WARNING: Version 6.1 of Auditbeat has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
Granting Users Access to Auditbeat Indices
editGranting Users Access to Auditbeat Indices
editTo enable users to access the indices a Auditbeat creates, grant them read
and view_index_metadata
privileges on the Auditbeat indices:
-
Create a role that has the
read
andview_index_metadata
privileges for the Auditbeat indices. You can create roles from the Management > Roles UI in Kibana or through therole
API. For example, the following request creates aauditbeat_reader
role: -
Assign your users the reader role so they can access the Auditbeat indices:
-
If you’re using the
native
realm, you can assign roles with the Management > Users UI in Kibana or through theuser
API. For example, the following request grantsauditbeat_user
theauditbeat_reader
role:POST /_xpack/security/user/auditbeat_user { "password" : "x-pack-test-password", "roles" : [ "auditbeat_reader"], "full_name" : "Auditbeat User" }
-
If you’re using the LDAP, Active Directory, or PKI realms, you assign the roles in the
role_mapping.yml
configuration file. For example, the following snippet grantsAuditbeat User
theauditbeat_reader
role:auditbeat_reader: - "cn=Auditbeat User,dc=example,dc=com"
For more information, see Using Role Mapping Files.
-