# What are the permissions required to generate and download a CSV?

**URL:** <https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018>\
**Category:** Security\
**Tags:** troubleshoot, configure, security-issue\
**Created:** [September 22, 2023, 6:13pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018 "2023-09-22T18:13:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamie\_coursemojo](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@jamie\_coursemojo](https://forum.opensearch.org/u/jamie_coursemojo)\
**Post date:** [September 22, 2023, 6:13pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018/1 "2023-09-22T18:13:01Z")

</div>

**Versions** (relevant - OpenSearch/Dashboard/Server OS/Browser):  
OpenSearch 2.5 on AWS / Chrome

**Describe the issue** :  
We have a limited read-only role set up for most of the users of our OpenSearch domain. These users are given permission to log into the dashboard via the `opensearch_dashboards_user` role. These users, however, can not generate and download a CSV via the Reporting tab that appears when they open a saved search. What are the permissions required to grant these users the ability to do this? I’ve tried all of the following:

```auto
cluster:admin/opendistro/reports/definition/create
cluster:admin/opendistro/reports/definition/update
cluster:admin/opendistro/reports/definition/on_demand
cluster:admin/opendistro/reports/definition/delete
cluster:admin/opendistro/reports/definition/get
cluster:admin/opendistro/reports/definition/list
cluster:admin/opendistro/reports/instance/list
cluster:admin/opendistro/reports/instance/get
cluster:admin/opendistro/reports/menu/download

```

**Configuration** :  
The `limited-user` role for these users has the `read` cluster permission group.

**Relevant Logs or Screenshots** :

![Screenshot 2023-09-22 at 12.09.22 PM](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/e/e15081c4f1c6fe0437f22d340ade0108d94bd13f.png)

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [September 25, 2023, 5:46pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018/2 "2023-09-25T17:46:56Z")

</div>

Hi @jamie_coursemojo

Could you share your OpenSearch logs? Have you tried to use the `reports_read_access` role?

---

<div class="post-metadata">

**Author:** ![Eugene7](https://avatars.discourse-cdn.com/v4/letter/e/bbce88/32.png) [@Eugene7](https://forum.opensearch.org/u/Eugene7)\
**Post date:** [September 25, 2023, 5:59pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018/3 "2023-09-25T17:59:04Z")

</div>

Also, please have a look at the following topic:

> [@Read-only user not able to download CSV Reports](https://forum.opensearch.org/t/read-only-user-not-able-to-download-csv-reports/5211):
>
> I have installed ELK OSS version 7.10.2 on CentOS machine. I have installed standalone opendistro reporting plugin. I have a user who has following three roles : kibana\_user readall reports\_full\_access This user is not able to download CSV Reports from Reporting plugin due to permission issue. I want this user to have only read-only rights. With the same user, I am able to download PNG or PDF reports. Is there any way I can achieve this ? Here is kibana log : Mar 04 06:18:03 ip-\*\*\*\* kibana…

---

<div class="post-metadata">

**Author:** ![jamie\_coursemojo](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@jamie\_coursemojo](https://forum.opensearch.org/u/jamie_coursemojo)\
**Post date:** [September 26, 2023, 1:51pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018/4 "2023-09-26T13:51:12Z")

</div>

> [@Eugene7](#):
>
> reports\_read\_access

I don’t have that role in my instance (I am running a managed instance via AWS), but I do have `reports_instances_read_access`. That said, that role has 3 permissions in it, and I have already tried those in my other role:

- `cluster:admin/opendistro/reports/instance/list`
- `cluster:admin/opendistro/reports/instance/get`
- `cluster:admin/opendistro/reports/menu/download`

I am not seeing anything in the error logs.

---

<div class="post-metadata">

**Author:** ![jamie\_coursemojo](https://avatars.discourse-cdn.com/v4/letter/j/50afbb/32.png) [@jamie\_coursemojo](https://forum.opensearch.org/u/jamie_coursemojo)\
**Post date:** [September 26, 2023, 2:04pm UTC](https://forum.opensearch.org/t/what-are-the-permissions-required-to-generate-and-download-a-csv/16018/5 "2023-09-26T14:04:21Z")

</div>

The solution in that topic worked! Thank you so much.
