# Allow Kibana role to access all indices EXCEPT FOR a specific one

**URL:** <https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 15, 2023, 7:03pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135 "2023-06-15T19:03:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [June 15, 2023, 7:03pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135/1 "2023-06-15T19:03:12Z")

</div>

# TL;DR

How do I grant access to all indices matching a pattern, but deny access to one specific index that also matches the pattern (e.g., how do I ALLOW access to all logs, including `logs-myapp.log-*`, but specifically DENY access to `logs-myapp.log-prod`)?

# Details

I manage our company's Elastic Cloud instance. I have a new requirement for a specific set of logs that **only** users with a specific role be allowed to access them.

Assuming that the log index in question is `logs-myapp.log-prod`, I presume that the following role will match it:

```json
{
  "myapp_prod_user": {
    "cluster": [],
    "indices": [
      {
        "names": [
          "logs-myapp.log-prod"
        ],
        "privileges": [
          "view_index_metadata",
          "read"
        ],
        "allow_restricted_indices": false
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  }
}

```

However, the question I have is how do I **deny** access to all users, except for those who have the `myapp_prod_user` role assigned?

Below is my current `standard_user` role, which is based on the `editor` role included by default in our Elastic Cloud installation. What is the best way to exclude indices matching this pattern?

```json
{
  "standard_user": {
    "cluster": [],
    "indices": [
      {
        "names": [
          "observability-annotations"
        ],
        "privileges": [
          "view_index_metadata",
          "write",
          "read"
        ],
        "field_security": {
          "grant": [
            "*"
          ]
        },
        "allow_restricted_indices": false
      },
      {
        "names": [
          "/~(([.]|ilm-history-).*)/"
        ],
        "privileges": [
          "view_index_metadata",
          "read"
        ],
        "allow_restricted_indices": false
      }
    ],
    "applications": [
      {
        "application": "kibana-.kibana",
        "privileges": [
          "feature_infrastructure.all",
          "feature_maps.all",
          "feature_savedObjectsManagement.read",
          "feature_observabilityCases.all",
          "feature_advancedSettings.read",
          "feature_visualize.all",
          "feature_apm.all",
          "feature_stackAlerts.all",
          "feature_indexPatterns.all",
          "feature_dev_tools.read",
          "feature_canvas.all",
          "feature_uptime.all",
          "feature_logs.all",
          "feature_savedObjectsTagging.read",
          "feature_discover.all",
          "feature_osquery.read",
          "feature_fleet.read",
          "feature_actions.all",
          "feature_dashboard.all"
        ],
        "resources": [
          "*"
        ]
      }
    ],
    "run_as": [],
    "metadata": {},
    "transient_metadata": {
      "enabled": true
    }
  }
}

```

If I update my `names` block to list the index separately, does Kibana match the first matching pattern in the list and stop, doing a DENY? Or does go down every element in the list to see if it matches ANY element and use that as an ALLOW?

```json
{
  "names": [
    "/~logs-myapp.log-prod/",
    "/~(([.]|ilm-history-).*)/"
  ],
  "privileges": [
    "view_index_metadata",
    "read"
  ],
  "allow_restricted_indices": false
}

```

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [June 15, 2023, 10:03pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135/2 "2023-06-15T22:03:17Z")

</div>

This might be the wrong forum for this (should probably be moved to Elasticsearch), but I believe the following should get you what you desire:

```auto
        "names": [
          "/~(([.]|ilm-history-|logs-myapp.log-prod).*)/"
        ],

```

---

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [June 16, 2023, 1:16pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135/3 "2023-06-16T13:16:49Z")

</div>

> [@lukas](#):
>
> This might be the wrong forum for this (should probably be moved to Elasticsearch), but I believe the following should get you what you desire:

Ack. I've asked so many questions in Kibana lately that I didn't even think about where I should be putting it. Thanks for the pointer! Any way to move it over to the correct category?

> ```auto
> "names": [
> "/~(([.]|ilm-history-|logs-myapp.log-prod).*)/"
> ],
> 
> ```

In other words, it's all got to be part of one match pattern for a DENY, multiple patterns don't get merged? But if I'm doing an ALLOW, then any one of multiple index patterns will allow it?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2023, 1:17pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135/4 "2023-07-14T13:17:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
