:** [November 29, 2018, 4:56am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/3 "2018-11-29T04:56:14Z")

</div>

[https://localhost:9200/\_searchguard/api/internalusers](https://localhost:9200/_searchguard/api/internalusers)

```
{

```

“logstash”: {  
“hash”: “”,  
“roles”: [  
“logstash”  
]  
},  
“snapshotrestore”: {  
“hash”: “”,  
“roles”: [  
“snapshotrestore”  
]  
},  
“formcept”: {  
“hash”: “”,  
“roles”: [  
“sg\_mecbot\_pankaj1”  
]  
},  
“admin”: {  
“attributes”: {  
“attribute1”: “value1”,  
“attribute3”: “value3”,  
“attribute2”: “value2”  
},  
“readonly”: “true”,  
“hash”: “”,  
“roles”: [  
“admin”  
]  
},  
“suresh”: {  
“hash”: “”,  
“roles”: [  
“sg\_own\_index”,  
“sg\_kibana\_user”  
]  
},  
“pankaj1”: {  
“hash”: “”,  
“roles”: [  
“sg\_own\_index”,  
“sg\_kibana\_user”  
]  
},  
“kibanaserver”: {  
“readonly”: “true”,  
“hash”: “”  
},  
“kibanaro”: {  
“hash”: “”,  
“roles”: [  
“kibanauser”,  
“readall”  
]  
},  
“readall”: {  
“hash”: “”,  
“roles”: [  
“readall”  
]  
}  
}

For user pankaj1 authinfo

{

“user”: “User [name=pankaj1, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,

“user\_name”: “pankaj1”,

“user\_requested\_tenant”: null,

“remote\_address”: “[::1]:49750”,

“backend\_roles”: [

“sg\_own\_index”,

“sg\_kibana\_user”

],

“custom\_attribute\_names”: ,

“sg\_roles”: [

“sg\_own\_index”

],

“sg\_tenants”: {

“pankaj1”: true

},

“principal”: null,

“peer\_certificates”: “0”,

“sso\_logout\_url”: null

}

For user suresh authinfo

{

“user”: “User [name=suresh, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,

“user\_name”: “suresh”,

“user\_requested\_tenant”: null,

“remote\_address”: “[::1]:49750”,

“backend\_roles”: [

“sg\_own\_index”,

“sg\_kibana\_user”

],

“custom\_attribute\_names”: ,

“sg\_roles”: [

“sg\_own\_index”

],

“sg\_tenants”: {

“suresh”: true

},

“principal”: null,

“peer\_certificates”: “0”,

“sso\_logout\_url”: null

}

Given the above configs when i login as suresh I can’t create visualization or dashboard while everything is fine with pankaj1 login. Infact, any other user I create with same role config I am not able to create visualization or dashboard.

Note - pankaj1 was the first user i created.

This is extremely critical for us because we are very near to releasing the product.

Thanks

> **···**
>
> On Wednesday, November 28, 2018 at 4:22:56 PM UTC+5:30, Jochen Kressin wrote:
> 
> > This usually means that the user does not have the required privileges to use Kibana.
> 
> > Can you check that your users are actually assigned to the s\_kibana\_user role? For that, visit the SG authinfo endpoint:
> 
> > 
> 
> > [https://sgssl-0.example.com:9200/\_searchguard/authinfo](https://sgssl-0.example.com:9200/_searchguard/authinfo)
> 
> > 
> 
> > And in the JSON please check the sg\_roles, it has to contain the sg\_kibnana\_user role.
> > 
> > On Tuesday, November 27, 2018 at 11:37:17 AM UTC+1, pankaj chand wrote:
> > 
> > > Hi,
> 
> > >
> 
> > > I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).
> 
> > >
> 
> > >
> 
> > > I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.
> 
> > >
> 
> > >
> 
> > >
> 
> > > When asking questions, please provide the following information:
> 
> > > - Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2
> 
> > > - Installed and used enterprise modules, if any
> 
> > > - JVM version and operating system version
> 
> > > - Search Guard configuration files
> 
> > > - Elasticsearch log messages on debug level
> 
> > > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > >
> 
> > > Regards
> 
> > > Pankaj

---

<div class="post-metadata">

**Author:** ![pankaj\_chand](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pankaj\_chand](https://forum.search-guard.com/u/pankaj_chand)\
**Post date:** [December 3, 2018, 7:53am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/4 "2018-12-03T07:53:14Z")

</div>

Hi Folks,

Any updates on this issue?

