# Access user to access particular index in shield

**URL:** <https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 10, 2015, 12:11pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310 "2015-07-10T12:11:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![karthikjaps](https://avatars.discourse-cdn.com/v4/letter/k/c67d28/32.png) [@karthikjaps](https://discuss.elastic.co/u/karthikjaps)\
**Post date:** [July 10, 2015, 12:11pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310/1 "2015-07-10T12:11:41Z")

</div>

Hi , i try to work in elastic shield with elastic search , i have an query about , how to assign single user to access only particular index ? in creating roles in roles.yml , there is option to speciall paricular role to access only particular index ?

Example , i have an user1 , user2 both in different role , how i make user1 to access only index 1 , and user2 to access index2 ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 10, 2015, 12:35pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310/2 "2015-07-10T12:35:50Z")

</div>

Hi,

Have you looked at the [authorization documentation](https://www.elastic.co/guide/en/shield/current/authorization.html)? It talks about how to specify roles for specific indices and then you would assign the respective role to the appropriate users.

-Jay

---

<div class="post-metadata">

**Author:** ![karthikjaps](https://avatars.discourse-cdn.com/v4/letter/k/c67d28/32.png) [@karthikjaps](https://discuss.elastic.co/u/karthikjaps)\
**Post date:** [July 10, 2015, 12:53pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310/3 "2015-07-10T12:53:49Z")

</div>

OK , thanks jaymodi , i look on it , supppose i have an index like

curl -XGET '[http://localhost:9200/index1/user/](http://localhost:9200/index1/user/)  
curl -XGET '[http://localhost:9200/index2/post/](http://localhost:9200/index2/post/)  
curl -XGET '[http://localhost:9200/index2/post/](http://localhost:9200/index2/post/)

Then the rule to access index1 is for user in role get\_user

get\_user:  
indices:  
'index1': 'indices:data/read/get'

Then the rule to access index2 is for user in role dev\_user

dev\_user:  
indices:  
'index12': 'indices:data/read/get'

Right ? or anything i missed ?

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [July 10, 2015, 1:01pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310/4 "2015-07-10T13:01:23Z")

</div>

I think it is close. The `indices:data/read/get` action usually just corresponds to a get by ID I think. You'll probably want to grant the user the special `read` privilege so they can search, use mget, count, etc. See [https://www.elastic.co/guide/en/shield/current/reference.html#privileges-list-indices](https://www.elastic.co/guide/en/shield/current/reference.html#privileges-list-indices)

So your example would then be:

```
get_user:
  indices:
    'index1': read

dev_user:
  indices:
    'index12': read
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/access-user-to-access-particular-index-in-shield/25310/5 "2017-07-06T13:48:53Z")

</div>


