# Permissions for saving a search

**URL:** <https://forum.search-guard.com/t/permissions-for-saving-a-search/2462>\
**Category:** Search Guard\
**Created:** [September 7, 2023, 6:33am UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462 "2023-09-07T06:33:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ossenfeld](https://avatars.discourse-cdn.com/v4/letter/o/7ea924/32.png) [@Ossenfeld](https://forum.search-guard.com/u/Ossenfeld)\
**Post date:** [September 7, 2023, 6:33am UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/1 "2023-09-07T06:33:28Z")

</div>

Hello,

currently, the users got read only permissions on certain indices from the action group SGS\_CLUSTER\_COMPOSITE\_OPS\_RO. Apparently, this leads to them not being able to save a search because of “indices:data/write/index”.  
I assume it’s because the search would be written to a .kibana index. Is there any way to work around this issue without giving users permissions to write and delete documents (SGS\_WRITE)?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.search-guard.com/u/Eugene7)\
**Post date:** [September 7, 2023, 5:10pm UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/2 "2023-09-07T17:10:41Z")

</div>

Hello @Ossenfeld,  
SGS\_KIBANA\_USER role has permission to save a search. You can use `SGS_KIBANA_USER` as an example in order to allow the user to save the search.

---

<div class="post-metadata">

**Author:** ![Ossenfeld](https://avatars.discourse-cdn.com/v4/letter/o/7ea924/32.png) [@Ossenfeld](https://forum.search-guard.com/u/Ossenfeld)\
**Post date:** [September 12, 2023, 7:31am UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/3 "2023-09-12T07:31:17Z")

</div>

Thanks, this might fix it for now. SGS\_KIBANA\_USER includes the cluster-level action group SGS\_CLUSTER\_COMPOSITE\_OPS, which “also grants bulk write permissions and all aliases permissions”.  
What exacly does that mean? Like, how and where can a user write and what’s meant with aliases permissions?

---

<div class="post-metadata">

**Author:** ![Ossenfeld](https://avatars.discourse-cdn.com/v4/letter/o/7ea924/32.png) [@Ossenfeld](https://forum.search-guard.com/u/Ossenfeld)\
**Post date:** [September 12, 2023, 8:28am UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/4 "2023-09-12T08:28:58Z")

</div>

It’s not working with SGS\_CLUSTER\_COMPOSITE\_OPS added to my specific role. What is that SGS\_KIBANA\_USER adds, so users can save a search?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.search-guard.com/u/Eugene7)\
**Post date:** [September 18, 2023, 1:38pm UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/5 "2023-09-18T13:38:25Z")

</div>

Hi @Ossenfeld  
You need to enable access to `.kibana*` indexes. Action groups are SGS\_DELETE , SGS\_INDEX , SGS\_MANAGE , SGS\_READ.

---

<div class="post-metadata">

**Author:** ![Ossenfeld](https://avatars.discourse-cdn.com/v4/letter/o/7ea924/32.png) [@Ossenfeld](https://forum.search-guard.com/u/Ossenfeld)\
**Post date:** [September 26, 2023, 5:46am UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/6 "2023-09-26T05:46:06Z")

</div>

Unfortunately, this doesn’t work without adding the the action group “SGS\_KIBANA\_ALL\_WRITE” to the specific tenant. So this works, although the user doesnt have the mentioned action groups:

![image](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/e/e3ddfcd7cacceed24d22e16577a04d369a52708f.png)

![image](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/4/427ade8519e86de925b1bd86361301be5705eee7.png)

This doesn’t work:

![image](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/7/76b1d9403987ca81fdf1153ee2ef1823db73a112.png)

![image](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/6/699b2e8d770bdcd24398a18439039abaf062a9d5.png)

I guess the action group “SGS\_KIBANA\_ALL\_WRITE” adds something else. Do you knoiw what else?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.search-guard.com/u/Eugene7)\
**Post date:** [September 28, 2023, 1:29pm UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/7 "2023-09-28T13:29:24Z")

</div>

What version of ElasticSearch and SearchGuard do you use?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.search-guard.com/u/Eugene7)\
**Post date:** [October 9, 2023, 2:06pm UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/9 "2023-10-09T14:06:52Z")

</div>

@Ossenfeld

If a user logs in to Kibana, it should be a role mapping between the default role called SGS\_KIBANA\_USER and the end-user. The user can save the search using the SGS\_KIBANA\_USER role.

Then, separately, there should be a custom role that defines:  
a) the permissions for the “regular” / “data” / non-Kibana indices, and  
b) the “Tenant” permissions

Finally, there should be a mapping between this custom role and the user.

If you have any questions, please let me know.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [October 30, 2023, 2:07pm UTC](https://forum.search-guard.com/t/permissions-for-saving-a-search/2462/10 "2023-10-30T14:07:01Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