Regards

Pankaj

> **···**
>
> On Thursday, November 29, 2018 at 10:26:15 AM UTC+5:30, pankaj chand wrote:
> 
> > [https://localhost:9200/\_searchguard/api/internalusers](https://localhost:9200/_searchguard/api/internalusers)
> 
> > 
> 
> > ```
> > {
> > 
> > ```
> > 
> > “logstash”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “logstash”  
> > ]  
> > },  
> > “snapshotrestore”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “snapshotrestore”  
> > ]  
> > },  
> > “formcept”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “sg\_mecbot\_pankaj1”  
> > ]  
> > },  
> > “admin”: {  
> > “attributes”: {  
> > “attribute1”: “value1”,  
> > “attribute3”: “value3”,  
> > “attribute2”: “value2”  
> > },  
> > “readonly”: “true”,  
> > “hash”: “”,  
> > “roles”: [  
> > “admin”  
> > ]  
> > },  
> > “suresh”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “sg\_own\_index”,  
> > “sg\_kibana\_user”  
> > ]  
> > },  
> > “pankaj1”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “sg\_own\_index”,  
> > “sg\_kibana\_user”  
> > ]  
> > },  
> > “kibanaserver”: {  
> > “readonly”: “true”,  
> > “hash”: “”  
> > },  
> > “kibanaro”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “kibanauser”,  
> > “readall”  
> > ]  
> > },  
> > “readall”: {  
> > “hash”: “”,  
> > “roles”: [  
> > “readall”  
> > ]  
> > }  
> > }
> 
> > 
> 
> > 
> 
> > 
> 
> > For user pankaj1 authinfo
> 
> > 
> 
> > {
> 
> > “user”: “User [name=pankaj1, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > “user\_name”: “pankaj1”,
> 
> > “user\_requested\_tenant”: null,
> 
> > “remote\_address”: “[::1]:49750”,
> 
> > “backend\_roles”: [
> 
> > “sg\_own\_index”,
> 
> > “sg\_kibana\_user”
> 
> > ],
> 
> > “custom\_attribute\_names”: ,
> 
> > “sg\_roles”: [
> 
> > “sg\_own\_index”
> 
> > ],
> 
> > “sg\_tenants”: {
> 
> > “pankaj1”: true
> 
> > },
> 
> > “principal”: null,
> 
> > “peer\_certificates”: “0”,
> 
> > “sso\_logout\_url”: null
> 
> > }
> 
> > 
> 
> > For user suresh authinfo
> 
> > {
> 
> > “user”: “User [name=suresh, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > “user\_name”: “suresh”,
> 
> > “user\_requested\_tenant”: null,
> 
> > “remote\_address”: “[::1]:49750”,
> 
> > “backend\_roles”: [
> 
> > “sg\_own\_index”,
> 
> > “sg\_kibana\_user”
> 
> > ],
> 
> > “custom\_attribute\_names”: ,
> 
> > “sg\_roles”: [
> 
> > “sg\_own\_index”
> 
> > ],
> 
> > “sg\_tenants”: {
> 
> > “suresh”: true
> 
> > },
> 
> > “principal”: null,
> 
> > “peer\_certificates”: “0”,
> 
> > “sso\_logout\_url”: null
> 
> > }
> 
> > 
> 
> > 
> 
> > Given the above configs when i login as suresh I can’t create visualization or dashboard while everything is fine with pankaj1 login. Infact, any other user I create with same role config I am not able to create visualization or dashboard.
> 
> > Note - pankaj1 was the first user i created.
> 
> > 
> 
> > This is extremely critical for us because we are very near to releasing the product.
> 
> > 
> 
> > Thanks
> > 
> > On Wednesday, November 28, 2018 at 4:22:56 PM UTC+5:30, Jochen Kressin wrote:
> > 
> > > This usually means that the user does not have the required privileges to use Kibana.
> 
> > > Can you check that your users are actually assigned to the s\_kibana\_user role? For that, visit the SG authinfo endpoint:
> 
> > >
> 
> > > [https://sgssl-0.example.com:9200/\_searchguard/authinfo](https://sgssl-0.example.com:9200/_searchguard/authinfo)
> 
> > >
> 
> > > And in the JSON please check the sg\_roles, it has to contain the sg\_kibnana\_user role.
> > > 
> > > On Tuesday, November 27, 2018 at 11:37:17 AM UTC+1, pankaj chand wrote:
> > > 
> > > > Hi,
> 
> > > >
> 
> > > > I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).
> 
> > > >
> 
> > > >
> 
> > > > I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.
> 
> > > >
> 
> > > >
> 
> > > >
> 
> > > > When asking questions, please provide the following information:
> 
> > > > - Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2
> 
> > > > - Installed and used enterprise modules, if any
> 
> > > > - JVM version and operating system version
> 
> > > > - Search Guard configuration files
> 
> > > > - Elasticsearch log messages on debug level
> 
> > > > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > > >
> 
> > > > Regards
> 
> > > > Pankaj

