# No permissions for \[indices:data/read/field\_caps\] and User \[name=kibanaserver, roles=\[\], requestedT\]

**URL:** <https://forum.search-guard.com/t/no-permissions-for-indices-data-read-field-caps-and-user-name-kibanaserver-roles-requestedt/706>\
**Category:** Search Guard\
**Created:** [December 7, 2017, 3:49pm UTC](https://forum.search-guard.com/t/no-permissions-for-indices-data-read-field-caps-and-user-name-kibanaserver-roles-requestedt/706 "2017-12-07T15:49:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![CuriousOne](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@CuriousOne](https://forum.search-guard.com/u/CuriousOne)\
**Post date:** [December 7, 2017, 3:49pm UTC](https://forum.search-guard.com/t/no-permissions-for-indices-data-read-field-caps-and-user-name-kibanaserver-roles-requestedt/706/1 "2017-12-07T15:49:45Z")

</div>

- Search Guard 6.0.0 + Elasticsearch 6.0.0

- openjdk 1.8.0 and CentOS 6.8

- Search Guard configuration files

cluster.name: my-es

node.name: node-0

path.data: /data/es

path.logs: /data/es/logs

bootstrap.memory\_lock: false

bootstrap.system\_call\_filter: false

network.host: 127.0.0.1

http.port: 9200

discovery.type: single-node

discovery.zen.ping.unicast.hosts: [“127.0.0.1”]

discovery.zen.minimum\_master\_nodes: 1

searchguard.ssl.transport.enabled: true

searchguard.ssl.transport.keystore\_filepath: node-0-keystore.jks

searchguard.ssl.transport.keystore\_password: mypass

searchguard.ssl.transport.truststore\_filepath: truststore.jks

searchguard.ssl.transport.truststore\_password: mypass

searchguard.ssl.transport.enforce\_hostname\_verification: false

searchguard.ssl.transport.resolve\_hostname: false

searchguard.ssl.http.enabled: true

searchguard.ssl.http.keystore\_filepath: node-0-keystore.jks

searchguard.ssl.http.keystore\_password: mypass

searchguard.ssl.http.truststore\_filepath: truststore.jks

searchguard.ssl.http.truststore\_password: mypass

searchguard.authcz.admin\_dn:

- CN=kirk,OU=client,O=client,L=Test, C=de

- Elasticsearch log messages on debug level

[INFO][c.f.s.c.PrivilegesEvaluator] No index-level perm match for User [name=kibanaserver, roles=, requestedTenant=null, attributes={}] [IndexType [index=logstash-_, type=_]] [Action [[indices:data/read/field\_caps]]] [RolesChecked [sg\_kibana\_server, sg\_own\_index]]

[INFO][c.f.s.c.PrivilegesEvaluator] No permissions for {sg\_own\_index=[IndexType [index=logstash-_, type=_]], sg\_kibana\_server=[IndexType [index=logstash-_, type=_]]}

> **···**
>
> * * *
> 
> I can login in Kibana with search guard. I use kibanaserver to login. However, the red bar on the top shows
> 
> [![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/b/bac3c38135a6fb9bcb1eb57bbde21e78f6de58bc.png)](https://forum.search-guard.com/uploads/short-url/qEcel1tyuHTCQEyeFTCfuWWsisI.png)
> 
> I tried to find any related answers about it. But no luck…that’s why i am asking around here. Wish to hear some good leads…thanks…

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [December 8, 2017, 10:23am UTC](https://forum.search-guard.com/t/no-permissions-for-indices-data-read-field-caps-and-user-name-kibanaserver-roles-requestedt/706/2 "2017-12-08T10:23:52Z")

</div>

The kibanaserver user/role is not suitable for regular Kibana user. It’s used by Kibana “under the hood” to perform management tasks / health checks etc.

Regular Kibana users should have the role sg\_kibana\_user, this role has the required field\_caps permissions set. In addition to this role, also assign permissions to the indices the user should have access to.

See also section “Configuring Elasticsearch: Adding Kibana users” in [Installing the Search Guard Kibana Plugin | Security for Elasticsearch | Search Guard](http://docs.search-guard.com/latest/kibana-plugin-installation)

> **···**
>
> On Thursday, December 7, 2017 at 4:49:46 PM UTC+1, CuriousOne wrote:
> 
> > - Search Guard 6.0.0 + Elasticsearch 6.0.0
> 
> > - openjdk 1.8.0 and CentOS 6.8
> 
> > - Search Guard configuration files
> 
> > 
> 
> > [cluster.name](http://cluster.name): my-es
> 
> > [node.name](http://node.name): node-0
> 
> > path.data: /data/es
> 
> > path.logs: /data/es/logs
> 
> > bootstrap.memory\_lock: false
> 
> > bootstrap.system\_call\_filter: false
> 
> > network.host: 127.0.0.1
> 
> > http.port: 9200
> 
> > 
> 
> > discovery.type: single-node
> 
> > discovery.zen.ping.unicast.hosts: [“127.0.0.1”]
> 
> > discovery.zen.minimum\_master\_nodes: 1
> 
> > 
> 
> > searchguard.ssl.transport.enabled: true
> 
> > searchguard.ssl.transport.keystore\_filepath: node-0-keystore.jks
> 
> > searchguard.ssl.transport.keystore\_password: mypass
> 
> > searchguard.ssl.transport.truststore\_filepath: truststore.jks
> 
> > searchguard.ssl.transport.truststore\_password: mypass
> 
> > searchguard.ssl.transport.enforce\_hostname\_verification: false
> 
> > searchguard.ssl.transport.resolve\_hostname: false
> 
> > 
> 
> > searchguard.ssl.http.enabled: true
> 
> > searchguard.ssl.http.keystore\_filepath: node-0-keystore.jks
> 
> > searchguard.ssl.http.keystore\_password: mypass
> 
> > searchguard.ssl.http.truststore\_filepath: truststore.jks
> 
> > searchguard.ssl.http.truststore\_password: mypass
> 
> > searchguard.authcz.admin\_dn:
> 
> > - CN=kirk,OU=client,O=client,L=Test, C=de
> 
> > 
> 
> > - Elasticsearch log messages on debug level
> 
> > [INFO][c.f.s.c.PrivilegesEvaluator] No index-level perm match for User [name=kibanaserver, roles=, requestedTenant=null, attributes={}] [IndexType [index=logstash-_, type=_]] [Action [[indices:data/read/field\_caps]]] [RolesChecked [sg\_kibana\_server, sg\_own\_index]]
> 
> > [INFO][c.f.s.c.PrivilegesEvaluator] No permissions for {sg\_own\_index=[IndexType [index=logstash-_, type=_]], sg\_kibana\_server=[IndexType [index=logstash-_, type=_]]}
> 
> > 
> 
> > * * *
> 
> > I can login in Kibana with search guard. I use kibanaserver to login. However, the red bar on the top shows
> 
> > [![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/b/bac3c38135a6fb9bcb1eb57bbde21e78f6de58bc.png)](https://forum.search-guard.com/uploads/short-url/qEcel1tyuHTCQEyeFTCfuWWsisI.png)
> 
> > 
> 
> > I tried to find any related answers about it. But no luck…that’s why i am asking around here. Wish to hear some good leads…thanks…
