# Different roles on different fields on different documents

**URL:** <https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367>\
**Category:** SIEM\
**Created:** [August 10, 2020, 8:32am UTC](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367 "2020-08-10T08:32:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![luj\_ogluszacz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luj_ogluszacz/32/45030_2.png) [@luj\_ogluszacz](https://discuss.elastic.co/u/luj_ogluszacz)\
**Post date:** [August 10, 2020, 8:32am UTC](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367/1 "2020-08-10T08:32:10Z")

</div>

Hi everyone, I have a question. I get a JSON like this

> {  
> "took" : 271,  
> "timed\_out" : false,  
> "\_shards" : {  
> "total" : 1,  
> "successful" : 1,  
> "skipped" : 0,  
> "failed" : 0  
> },  
> "hits" : {  
> "total" : {  
> "value" : 4,  
> "relation" : "eq"  
> },  
> "max\_score" : 1.0,  
> "hits" : [  
> {  
> "\_index" : "test",  
> "\_type" : "\_doc",  
> "\_id" : "1",  
> "\_score" : 1.0,  
> "\_source" : {  
> "name" : ["John", "user1"],  
> "lastname" : ["Doe" ,"user2"],  
> "job\_description" : ["Systems administrator and Linux specialist", "user3"]  
> }  
> },  
> {  
> "\_index" : "test",  
> "\_type" : "\_doc",  
> "\_id" : "2",  
> "\_score" : 1.0,  
> "\_source" : {  
> "name" : ["John", "user2"],  
> "lastname" : ["Doe", "user3"],  
> "job\_description" : ["Systems administrator and Linux specialist", "user1"]  
> }  
> },  
> {  
> "\_index" : "test",  
> "\_type" : "\_doc",  
> "\_id" : "3",  
> "\_score" : 1.0,  
> "\_source" : {  
> "name" : ["John", "user3"],  
> "lastname" : ["Doe", "user1"],  
> "job\_description" : ["Systems administrator and Linux specialist", "user2"]  
> }  
> }  
> ]  
> }  
> }

different documents have different permission on different fields for example if I login to user1 and I want to find name = "John" I will see only document with \_id 1 without fields that I don't have permission

> ```
> {
> "_index" : "test",
> "_type" : "_doc",
> "_id" : "1",
> "_score" : 1.0,
> "_source" : {
> "name" : ["John", "user1"]
> }
> }
> 
> ```

any ideas how to do it?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [August 10, 2020, 2:49pm UTC](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367/2 "2020-08-10T14:49:44Z")

</div>

Hi,

This might be possible to do with field level security but I'm not quite sure myself. I think you have a better chance to get an answer to this question if you open a topic in the [Elasticsearch](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6) section, and apply the `stack-security` label.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 2:50pm UTC](https://discuss.elastic.co/t/different-roles-on-different-fields-on-different-documents/244367/3 "2020-09-07T14:50:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
