#  How to prevent dashboard\_only\_user from editing or searching

**URL:** <https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753>\
**Category:** Security\
**Created:** [April 26, 2021, 1:19pm UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753 "2021-04-26T13:19:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![daiki\_1028](https://avatars.discourse-cdn.com/v4/letter/d/839c29/32.png) [@daiki\_1028](https://forum.opensearch.org/u/daiki_1028)\
**Post date:** [April 26, 2021, 1:19pm UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/1 "2021-04-26T13:19:16Z")

</div>

Hi.  
Help me.  
I am using open distro for elasticsearch 13.2.1.  
To prevent users with dashboard\_only\_user privileges from viewing edits and search items  
What kind of authority should I grant?  
I want to know if I can do it in the first place.

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [April 27, 2021, 8:45am UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/2 "2021-04-27T08:45:07Z")

</div>

@daiki_1028 Can you please explain a bit more what you are trying to achieve (“viewing edits?”)? Also I assume you are using odfe 1.13.2?

---

<div class="post-metadata">

**Author:** ![daiki\_1028](https://avatars.discourse-cdn.com/v4/letter/d/839c29/32.png) [@daiki\_1028](https://forum.opensearch.org/u/daiki_1028)\
**Post date:** [May 24, 2021, 5:20am UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/3 "2021-05-24T05:20:37Z")

</div>

tnx!  
yes! i using version 1.13.2.

Dashboard-only users want to limit items in the red frame

 ![ダッシュボード](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/c/cc00d67e82d43777b9e3d4e211b54fdf5619ff77.png)

---

<div class="post-metadata">

**Author:** ![Anthony](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/anthony/32/9939_2.png) [@Anthony](https://forum.opensearch.org/u/Anthony)\
**Post date:** [May 24, 2021, 8:47am UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/4 "2021-05-24T08:47:14Z")

</div>

@daiki_1028  
You can prevent the users from editing the visualisation and saving them by mapping users to a read\_only\_role and additional role like below:

```
testRole1:
  index_permissions:
    - index_patterns:
        - 'test*'
      allowed_actions:
        - 'read'
    - index_patterns:
        - '.kibana*'
      allowed_actions:
        - 'read'
  cluster_permissions:
    - "cluster_composite_ops"
  tenant_permissions:
    - tenant_patterns:
      - 'global_tenant'
      allowed_actions:
        - 'kibana_all_read'

```

But the rest doesn’t seem to be possible

---

<div class="post-metadata">

**Author:** ![AmitC](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@AmitC](https://forum.opensearch.org/u/AmitC)\
**Post date:** [June 17, 2021, 11:49am UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/5 "2021-06-17T11:49:56Z")

</div>

This is working in ES version of 6.8 and lower.

I have upgraded AWS ES service from 6.8 to 7.10.2 and started facing this issue on user which are already created.

In my case  
Every user has 2 roles in ES v6.8

1. Kibana Read Only
2. Customize role with Document Level Security  
Cluster permission is : cluster\_composite\_ops\_ro  
Indexes: ?kibana\* and my own created index with DLS

It was working fine in v6.8. After upgrade to 7.10.2 it is NOT working.

Then, I added the same user to kibana\_user role and it started working. but User now can do the CRUD on dashboards. Can go on creating visualisations. Which I don’t want and same things is mentioned above in screenshots by @daiki_1028

---

<div class="post-metadata">

**Author:** ![AmitCh](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@AmitCh](https://forum.opensearch.org/u/AmitCh)\
**Post date:** [June 17, 2021, 7:04pm UTC](https://forum.opensearch.org/t/how-to-prevent-dashboard-only-user-from-editing-or-searching/5753/6 "2021-06-17T19:04:16Z")

</div>

@Anthony Hi, This is Amit. I am replying from another user now as old user sending reply limit reached.( I can’t see older messages in this user account)

@Anthony As i said I am using the AWS managed service. So I don’t have control on the config files.

Also, If you check with ES v6.8 It require only 2 roles to map ( 1 kibana read only + 1 custom role) then why same thing is not working in ES v7,10,2

ES v7.10.2 makes compulsion on mapping the kibana\_user role. Then only it started working( with CRUD issue of dashboard)

Why there is difference between 2 versions?

Can you please tell me how I can achieve dashboard only view in ESv7.10.2?

If you need I am ready to connect with you on google meet

Thanks, Amit