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [December 3, 2018, 11:12am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/5 "2018-12-03T11:12:02Z")

</div>

Your are using the wrong backenrole for your Kibana users. The sequence is:

1. Search Guard will pick up a users backend roles

2. Search Guard will read the sg\_rolesmapping.yml

3. Search Guard will assign the Search Guard roles based in the settings in sg\_rolesmapping.

The corresponding entry in sg\_rolesmapping:

sg\_kibana\_user:  
backendroles:  
- kibanauser

``

So you need to assign the backendrole “kibanauser” in your internalusers.yml like:

```
"suresh": {
    "hash": "",
    "roles": [
        "sg_own_index",
        **"kibanauser"**
    ]
}

```

``

> **···**
>
> On Monday, December 3, 2018 at 8:53:15 AM UTC+1, pankaj chand wrote:
> 
> > Hi Folks,
> 
> > Any updates on this issue?
> 
> > 
> 
> > Regards
> 
> > Pankaj
> > 
> > On Thursday, November 29, 2018 at 10:26:15 AM UTC+5:30, pankaj chand wrote:
> > 
> > > [https://localhost:9200/\_searchguard/api/internalusers](https://localhost:9200/_searchguard/api/internalusers)
> 
> > >
> 
> > > ```
> > > {
> > > 
> > > ```
> > > 
> > > “logstash”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “logstash”  
> > > ]  
> > > },  
> > > “snapshotrestore”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “snapshotrestore”  
> > > ]  
> > > },  
> > > “formcept”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “sg\_mecbot\_pankaj1”  
> > > ]  
> > > },  
> > > “admin”: {  
> > > “attributes”: {  
> > > “attribute1”: “value1”,  
> > > “attribute3”: “value3”,  
> > > “attribute2”: “value2”  
> > > },  
> > > “readonly”: “true”,  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “admin”  
> > > ]  
> > > },  
> > > “suresh”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “sg\_own\_index”,  
> > > “sg\_kibana\_user”  
> > > ]  
> > > },  
> > > “pankaj1”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “sg\_own\_index”,  
> > > “sg\_kibana\_user”  
> > > ]  
> > > },  
> > > “kibanaserver”: {  
> > > “readonly”: “true”,  
> > > “hash”: “”  
> > > },  
> > > “kibanaro”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “kibanauser”,  
> > > “readall”  
> > > ]  
> > > },  
> > > “readall”: {  
> > > “hash”: “”,  
> > > “roles”: [  
> > > “readall”  
> > > ]  
> > > }  
> > > }
> 
> > >
> 
> > >
> 
> > >
> 
> > > For user pankaj1 authinfo
> 
> > >
> 
> > > {
> 
> > > “user”: “User [name=pankaj1, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > > “user\_name”: “pankaj1”,
> 
> > > “user\_requested\_tenant”: null,
> 
> > > “remote\_address”: “[::1]:49750”,
> 
> > > “backend\_roles”: [
> 
> > > “sg\_own\_index”,
> 
> > > “sg\_kibana\_user”
> 
> > > ],
> 
> > > “custom\_attribute\_names”: ,
> 
> > > “sg\_roles”: [
> 
> > > “sg\_own\_index”
> 
> > > ],
> 
> > > “sg\_tenants”: {
> 
> > > “pankaj1”: true
> 
> > > },
> 
> > > “principal”: null,
> 
> > > “peer\_certificates”: “0”,
> 
> > > “sso\_logout\_url”: null
> 
> > > }
> 
> > >
> 
> > > For user suresh authinfo
> 
> > > {
> 
> > > “user”: “User [name=suresh, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > > “user\_name”: “suresh”,
> 
> > > “user\_requested\_tenant”: null,
> 
> > > “remote\_address”: “[::1]:49750”,
> 
> > > “backend\_roles”: [
> 
> > > “sg\_own\_index”,
> 
> > > “sg\_kibana\_user”
> 
> > > ],
> 
> > > “custom\_attribute\_names”: ,
> 
> > > “sg\_roles”: [
> 
> > > “sg\_own\_index”
> 
> > > ],
> 
> > > “sg\_tenants”: {
> 
> > > “suresh”: true
> 
> > > },
> 
> > > “principal”: null,
> 
> > > “peer\_certificates”: “0”,
> 
> > > “sso\_logout\_url”: null
> 
> > > }
> 
> > >
> 
> > >
> 
> > > Given the above configs when i login as suresh I can’t create visualization or dashboard while everything is fine with pankaj1 login. Infact, any other user I create with same role config I am not able to create visualization or dashboard.
> 
> > > Note - pankaj1 was the first user i created.
> 
> > >
> 
> > > This is extremely critical for us because we are very near to releasing the product.
> 
> > >
> 
> > > Thanks
> > > 
> > > On Wednesday, November 28, 2018 at 4:22:56 PM UTC+5:30, Jochen Kressin wrote:
> > > 
> > > > This usually means that the user does not have the required privileges to use Kibana.
> 
> > > > Can you check that your users are actually assigned to the s\_kibana\_user role? For that, visit the SG authinfo endpoint:
> 
> > > >
> 
> > > > [https://sgssl-0.example.com:9200/\_searchguard/authinfo](https://sgssl-0.example.com:9200/_searchguard/authinfo)
> 
> > > >
> 
> > > > And in the JSON please check the sg\_roles, it has to contain the sg\_kibnana\_user role.
> > > > 
> > > > On Tuesday, November 27, 2018 at 11:37:17 AM UTC+1, pankaj chand wrote:
> > > > 
> > > > > Hi,
> 
> > > > >
> 
> > > > > I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).
> 
> > > > >
> 
> > > > >
> 
> > > > > I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.
> 
> > > > >
> 
> > > > >
> 
> > > > >
> 
> > > > > When asking questions, please provide the following information:
> 
> > > > > - Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2
> 
> > > > > - Installed and used enterprise modules, if any
> 
> > > > > - JVM version and operating system version
> 
> > > > > - Search Guard configuration files
> 
> > > > > - Elasticsearch log messages on debug level
> 
> > > > > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > > > >
> 
> > > > > Regards
> 
> > > > > Pankaj

