# Sg\_kibana\_user role doesn't let users use Kibana

**URL:** <https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693>\
**Category:** Search Guard\
**Created:** [November 7, 2019, 5:38pm UTC](https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693 "2019-11-07T17:38:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikew](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@mikew](https://forum.search-guard.com/u/mikew)\
**Post date:** [November 7, 2019, 5:38pm UTC](https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693/1 "2019-11-07T17:38:26Z")

</div>

search-guard-6-6.8.4-25.5.zip  
search-guard-kibana-plugin-6.8.4-18.5.zip

Install Demo per [Demo Installer (Linux/Mac) | Elasticsearch Security | Search Guard](https://docs.search-guard.com/6.x-25/demo-installer)

Define user `alice` in `sg_internal_users.yml`

```
alice:
  readonly: true
  hash: $2y$12$xGK4NJredact
  roles:
    - sg_kibana_user

```

` sg_kibana_user` role is as provided by demo installer:

```
sg_kibana_user:
  readonly: true
  cluster:
    - INDICES_MONITOR
    - CLUSTER_COMPOSITE_OPS
  indices:
    '?kibana':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana-6':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana_*':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?tasks':
      '*':
        - INDICES_ALL
    '?management-beats':
      '*':
        - INDICES_ALL
    '*':
      '*':
        - indices:data/read/field_caps*
        - indices:data/read/xpack/rollup*
        - indices:admin/mappings/get*
        - indices:admin/get

```

Log in to Kibana as `alice` and all that is displayed is this:

`{"message":"no permissions for [indices:data/read/search] and User [name=alice, roles=[sg_kibana_user], requestedTenant=null]: [security_exception] no permissions for [indices:data/read/search] and User [name=alice, roles=[sg_kibana_user], requestedTenant=null]","statusCode":403,"error":"Forbidden"}`

In `/var/log/elasticsearch/searchguard_demo.log` is

```
[2019-11-07T17:33:55,502][INFO][c.f.s.p.PrivilegesEvaluator] [P053Uyn] No index-level perm match for User [name=alice, roles=[sg_kibana_user], requestedTenant=null] Resolved [aliases=[.kibana], indices=[], allIndices=[.kibana_1], types=[*], originalRequested=[.kibana], remoteIndices=[]] [Action [indices:data/read/search]] [RolesChecked [sg_own_index]]
[2019-11-07T17:33:55,502][INFO][c.f.s.p.PrivilegesEvaluator] [P053Uyn] No permissions for [indices:data/read/search]

```

If I give `alice` the `admin` role then Kibana works fine. I’ve tried explicitly adding `indices:data/read/search` to the `sg_kibana_user` role but it doesn’t help. (Nor would I expect it to given what `READ` expands to.)

---

<div class="post-metadata">

**Author:** ![hsaly](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/hsaly/32/21_2.png) [@hsaly](https://forum.search-guard.com/u/hsaly)\
**Post date:** [November 11, 2019, 9:14pm UTC](https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693/2 "2019-11-11T21:14:35Z")

</div>

Please refer to [Roles mapping | Security for Elasticsearch | Search Guard](https://docs.search-guard.com/latest/first-steps-mapping-users-roles#roles-mapping-concept) and try

```auto
alice:
  readonly: true
  hash: $2y$12$xGK4NJredact
  roles:
    - kibanauser

```

---

<div class="post-metadata">

**Author:** ![mikew](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@mikew](https://forum.search-guard.com/u/mikew)\
**Post date:** [November 12, 2019, 3:23pm UTC](https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693/3 "2019-11-12T15:23:31Z")

</div>

Your example is inconsistent with the webpage you cite

> **[Mapping users to Search Guard roles](https://docs.search-guard.com/latest/first-steps-mapping-users-roles#roles-mapping-concept)**
>
> How to map users to Search Guard roles to assign cluster- and index-level access permissions.

where the examples show an attribute called `backend_roles` not `roles`. But that webpage is for a different version of Search Guard than I said I’m using. The equivalent page for the version I’m using is

> **[Mapping users to Search Guard roles](https://docs.search-guard.com/6.x-25/first-steps-mapping-users-roles)**
>
> How to map users to Search Guard roles to assign cluster- and index-level access permissions.

and your example is also inconsistent with that as it shows defining an attribute called `backendroles`. But I think that webpage is wrong because

> **[Adding users](https://docs.search-guard.com/6.x-25/first-steps-user-configuration)**
>
> How to add new Search Guard users by using sgctl and the Search Guard configuration.

shows defining an attribute called `roles`.

