# Dynamic filtering of indices based on SAML attributes

**URL:** <https://discuss.elastic.co/t/dynamic-filtering-of-indices-based-on-saml-attributes/221371>\
**Category:** Kibana\
**Created:** [February 28, 2020, 6:44am UTC](https://discuss.elastic.co/t/dynamic-filtering-of-indices-based-on-saml-attributes/221371 "2020-02-28T06:44:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lucasnad27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucasnad27/32/63506_2.png) [@lucasnad27](https://discuss.elastic.co/u/lucasnad27)\
**Post date:** [February 28, 2020, 6:44am UTC](https://discuss.elastic.co/t/dynamic-filtering-of-indices-based-on-saml-attributes/221371/1 "2020-02-28T06:44:33Z")

</div>

I want to dynamically filter a dashboard based on a user's SAML attributes. Here are the basics of my attempts so far...

I've setup a special field in my user's metadata, we'll call it `filter_id`. If you hit the authenticate endpoint (`GET /_security/_authenticate`) it returns back a lot of attributes, here's an abbreviated version...

```auto
{
  "username" : "jane.doe@gmail.com",
  "roles" : [
    "hub-test"
  ],
  "metadata" : {
    "saml(http://schemas.auth0.com/filter_id)" : [
      "special-filter-id"
    ],
  },
  ...
}

```

The `hub-test` role allows us to access all indices such as `listings\_\*. And within the granted documents query we limit access based on saml attribute. here's a screenshot of what that looks like in Kibana...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/0/b094ef6ee5676a3cd5111ceb95d871da47f7475d.png)

All should be good right? Nope ☹ With a simple dashboard that displays the total count, 0 documents are returned. Now if I remove the `{{ }}` dynamic insertion and hard code the value of filter\_id as it was received from the `GET /_security/_authenticate` endpoint above ("special-filter-id"), voila! We get 77 documents. Here is a screenshot showing that setup and the resulting dashboard

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/3/d37cd199921082a4f2ee9eb346024ac6020d369b.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/1/316e691e129ccdad84f163f50212f81dd9cd68aa.png)

With all the background info and setup out of the way, here's my question...how can I get this working properly?! I've tried numerous incantations to get the SAML attribute correctly inserted into the template query, but no luck so far. Perhaps I need to configure my IDP (auth0) to massage the attributes into a form that Kibana can understand?? Any help would be **greatly**  **appreciated** on this matter.

---

<div class="post-metadata">

**Author:** ![lucasnad27](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lucasnad27/32/63506_2.png) [@lucasnad27](https://discuss.elastic.co/u/lucasnad27)\
**Post date:** [March 5, 2020, 5:00am UTC](https://discuss.elastic.co/t/dynamic-filtering-of-indices-based-on-saml-attributes/221371/2 "2020-03-05T05:00:56Z")

</div>

Following up on my own thread as I've resolved my issue.

Turns out, mustache doesn't like the "out of the box" saml attributes so I had to remap the attributes in Auth0 to be friendly. By removing the dots and slashes and grabbing the first item from the array (unsuccessful getting auth0 to send a string rather than an array of strings) elastic was able to successfully parse the template. Here is what it ended up looking like...

```
{"template" : {
          "source" : {
            "term" : { "_index" : "{{_user.metadata.saml(saml_filter_id).0}}"}
          }
        }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2020, 5:01am UTC](https://discuss.elastic.co/t/dynamic-filtering-of-indices-based-on-saml-attributes/221371/3 "2020-04-02T05:01:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