---

<div class="post-metadata">

**Author:** ![pankaj\_chand](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pankaj\_chand](https://forum.search-guard.com/u/pankaj_chand)\
**Post date:** [December 5, 2018, 8:46am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/6 "2018-12-05T08:46:18Z")

</div>

Thanks Jochen,

If I want my users to have access to specific indexes ( different users might have access to different set of indexes) I have to create new sg roles first, then new sg role mappings to new backend roles and then assign those backend roles to users? Please let me know if I have understood it properly.

Also, if I want users to have access to only their own dashboards or visualizations in Kibana. How can I achieve that? Kibana stores all dashboards in same index and same document type. Also the documents stored don’t have any field which might indicate the owner/creator of that dashboard.

> **···**
>
> On Monday, December 3, 2018 at 4:42:02 PM UTC+5:30, Jochen Kressin wrote:
> 
> > Your are using the wrong backenrole for your Kibana users. The sequence is:
> 
> > 1. Search Guard will pick up a users backend roles
> 
> > 1. Search Guard will read the sg\_rolesmapping.yml
> 
> > 1. Search Guard will assign the Search Guard roles based in the settings in sg\_rolesmapping.
> 
> > 
> 
> > The corresponding entry in sg\_rolesmapping:
> 
> > 
> 
> > sg\_kibana\_user:  
> > backendroles:  
> > - kibanauser
> 
> > ``
> 
> > 
> 
> > So you need to assign the backendrole “kibanauser” in your internalusers.yml like:
> 
> > 
> 
> > ```
> > "suresh": {
> > "hash": "",
> > "roles": [
> > "sg_own_index",
> > **"kibanauser"**
> > ]
> > }
> > 
> > ```
> 
> > ``
> 
> > 
> 
> > 
> 
> > 
> 
> > On Monday, December 3, 2018 at 8:53:15 AM UTC+1, pankaj chand wrote:
> > 
> > > Hi Folks,
> 
> > > Any updates on this issue?
> 
> > >
> 
> > > Regards
> 
> > > Pankaj
> > > 
> > > On Thursday, November 29, 2018 at 10:26:15 AM UTC+5:30, pankaj chand wrote:
> > > 
> > > > [https://localhost:9200/\_searchguard/api/internalusers](https://localhost:9200/_searchguard/api/internalusers)
> 
> > > >
> 
> > > > ```
> > > > {
> > > > 
> > > > ```
> > > > 
> > > > “logstash”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “logstash”  
> > > > ]  
> > > > },  
> > > > “snapshotrestore”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “snapshotrestore”  
> > > > ]  
> > > > },  
> > > > “formcept”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “sg\_mecbot\_pankaj1”  
> > > > ]  
> > > > },  
> > > > “admin”: {  
> > > > “attributes”: {  
> > > > “attribute1”: “value1”,  
> > > > “attribute3”: “value3”,  
> > > > “attribute2”: “value2”  
> > > > },  
> > > > “readonly”: “true”,  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “admin”  
> > > > ]  
> > > > },  
> > > > “suresh”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “sg\_own\_index”,  
> > > > “sg\_kibana\_user”  
> > > > ]  
> > > > },  
> > > > “pankaj1”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “sg\_own\_index”,  
> > > > “sg\_kibana\_user”  
> > > > ]  
> > > > },  
> > > > “kibanaserver”: {  
> > > > “readonly”: “true”,  
> > > > “hash”: “”  
> > > > },  
> > > > “kibanaro”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “kibanauser”,  
> > > > “readall”  
> > > > ]  
> > > > },  
> > > > “readall”: {  
> > > > “hash”: “”,  
> > > > “roles”: [  
> > > > “readall”  
> > > > ]  
> > > > }  
> > > > }
> 
> > > >
> 
> > > >
> 
> > > >
> 
> > > > For user pankaj1 authinfo
> 
> > > >
> 
> > > > {
> 
> > > > “user”: “User [name=pankaj1, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > > > “user\_name”: “pankaj1”,
> 
> > > > “user\_requested\_tenant”: null,
