Skip to content

Commit 1bbb7fb

Browse files
committed
Give the kibana system user .entities read permissions
1 parent 2ba9bc9 commit 1bbb7fb

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/store/KibanaOwnedReservedRoleDescriptors.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -458,13 +458,13 @@ static RoleDescriptor kibanaSystem(String name) {
458458
TransportUpdateSettingsAction.TYPE.name()
459459
)
460460
.build(),
461-
461+
// security entity analytics indices
462462
RoleDescriptor.IndicesPrivileges.builder().indices("risk-score.risk-*").privileges("all").build(),
463463
RoleDescriptor.IndicesPrivileges.builder()
464464
.indices(".asset-criticality.asset-criticality-*")
465465
.privileges("create_index", "manage", "read", "write")
466466
.build(),
467-
467+
RoleDescriptor.IndicesPrivileges.builder().indices(".entities.v1.latest.security*").privileges("read").build(),
468468
// For cloud_defend usageCollection
469469
RoleDescriptor.IndicesPrivileges.builder()
470470
.indices("logs-cloud_defend.*", "metrics-cloud_defend.*")

0 commit comments

Comments
 (0)