Default action groups

This page catalogs all default action groups. Often, the most coherent way to create new action groups is to use a combination of these default groups and individual permissions.

General

Action groupDescriptionPermissions
unlimitedGrants complete access to action groups. Can be used on an cluster- or index- level. Equates to “”.

Cluster-level

Action groupDescriptionPermissions
cluster_allGrants all cluster permissions. Equates to cluster:.cluster:
cluster_monitorGrants all cluster monitoring permissions. Equates to cluster:monitor/.cluster:monitor/
cluster_composite_ops_roGrants read-only permissions to execute requests like mget, msearch, or mtv, as well as permissions to query for aliases.indices:data/read/mget indices:data/read/msearch indices:data/read/mtv indices:admin/aliases/exists indices:admin/aliases/get indices:data/read/scroll indices:admin/resolve/index
cluster_composite_opsSame as CLUSTER_COMPOSITE_OPS_RO, but also grants bulk permissions and all aliases permissions.indices:data/write/bulk indices:admin/aliases indices:data/write/reindex indices:data/read/mget indices:data/read/msearch indices:data/read/mtv indices:admin/aliases/exists indices:admin/aliases/get indices:data/read/scroll indices:admin/resolve/index
manage_snapshotsGrants permissions to manage snapshots and repositories.cluster:admin/snapshot/ cluster:admin/repository/
cluster_manage_pipelinesGrants permissions to manage ingest pipelines.cluster:admin/ingest/pipeline/
cluster_manage_index_templatesGrants permissions to manage index templates.indices:admin/template/ indices:admin/index_template/ cluster:admin/component_template/*

Index-level

Action groupDescriptionPermissions
indices_allGrants all permissions on the index. Equates to indices:.indices:
getGrants permissions to use get and mget actions.indices:data/read/get indices:data/read/mget
readGrants read permissions on the index such as search, get field mappings, get, and mget.indices:data/read indices:admin/mappings/fields/get indices:admin/resolve/index
writeGrants permissions to create and update documents within existing indexes.indices:data/write indices:admin/mapping/put
deleteGrants permissions to delete documents.indices:data/write/delete
crudCombines the read, write, and delete action groups. Included in the data_access action group.indices:data/read indices:admin/mappings/fields/get indices:admin/resolve/index indices:data/write indices:admin/mapping/put
searchGrants permissions to search documents, including the Suggest API.indices:data/read/search indices:data/read/msearch indices:admin/resolve/index indices:data/read/suggest
suggestGrants permissions to use the Suggest API. Included in the read action group.indices:data/read/suggest
create_indexGrants permissions to create indexes and mappings.indices:admin/create indices:admin/mapping/put
indices_monitorGrants permissions to run all index monitoring actions, such as recovery, segments_info, index_stats, and status).indices:monitor/
indexA more limited version of the write action group.indices:data/write/index indices:data/write/update indices:admin/mapping/put indices:data/write/bulk
data_accessCombines the CRUD action group with indices:data/.indices:data/ indices:data/read indices:admin/mappings/fields/get indices:admin/resolve/index indices:data/write indices:admin/mapping/put
manage_aliasesGrants permissions to manage aliases.indices:admin/aliases
manageGrants all monitoring and administration permissions for indexes.indices:monitor/ indices:admin/*