> 
> > > > “remote\_address”: “[::1]:49750”,
> 
> > > > “backend\_roles”: [
> 
> > > > “sg\_own\_index”,
> 
> > > > “sg\_kibana\_user”
> 
> > > > ],
> 
> > > > “custom\_attribute\_names”: ,
> 
> > > > “sg\_roles”: [
> 
> > > > “sg\_own\_index”
> 
> > > > ],
> 
> > > > “sg\_tenants”: {
> 
> > > > “pankaj1”: true
> 
> > > > },
> 
> > > > “principal”: null,
> 
> > > > “peer\_certificates”: “0”,
> 
> > > > “sso\_logout\_url”: null
> 
> > > > }
> 
> > > >
> 
> > > > For user suresh authinfo
> 
> > > > {
> 
> > > > “user”: “User [name=suresh, roles=[sg\_own\_index, sg\_kibana\_user], requestedTenant=null]”,
> 
> > > > “user\_name”: “suresh”,
> 
> > > > “user\_requested\_tenant”: null,
> 
> > > > “remote\_address”: “[::1]:49750”,
> 
> > > > “backend\_roles”: [
> 
> > > > “sg\_own\_index”,
> 
> > > > “sg\_kibana\_user”
> 
> > > > ],
> 
> > > > “custom\_attribute\_names”: ,
> 
> > > > “sg\_roles”: [
> 
> > > > “sg\_own\_index”
> 
> > > > ],
> 
> > > > “sg\_tenants”: {
> 
> > > > “suresh”: true
> 
> > > > },
> 
> > > > “principal”: null,
> 
> > > > “peer\_certificates”: “0”,
> 
> > > > “sso\_logout\_url”: null
> 
> > > > }
> 
> > > >
> 
> > > >
> 
> > > > Given the above configs when i login as suresh I can’t create visualization or dashboard while everything is fine with pankaj1 login. Infact, any other user I create with same role config I am not able to create visualization or dashboard.
> 
> > > > Note - pankaj1 was the first user i created.
> 
> > > >
> 
> > > > This is extremely critical for us because we are very near to releasing the product.
> 
> > > >
> 
> > > > Thanks
> > > > 
> > > > On Wednesday, November 28, 2018 at 4:22:56 PM UTC+5:30, Jochen Kressin wrote:
> > > > 
> > > > > This usually means that the user does not have the required privileges to use Kibana.
> 
> > > > > Can you check that your users are actually assigned to the s\_kibana\_user role? For that, visit the SG authinfo endpoint:
> 
> > > > >
> 
> > > > > [https://sgssl-0.example.com:9200/\_searchguard/authinfo](https://sgssl-0.example.com:9200/_searchguard/authinfo)
> 
> > > > >
> 
> > > > > And in the JSON please check the sg\_roles, it has to contain the sg\_kibnana\_user role.
> > > > > 
> > > > > On Tuesday, November 27, 2018 at 11:37:17 AM UTC+1, pankaj chand wrote:
> > > > > 
> > > > > > Hi,
> 
> > > > > >
> 
> > > > > > I created a user with roles sg\_own\_index and sg\_kibana\_user. But when I log in with that user the left side menu links for visualization, dashboard, Management are inactive ( ie if i click on these links I see nothing just blank whitespace no options to create dashboard or visualization or index patern…just an empty screen).
> 
> > > > > >
> 
> > > > > >
> 
> > > > > > I have attached a file showing roles for user ‘Suresh’. Infact, funny part is that it is working for only one user ‘pankaj1’, if I create user with any other name it is not showing any thing. I have index created by name pankaj1, pankaj2, pankaj3 etc. But if i create users pankaj2, pankaj3 with same sg\_own\_index and sg\_kibana\_user permission, I don’t see any thing in visualization and other links.
> 
> > > > > >
> 
> > > > > >
> 
> > > > > >
> 
> > > > > > When asking questions, please provide the following information:
> 
> > > > > > - Search Guard and Elasticsearch version - SG - 6.4.2-23.2 - ES 6.4.2
> 
> > > > > > - Installed and used enterprise modules, if any
> 
> > > > > > - JVM version and operating system version
> 
> > > > > > - Search Guard configuration files
> 
> > > > > > - Elasticsearch log messages on debug level
> 
> > > > > > - Other installed Elasticsearch or Kibana plugins, if any
> 
> > > > > >
> 
> > > > > > Regards
> 
> > > > > > Pankaj

