# problem to create my user with the right rights

**URL:** https://forum.search-guard.com/t/problem-to-create-my-user-with-the-right-rights/1009
**Category:** Search Guard
**Created:** [July 11, 2018, 1:24pm UTC](https://forum.search-guard.com/t/problem-to-create-my-user-with-the-right-rights/1009 "2018-07-11T13:24:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Dylan\_Osef](https://avatars.discourse-cdn.com/v4/letter/d/54ee81/32.png) [@Dylan\_Osef](https://forum.search-guard.com/u/Dylan_Osef)
#### Post date: [July 11, 2018, 1:24pm UTC](https://forum.search-guard.com/t/problem-to-create-my-user-with-the-right-rights/1009/1 "2018-07-11T13:24:42Z")

</div>

Hello,

I try to create :

- User “mno”

- This user is able to readonly only the indices “vegaproduem”.

So I create : My user “mno”

[![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/2/27e5b057139c2bffc09fd7b3ce8c798110cde068.jpeg)](https://lh3.googleusercontent.com/-GyiMuS_j-h0/W0YDs-VxO2I/AAAAAAAAAG0/toRhgyZDiwg9pNSvUVavM1Quy2R-2topgCLcBGAs/s1600/z.JPG)

And then I create my custom “role” : (cluster/indices permissions on same screen) :

Cluster permissions : CLUSTER\_COMPOSITE\_OPS\_RO

Indices permissions : on index vegaproduem all document and action groups “read”

[![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/b/bb0fca70b45d5e536a1b9ae4525a4a0b6f90f941.png)](https://lh3.googleusercontent.com/-UVQf6rzOgjc/W0YEMNkl4FI/AAAAAAAAAHA/GHx4EuZGSWYC97MXN6HCgTBXKBsMssjNQCLcBGAs/s1600/Sans%2Btitre.png)

And to conclude, I mapped my user with his new role :

[![](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/2X/e/eda24c6df37744677a14bb8ca38082468055ba2d.jpeg)](https://lh3.googleusercontent.com/-sE9jAZfYCAA/W0YEpjwfEYI/AAAAAAAAAHI/FkFdlSaaEDMGP5jrJAk-Ljxa_NJQ3NfYgCLcBGAs/s1600/map.JPG)

So it’s OK my user gets his new right. But when I connect this user, everything is white, I can’t go on any field (dashboard, vizualise, discover …) everything stay white… I can only logout me lol

Do you know my error ?

Thx you

---

<div class="post-metadata">

### Author: ![Dylan\_Osef](https://avatars.discourse-cdn.com/v4/letter/d/54ee81/32.png) [@Dylan\_Osef](https://forum.search-guard.com/u/Dylan_Osef)
#### Post date: [July 11, 2018, 1:47pm UTC](https://forum.search-guard.com/t/problem-to-create-my-user-with-the-right-rights/1009/2 "2018-07-11T13:47:02Z")

</div>

I found my error.

I didn’t add the .kibana index read permissions 🙂

---

<div class="post-metadata">

### Author: ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)
#### Post date: [July 11, 2018, 1:57pm UTC](https://forum.search-guard.com/t/problem-to-create-my-user-with-the-right-rights/1009/3 "2018-07-11T13:57:29Z")

</div>

Yes, every Kibana user needs to have access to the .kibana index. That’s what the built-in sg\_kibana\_user role is for:

> **[Demo users and roles](https://docs.search-guard.com/latest/demo-users-roles)**
>
> Description of the demo users and roles Search Guard ships with. Use them as blueprint for your own permission schema.

> **···**
>
> On Wednesday, July 11, 2018 at 3:47:02 PM UTC+2, Dylan Osef wrote:
> 
> > I found my error.
> 
> > 
> 
> > I didn’t add the .kibana index read permissions 🙂
> 
> > 
> 
> >
