Back to Beats

Grant privileges and roles needed to read Filebeat data from {{kib}} [kibana-user-privileges]

docs/reference/filebeat/kibana-user-privileges.md

9.4.01.1 KB
Original Source

Grant privileges and roles needed to read Filebeat data from {{kib}} [kibana-user-privileges]

{{kib}} users typically need to view dashboards and visualizations that contain Filebeat data. These users might also need to create and edit dashboards and visualizations.

To grant users the required privileges:

  1. Create a reader role, called something like filebeat_reader, that has the following privilege:

    TypePrivilegePurpose
    Indexread on filebeat-* indicesRead data indexed by Filebeat
    SpacesRead or All on Dashboards, Visualize, and DiscoverAllow the user to view, edit, and create dashboards, as well as browse data.
    SpacesRead or All on {{kib}} LogsAllow the use of {{kib}} Logs
  2. Assign the reader role, along with the following built-in roles, to users who need to read Filebeat data:

    RolePurpose
    monitoring_userAllow users to monitor the health of Filebeat itself. Only assign this role to users who manage Filebeat.