Journalbeat features that require authorizationedit

After securing Journalbeat, make sure your users have the roles (or associated privileges) required to use these Journalbeat features. Note that some of the roles shown here are built-in, and some are user-defined.

Feature Role

Send data to a secured cluster

journalbeat_writer [1]

Load index templates

journalbeat_writer [1] and kibana_user

Read indices created by Journalbeat

journalbeat_reader [1]

Load index lifecycle policies and use index lifecycle management

journalbeat_ilm [1]

To create the user-defined roles shown here, see Configure authentication credentials and Grant users access to Journalbeat indices. You may want to define additional roles to provide more restrictive access.

[1] These roles are user-defined.