# User access kibana

**URL:** <https://forum.search-guard.com/t/user-access-kibana/169>\
**Category:** Search Guard\
**Created:** [May 17, 2016, 2:40pm UTC](https://forum.search-guard.com/t/user-access-kibana/169 "2016-05-17T14:40:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cedric\_moreaux](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@cedric\_moreaux](https://forum.search-guard.com/u/cedric_moreaux)\
**Post date:** [May 17, 2016, 2:40pm UTC](https://forum.search-guard.com/t/user-access-kibana/169/1 "2016-05-17T14:40:14Z")

</div>

Hello,

I want to centralize logs of differents servers hosting differents services. Each services has his index and i want to create one user per index to let them access there own data see data from other indexes.

Actualy, if I created a user services02-adm in group services\_filebeat and give this group right to access the indexes filebeat-services02-adm-\*

services\_filebeat:  
indices:  
filebeat-services02-adm-_:  
- '_’

services\_filebeat:  
users:  
- services02-adm

i get this error when trying to log in kibana:

Courier Fetch Error: unhandled courier request error: [security\_exception] no permissions for indices:data/read/mget  
Version: 4.5.0  
Build: 9889

Error: unhandled courier request error: [security\_exception] no permissions for indices:data/read/mget  
handleError@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88553:23](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88553:23)  
AbstractReqProvider/AbstractReq.prototype.handleFailure@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88473:15](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88473:15)  
callClient/\</\<@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88367:14](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88367:14)  
callClient/\<@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88365:10](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88365:10)  
processQueue@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29](http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29)  
scheduleProcessQueue/\<@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28](http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28)  
$RootScopeProvider/this.$get\</Scope.prototype.$eval@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17](http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17)  
$RootScopeProvider/this.$get\</Scope.prototype.$digest@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16](http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16)  
$RootScopeProvider/this.$get\</Scope.prototype.$apply@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14](http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14)  
done@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37)  
completeRequest@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8)  
requestLoaded@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1)

``

```auto

If i had this user to the group sg_kibana4, he can access kibana but he get access to others index too.

How can i restrict his access to only one index?

Regards

```

---

<div class="post-metadata">

**Author:** ![cedric\_moreaux](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@cedric\_moreaux](https://forum.search-guard.com/u/cedric_moreaux)\
**Post date:** [May 18, 2016, 1:50pm UTC](https://forum.search-guard.com/t/user-access-kibana/169/2 "2016-05-18T13:50:51Z")

</div>

To simplify my question, which right are required to authorize a user to access Kibana?

Regards

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [May 19, 2016, 3:14pm UTC](https://forum.search-guard.com/t/user-access-kibana/169/3 "2016-05-19T15:14:46Z")

</div>

i assume you need something like

services\_filebeat:  
indices:  
&nbsp;&nbsp;&nbsp;filebeat-services02-adm-\*: #index  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*': #type  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- READ #permission  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\* #permission  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query #permission  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/get #permission  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'?kibana': #index  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*': #type  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/exists\* #permission  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mapping/put\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/refresh\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/get\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/mget\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/search\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/delete\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/index\*  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/update\*

instead of

services\_filebeat:  
indices:  
&nbsp;&nbsp;&nbsp;filebeat-services02-adm-\*:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- '\*'