---

<div class="post-metadata">

**Author:** ![marc.zominy](https://avatars.discourse-cdn.com/v4/letter/m/919ad9/32.png) [@marc.zominy](https://forum.search-guard.com/u/marc.zominy)\
**Post date:** [December 5, 2018, 8:56am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/7 "2018-12-05T08:56:47Z")

</div>

Maybe I can reply from what I’ve learnt, Jochen may complete or correct my answer.

You seem to have understood the roles system.

If you want to split what dashboards and visualizations users can see in Kibana, you will have to look towards the multi tenany system described here: [Kibana Multitenancy | Security for Elasticsearch | Search Guard](https://docs.search-guard.com/latest/kibana-multi-tenancy)

Hope it helps!

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [December 5, 2018, 11:01am UTC](https://forum.search-guard.com/t/left-menu-links-doesnt-work-in-kibana-after-login-with-a-user-created-under-internal-users/1215/8 "2018-12-05T11:01:29Z")

</div>

Yes, for splitting dashboards and visualizations by role/tenant you need to use the multi-tenancy feature.

Your understanding of the role system is correct, but I would rephrase it a bit:

You create new users and then map those users to Search Guard roles by using the roles mapping. You can map users by their backend role(s) and also directly by their username. Using backend roles is the preferred way because it gives you more flexibility.

> **···**
>
> On Wednesday, December 5, 2018 at 9:56:47 AM UTC+1, [marc.zominy@hoomano.com](mailto:marc.zominy@hoomano.com) wrote:
> 
> > Maybe I can reply from what I’ve learnt, Jochen may complete or correct my answer.
> 
> > You seem to have understood the roles system.
> 
> > 
> 
> > If you want to split what dashboards and visualizations users can see in Kibana, you will have to look towards the multi tenany system described here: [https://docs.search-guard.com/latest/kibana-multi-tenancy](https://docs.search-guard.com/latest/kibana-multi-tenancy)
> > 
> > Hope it helps!
