Setting up machine learning
Serverless Stack
To use the Elastic Stack machine learning features, you must have:
- the appropriate subscription level or the free trial period activated 
- xpack.ml.enabledset to its default value of- trueon every node in the cluster (refer to Machine learning settings in Elasticsearch)
- mlvalue defined in the list of- node.roleson the machine learning nodes
- machine learning features visible in the Kibana space 
- security privileges assigned to the user that: - grant use of machine learning features, and
- grant access to source and destination indices.
 
The fastest way to get started with machine learning features is to start a free 14-day trial of Elastic Cloud.
Assigning security privileges affects how users access machine learning features. Consider the two main categories:
- Elasticsearch API user: uses an Elasticsearch client, cURL, or Kibana Dev Tools to access machine learning features via Elasticsearch APIs. It requires Elasticsearch security privileges.
- Kibana user: uses the machine learning features in Kibana and does not use Dev Tools. It requires either Kibana feature privileges or Elasticsearch security privileges and is granted the most permissive combination of both. Kibana feature privileges are recommended if you control job level visibility via Spaces. Machine learning features must be visible in the relevant space. Refer to Feature visibility in Spaces for configuration information.
You can configure these privileges
- under the Roles and Spaces management pages. Find these pages in the main menu or use the global search field.
- via the respective Elasticsearch security APIs.
If you use machine learning APIs, you must have the following cluster and index privileges:
For full access:
- machine_learning_adminbuilt-in role or the equivalent cluster privileges
- readand- view_index_metadataon source indices
- read,- manage, and- indexon destination indices (for data frame analytics analytics jobs only)
For read-only access:
- machine_learning_userbuilt-in role or the equivalent cluster privileges
- readindex privileges on source indices
- readindex privileges on destination indices (for data frame analytics analytics jobs only)
The machine_learning_admin and machine_learning_user built-in roles give access to the results of all anomaly detection jobs, irrespective of whether the user has access to the source indices. You must carefully consider who is given these roles, as anomaly detection job results may propagate field values that contain sensitive information from the source indices to the results.
Granting All or Read Kibana feature privilege for Machine Learning will also grant the role the equivalent feature privileges to certain types of Kibana saved objects, namely index patterns, dashboards, saved searches, and visualizations as well as machine learning job, trained model and module saved objects.
In Kibana, the machine learning features must be visible in your space. To manage which features are visible in your space, go to the Spaces management page using the navigation menu or the global search field.
 
	
In addition to index privileges, source data views must also exist in the same space as your machine learning jobs. You can configure these under Data Views. To open Data Views, find Stack Management > Kibana in the main menu, or use the global search field.
Each machine learning job and trained model can be assigned to all, one, or multiple spaces. This can be configured in Machine Learning. To open Machine Learning, find the page in the main menu, or use the global search field. You can edit the spaces that a job or model is assigned to by clicking the icons in the Spaces column.
 
	
Within a Kibana space, for full access to the machine learning features, you must have:
- Machine Learning: AllKibana privileges
- Data Views Management: AllKibana feature privileges
- read, and- view_index_metadataindex privileges on your source indices
- data views for your source indices
- data views, read,manage, andindexindex privileges on destination indices (for data frame analytics analytics jobs only)
Within a Kibana space, for read-only access to the machine learning features, you must have:
- Machine Learning: ReadKibana privileges
- data views for your source indices
- readindex privilege on your source indices
- data views and readindex privileges on destination indices (for data frame analytics analytics jobs only)
A user who has full or read-only access to machine learning features within a given Kibana space can view the results of all anomaly detection jobs that are visible in that space, even if they do not have access to the source indices of those jobs. You must carefully consider who is given access to machine learning features, as anomaly detection job results may propagate field values that contain sensitive information from the source indices to the results.
Data views can be automatically created when creating a data frame analytics analytics job.
For access to use machine learning APIs via Dev Tools in Kibana, set the Elasticsearch security privileges and grant access to machine_learning_admin or machine_learning_user built-in roles.
Within a Kibana space, to upload and import files in the Data Visualizer, you must have:
- Machine Learning: Reador- Discover: AllKibana feature privileges
- Data Views Management: AllKibana feature privileges
- ingest_adminbuilt-in role, or- manage_ingest_pipelinescluster privilege
- create,- create_index,- manageand- readindex privileges for destination indices
For more information, see Security privileges and Kibana privileges.