> **···**
>
> > Am 17.05.2016 um 16:40 schrieb cedric moreaux \<misterced91@gmail.com\>:
> > 
> > Hello,
> > 
> > I want to centralize logs of differents servers hosting differents services. Each services has his index and i want to create one user per index to let them access there own data see data from other indexes.
> > 
> > Actualy, if I created a user services02-adm in group services\_filebeat and give this group right to access the indexes filebeat-services02-adm-\*
> > 
> > services\_filebeat:  
> > &nbsp;&nbsp;indices:  
> > &nbsp;&nbsp;&nbsp;&nbsp;filebeat-services02-adm-\*:  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- '\*'
> > 
> > services\_filebeat:  
> > &nbsp;&nbsp;users:  
> > &nbsp;&nbsp;&nbsp;&nbsp;- services02-adm
> > 
> > i get this error when trying to log in kibana:
> > 
> > Courier Fetch Error: unhandled courier request error: [security\_exception] no permissions for indices:data/read/mget  
> > Version: 4.5.0  
> > Build: 9889
> > 
> > Error: unhandled courier request error: [security\_exception] no permissions for indices:data/read/mget  
> > handleError@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88553:23](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88553:23)  
> > AbstractReqProvider/AbstractReq.prototype.handleFailure@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88473:15](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88473:15)  
> > callClient/\</\<@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88367:14](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88367:14)  
> > callClient/\<@[http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88365:10](http://192.168.1.217/bundles/kibana.bundle.js?v=9889:88365:10)  
> > processQueue@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29](http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29)  
> > scheduleProcessQueue/\<@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28](http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28)  
> > $RootScopeProvider/this.$get\</Scope.prototype.$eval@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17](http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17)  
> > $RootScopeProvider/this.$get\</Scope.prototype.$digest@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16](http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16)  
> > $RootScopeProvider/this.$get\</Scope.prototype.$apply@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14](http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14)  
> > done@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37)  
> > completeRequest@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8)  
> > requestLoaded@[http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1](http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1)
> > 
> > If i had this user to the group sg\_kibana4, he can access kibana but he get access to others index too.
> > 
> > How can i restrict his access to only one index?
> > 
> > Regards
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/e1cbbe10-6368-4d49-9d96-ceb2383d07b1%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/e1cbbe10-6368-4d49-9d96-ceb2383d07b1%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![cedric\_moreaux](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@cedric\_moreaux](https://forum.search-guard.com/u/cedric_moreaux)\
**Post date:** [May 20, 2016, 9:36am UTC](https://forum.search-guard.com/t/user-access-kibana/169/4 "2016-05-20T09:36:11Z")

</div>

With this i get 2 errors at kibana loading:

```auto
Error: [security_exception] no permissions for indices:data/read/field_stats
ErrorAbstract@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62833:20
StatusCodeError@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62995:6
respond@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:64200:16
checkRespForFailure@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:64163:8
[24]</AngularConnector.prototype.request/<@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62781:8
processQueue@http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29
scheduleProcessQueue/<@http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28
$RootScopeProvider/this.$get</Scope.prototype.$eval@http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17
$RootScopeProvider/this.$get</Scope.prototype.$digest@http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16
$RootScopeProvider/this.$get</Scope.prototype.$apply@http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14
done@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37
completeRequest@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8
requestLoaded@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1

```

``

And

```auto
Error: [security_exception] no permissions for indices:data/read/msearch
ErrorAbstract@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62833:20
StatusCodeError@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62995:6
respond@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:64200:16
checkRespForFailure@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:64163:8
[24]</AngularConnector.prototype.request/<@http://192.168.1.217/bundles/kibana.bundle.js?v=9889:62781:8
processQueue@http://192.168.1.217/bundles/commons.bundle.js?v=9889:41836:29
scheduleProcessQueue/<@http://192.168.1.217/bundles/commons.bundle.js?v=9889:41852:28
$RootScopeProvider/this.$get</Scope.prototype.$eval@http://192.168.1.217/bundles/commons.bundle.js?v=9889:43080:17
$RootScopeProvider/this.$get</Scope.prototype.$digest@http://192.168.1.217/bundles/commons.bundle.js?v=9889:42891:16
$RootScopeProvider/this.$get</Scope.prototype.$apply@http://192.168.1.217/bundles/commons.bundle.js?v=9889:43188:14
done@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37637:37
completeRequest@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37835:8
requestLoaded@http://192.168.1.217/bundles/commons.bundle.js?v=9889:37776:1

```

``

The fact is i have others indexes named filebeat-“server-name”-“date”.  
If i modify the line  
filebeat-services02-adm-\*

``

to  
filebeat-\*:

``

it work, but the user can see data from all indexes 😕

Is there a solution?

Regards

---

<div class="post-metadata">

**Author:** ![cedric\_moreaux](https://avatars.discourse-cdn.com/v4/letter/c/57b2e6/32.png) [@cedric\_moreaux](https://forum.search-guard.com/u/cedric_moreaux)\
**Post date:** [May 20, 2016, 9:53am UTC](https://forum.search-guard.com/t/user-access-kibana/169/5 "2016-05-20T09:53:05Z")