Anyway, all that confusing inconsistency and possibly wrongness aside, I already got things working as after making this post but left it open to see what was suggested as a solution. The way I’ve done it doesn’t involve specifying any roles or backendroles or backend\_roles as part of the user definition.

In `sg_internal_users.yml`

```
bob:
  readonly: true
  hash: $2y$12$redact

alice:
  readonly: true
  hash: $2y$12$redact

harold:
  readonly: true
  hash: $2y$12$redact

```

In `sg_roles_mapping.yml`

```
sg_kibana_user:
  backendroles:
    - kibanauser
  users:
    - alice
    - bob

sg_readall:
  readonly: true
  backendroles:
    - readall
    - alice
    - bob

this_is_red_team_role:
  users:
    - bob
    - alice

this_is_blue_team_role:
  users:
    - harold
    - alice

```

In `sg_roles.yml`

```
this_is_blue_team_role:
  readonly: true
  cluster:
    - INDICES_MONITOR
    - CLUSTER_COMPOSITE_OPS
    - indices:data/read/search
  indices:
    '?kibana':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana-6':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana_*':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?tasks':
      '*':
        - INDICES_ALL
    '?management-beats':
      '*':
        - INDICES_ALL
    '*':
      '*':
        - indices:data/read/field_caps*
        - indices:data/read/xpack/rollup*
        - indices:admin/mappings/get*
        - indices:admin/get
    'kibana_sample_data_logs':
      '*':
        - READ
  tenants:
    blue_team: "RW"
                           

this_is_red_team_role:
  readonly: true
  cluster:
    - INDICES_MONITOR
    - CLUSTER_COMPOSITE_OPS
    - indices:data/read/search
  indices:
    '?kibana':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana-6':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana_*':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?tasks':
      '*':
        - INDICES_ALL
    '?management-beats':
      '*':
        - INDICES_ALL
    '*':
      '*':
        - indices:data/read/field_caps*
        - indices:data/read/xpack/rollup*
        - indices:admin/mappings/get*
        - indices:admin/get
    'kibana_sample_data_logs':
      '*':
        - READ
  tenants:
    red_team: "RW"

this_is_alice_role:
  readonly: true
  cluster:
    - INDICES_MONITOR
    - CLUSTER_COMPOSITE_OPS
    - indices:data/read/search
  indices:
    '?kibana':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana-6':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana_*':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?tasks':
      '*':
        - INDICES_ALL
    '?management-beats':
      '*':
        - INDICES_ALL
    '*':
      '*':
        - indices:data/read/field_caps*
        - indices:data/read/xpack/rollup*
        - indices:admin/mappings/get*
        - indices:admin/get
    'kibana_sample_data_logs':
      '*':
        - READ
  tenants:
    alice_stuff: "RW"

this_is_bob_role:
  readonly: true
  cluster:
    - INDICES_MONITOR
    - CLUSTER_COMPOSITE_OPS
  indices:
    '?kibana':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana-6':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?kibana_*':
      '*':
        - MANAGE
        - INDEX
        - READ
        - DELETE
    '?tasks':
      '*':
        - INDICES_ALL
    '?management-beats':
      '*':
        - INDICES_ALL
    '*':
      '*':
        - indices:data/read/field_caps*
        - indices:data/read/xpack/rollup*
        - indices:admin/mappings/get*
        - indices:admin/get
  tenants:
    bob_stuff: "RW"

```

The above config all part of a proof of concept for Kibana multitenancy but the concept is how we do things in our production environment where most of the users we need to assign to roles come from LDAP. We define our own roles in `sg_roles.yml`, just the names and password hashes for some users like `kibana_server` are defined in `sg_internal_users.yml` and everything about which roles users are in is done in `sg_roles_mapping.yml`.

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [December 3, 2019, 3:35pm UTC](https://forum.search-guard.com/t/sg-kibana-user-role-doesnt-let-users-use-kibana/1693/4 "2019-12-03T15:35:20Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
