Back to Beats

Grant privileges and roles needed to read Auditbeat data from {{kib}} [kibana-user-privileges]

docs/reference/auditbeat/kibana-user-privileges.md

9.4.01004 B
Original Source

Grant privileges and roles needed to read Auditbeat data from {{kib}} [kibana-user-privileges]

{{kib}} users typically need to view dashboards and visualizations that contain Auditbeat data. These users might also need to create and edit dashboards and visualizations.

To grant users the required privileges:

  1. Create a reader role, called something like auditbeat_reader, that has the following privilege:

    TypePrivilegePurpose
    Indexread on auditbeat-* indicesRead data indexed by Auditbeat
    SpacesRead or All on Dashboards, Visualize, and DiscoverAllow the user to view, edit, and create dashboards, as well as browse data.
  2. Assign the reader role, along with the following built-in roles, to users who need to read Auditbeat data:

    RolePurpose
    monitoring_userAllow users to monitor the health of Auditbeat itself. Only assign this role to users who manage Auditbeat.