</div>

I found a solution,  
services\_filebeat:  
indices:  
‘_':  
'_’:  
- indices:data/read/field\_stats  
- indices:data/read/msearch  
‘filebeat-service02\*’:  
'_':  
- READ  
- indices:admin/mappings/fields/get_  
- indices:admin/validate/query  
- indices:admin/get  
‘?kibana’:  
'_':  
- indices:admin/exists_  
- indices:admin/mapping/put\*  
- indices:admin/mappings/fields/get\*  
- indices:admin/refresh\*  
- indices:admin/validate/query\*  
- indices:data/read/get\*  
- indices:data/read/mget\*  
- indices:data/read/search\*  
- indices:data/read/msearch  
- indices:data/read/field\_stats  
- indices:data/write/delete\*  
- indices:data/write/index\*  
- indices:data/write/update\*  
- indices:admin/mappings/fields/get\*

``

If i had the two missing rights on \* it works, i just get an error : Discover: no permissions for indices:data/read/search  
If i had this right, the user can see everything, but i ignore the error i can just see data from his index.

Thanks!

---

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 20, 2016, 1:57am UTC](https://forum.search-guard.com/t/user-access-kibana/169/6 "2016-06-20T01:57:18Z")

</div>

Hi, i have some issues like you , the config is here:  
sg\_apache\_tomcat:

indices:

‘\*’:

‘\*’:

- indices:data/read/field\_stats

- indices:data/read/msearch

‘apache\_tomcat\*’:

‘\*’:

- READ

- indices:admin/mappings/fields/get\*

- indices:admin/validate/query

- indices:admin/get

- indices:data/read/field\_stats

‘?kibana’:

‘\*’:

- indices:admin/exists\*

- indices:admin/mapping/put\*

- indices:admin/mappings/fields/get\*

- indices:admin/refresh\*

- indices:admin/validate/query\*

- indices:data/read/get\*

- indices:data/read/mget\*

- indices:data/read/search\*

- indices:data/read/msearch

- indices:data/read/field\_stats

- indices:data/write/delete\*

- indices:data/write/index\*

- indices:data/write/update\*

- indices:admin/mappings/fields/get\*

And i got the errors:

Discover: no permissions for indices:data/read/search

But i can’t see the index of “apache-tomcat\*”. What is the errors???

在 2016年5月20日星期五 UTC+8下午5:53:05，cedric moreaux写道：

> **···**
>
> > I found a solution,  
> > services\_filebeat:  
> > indices:  
> > ‘_':  
> > '_’:  
> > - indices:data/read/field\_stats  
> > - indices:data/read/msearch  
> > ‘filebeat-service02\*’:  
> > '_':  
> > - READ  
> > - indices:admin/mappings/fields/get_  
> > - indices:admin/validate/query  
> > - indices:admin/get  
> > ‘?kibana’:  
> > '_':  
> > - indices:admin/exists_  
> > - indices:admin/mapping/put\*  
> > - indices:admin/mappings/fields/get\*  
> > - indices:admin/refresh\*  
> > - indices:admin/validate/query\*  
> > - indices:data/read/get\*  
> > - indices:data/read/mget\*  
> > - indices:data/read/search\*  
> > - indices:data/read/msearch  
> > - indices:data/read/field\_stats  
> > - indices:data/write/delete\*  
> > - indices:data/write/index\*  
> > - indices:data/write/update\*  
> > - indices:admin/mappings/fields/get\*
> 
> > ``
> 
> > If i had the two missing rights on \* it works, i just get an error : Discover: no permissions for indices:data/read/search  
> > If i had this right, the user can see everything, but i ignore the error i can just see data from his index.
> > 
> > Thanks!

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [June 20, 2016, 8:08am UTC](https://forum.search-guard.com/t/user-access-kibana/169/7 "2016-06-20T08:08:10Z")

</div>

'apache\_tomcat\*' does not match "apache-tomcat\*" (underscore != dash)

