-
Notifications
You must be signed in to change notification settings - Fork 25.4k
Open
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACTeam:SecurityMeta label for security teamMeta label for security team
Description
Kibana/Elasticsearch Stack version: 8.18.0
Describe the bug:
The kibana_system
role lacks the necessary permissions to delete system indices related to logs-extrahop.investigation
and logs-qualys_gav.asset
, as defined in the ILM policy located here.
Steps to reproduce:
- Checkout the
sharadcrest:package-extrahop-investigation-datastream
branch forExtraHop package
andjanvi-elastic:package-qualys_gav
branch forQualys GAV package
and create a zip of the respective package. - Upload the package zip to a hosted deployment.
- Add the integration.
- Monitor the hidden index under
Stack Management > Index Management
and wait for the ILM policy’s delete phase to trigger.
Current behavior:
- It shows permission issue in deleting the index
For Qualys GAV:
{
"failed_step": "delete",
"step_info": {
"type": "security_exception",
"reason": "action [indices:admin/delete] is unauthorized for user [found-internal-kibana4-server] with effective roles [found-internal-kibana4-server,kibana_system] on indices [.ds-logs-qualys_gav.asset-default-2025.07.24-000001], this action is granted by the index privileges [delete_index,manage,all]"
}
}
For ExtraHop:
{
"failed_step": "delete",
"step_info": {
"type": "security_exception",
"reason": "action [indices:admin/delete] is unauthorized for user [found-internal-kibana4-server] with effective roles [found-internal-kibana4-server, kibana_system] on indices [.ds-logs-extrahop.investigation-default-2025.07.23-000001], this action is granted by the index privileges [delete_index, manage, all]"
}
}
Expected behavior:
- Index must be delete after the time duration mentioned in the ILM policy
Metadata
Metadata
Assignees
Labels
:Security/AuthorizationRoles, Privileges, DLS/FLS, RBAC/ABACRoles, Privileges, DLS/FLS, RBAC/ABACTeam:SecurityMeta label for security teamMeta label for security team