Security Kibana privileges

Roles control what users can access and what actions they can perform. When you create or edit a role, you grant it Kibana privileges, which give access to individual features within one or more spaces.

To create or edit a role, find Roles in the navigation menu or by using the global search field. Adding Kibana privileges opens the Assign role to spaces flyout, where features are grouped by solution. Access to Elastic Security features is controlled by the Security group privileges, described on this page.

For more details on using this UI, refer to Role management using Kibana for Elastic Stack, or to Custom roles for Serverless.

For each of the feature privileges, select the type of access you want to allow:

  • All: Users have full access to the feature, which includes performing all available actions and managing configuration.
  • Read: Users can view the feature, but can't perform any actions or manage configuration.
  • None: Users can't access or view the feature.
Note

Some features don't have a Read privilege.

Each of the following privileges controls access to a different part of Elastic Security.

Privilege What it allows
Security Access the Elastic Security features that don't have a privilege of their own. Turn on Customize sub-feature privileges to grant individual privileges. Refer to Security sub-feature privileges.
Security also allows access to detection rules, alerts, and exceptions.
Cases Access cases. Turn on Customize sub-feature privileges to grant individual case privileges. For the full list, refer to Customize sub-feature privileges for cases.
Timeline Access Timeline.
Notes Access Notes.
Rules and Exceptions Access detection rules and exceptions, including the Rules table, rule details, and rule monitoring. Turn on Customize sub-feature privileges to grant individual rule and exception privileges. For the full list, refer to Rules and Exceptions sub-feature privileges.
Alerts Access detection alerts.
Rules, Alerts, and Exceptions Access detection rules, alerts, and exceptions. Roles that use this privilege keep working, but the privilege is no longer available. Use Rules and Exceptions and Alerts instead.
Elastic AI Assistant Access Elastic AI Assistant. Turn on Customize sub-feature privileges to grant individual AI Assistant privileges. For the full list, refer to Elastic AI Assistant sub-feature privileges.
Attack discovery Access Attack Discovery.
Turn on Customize sub-feature privileges to grant individual Attack discovery privileges. For details, refer to Attack discovery sub-feature privileges.
Automatic Migration Access Automatic Migration.
This privilege is called SIEM migrations.

Unlike the other features in this group, selecting All for Security doesn't include its sub-feature privileges. You grant each one separately.

Most of the Security privileges control Elastic Defend features. For the full list, refer to Elastic Defend sub-feature privileges. The following table lists the rest.

Privilege What it allows
SOC Management Access the Value report page.

These privileges control specific actions on detection rules and exceptions. Selecting All includes everything in the following table.

Privilege What it allows
Exceptions Create and manage exceptions for rules and shared exception lists. If this privilege is cleared, users with Read for Rules and Exceptions can still view exception lists and exception items.
Investigation guides Create and edit investigation guides on custom rules.
Custom highlighted fields Add and edit custom highlighted fields on rules.
Enable or Disable Enable and disable detection rules.
Manual rule run Manually run rules for a selected time range.
Rule management settings Change Settings above the Rules table, including options that affect gap monitoring.

These privileges control changes to AI Assistant settings. Selecting All includes everything in the following table.

Privilege What it allows
Field Selection and Anonymization Change which alert fields Elastic AI Assistant and Attack Discovery can use, and anonymize the content of those fields.
Knowledge Base Change global Knowledge Base entries, which apply to everyone in the space, including entries that other users created.

These privileges control specific Attack Discovery actions. Selecting All includes everything in the following table.

Privilege What it allows
Schedules Create, edit, enable, disable, and delete Attack Discovery schedules.