> **···**
>
> > Am 20.06.2016 um 03:57 schrieb Wei Hong \<fzuerhw@gmail.com\>:
> > 
> > Hi, i have some issues like you , the config is here:  
> > sg\_apache\_tomcat:  
> > &nbsp;&nbsp;indices:  
> > &nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/field\_stats  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/msearch  
> > &nbsp;&nbsp;&nbsp;&nbsp;'apache\_tomcat\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- READ  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/get  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/field\_stats  
> > &nbsp;&nbsp;&nbsp;&nbsp;'?kibana':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/exists\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mapping/put\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/refresh\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/mget\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/search\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/msearch  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/field\_stats  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/delete\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/index\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/update\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
> > &nbsp;&nbsp;  
> > And i got the errors:  
> > Discover: no permissions for indices:data/read/search
> > 
> > But i can't see the index of "apache-tomcat\*". What is the errors???
> > 
> > 在 2016年5月20日星期五 UTC+8下午5:53:05，cedric moreaux写道：  
> > I found a solution,  
> > services\_filebeat:  
> > &nbsp;&nbsp;indices:  
> > &nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/field\_stats  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/msearch  
> > &nbsp;&nbsp;&nbsp;&nbsp;'filebeat-service02\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- READ  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/get  
> > &nbsp;&nbsp;&nbsp;&nbsp;'?kibana':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;'\*':  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/exists\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mapping/put\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/refresh\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/validate/query\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/get\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/mget\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/search\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/msearch  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/read/field\_stats  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/delete\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/index\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:data/write/update\*  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;- indices:admin/mappings/fields/get\*
> > 
> > If i had the two missing rights on \* it works, i just get an error : Discover: no permissions for indices:data/read/search  
> > If i had this right, the user can see everything, but i ignore the error i can just see data from his index.
> > 
> > Thanks!
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/55ab6d48-aad0-43e1-80ff-0bbcd222cbc6%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/55ab6d48-aad0-43e1-80ff-0bbcd222cbc6%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).

---

<div class="post-metadata">

**Author:** ![Wei\_Hong](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@Wei\_Hong](https://forum.search-guard.com/u/Wei_Hong)\
**Post date:** [June 20, 2016, 8:54am UTC](https://forum.search-guard.com/t/user-access-kibana/169/8 "2016-06-20T08:54:48Z")

</div>

Thanks, i am so careless.

在 2016年6月20日星期一 UTC+8下午4:08:13，SG写道：

> **···**
>
> > ‘apache\_tomcat\*’ does not match “apache-tomcat\*” (underscore != dash)
> > 
> > > Am 20.06.2016 um 03:57 schrieb Wei Hong [fzu...@gmail.com](mailto:fzu...@gmail.com):
> > 
> > > Hi, i have some issues like you , the config is here:
> > 
> > > sg\_apache\_tomcat:
> > 
> > > indices:
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/field_stats
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/msearch
> > > 
> > > ```
> > 
> > > ```
> > > 'apache_tomcat*':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - READ
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/validate/query
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/get
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/field_stats
> > > 
> > > ```
> > 
> > > ```
> > > '?kibana':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/exists*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mapping/put*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/refresh*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/validate/query*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/mget*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/search*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/msearch
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/field_stats
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/delete*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/index*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/update*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > And i got the errors:
> > 
> > > Discover: no permissions for indices:data/read/search
> > 
> > > But i can’t see the index of “apache-tomcat\*”. What is the errors???
> > 
> > > 在 2016年5月20日星期五 UTC+8下午5:53:05，cedric moreaux写道：
> > 
> > > I found a solution,  
> > > services\_filebeat:
> > 
> > > indices:
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/field_stats
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/msearch
> > > 
> > > ```
> > 
> > > ```
> > > 'filebeat-service02*':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - READ
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/validate/query
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/get
> > > 
> > > ```
> > 
> > > ```
> > > '?kibana':
> > > 
> > > ```
> > 
> > > ```
> > > '*':
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/exists*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mapping/put*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/refresh*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/validate/query*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/get*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/mget*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/search*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/msearch
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/read/field_stats
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/delete*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/index*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:data/write/update*
> > > 
> > > ```
> > 
> > > ```
> > > - indices:admin/mappings/fields/get*
> > > 
> > > ```
> > 
> > > If i had the two missing rights on \* it works, i just get an error : Discover: no permissions for indices:data/read/search
> > 
> > > If i had this right, the user can see everything, but i ignore the error i can just see data from his index.
> > 
> > > Thanks!
> > 
> > > –  
> > > You received this message because you are subscribed to the Google Groups “Search Guard” group.
> > 
> > > To unsubscribe from this group and stop receiving emails from it, send an email to [search-guard...@googlegroups.com](mailto:search-guard...@googlegroups.com).
> > 
> > > To post to this group, send email to [search...@googlegroups.com](mailto:search...@googlegroups.com).
> > 
> > > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/55ab6d48-aad0-43e1-80ff-0bbcd222cbc6%40googlegroups.com](https://groups.google.com/d/msgid/search-guard/55ab6d48-aad0-43e1-80ff-0bbcd222cbc6%40googlegroups.com).
> > 
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
