# Elastic Cloud output on shared / non-trusted environments

**URL:** <https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 21, 2020, 9:55am UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855 "2020-01-21T09:55:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gerard1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard1/32/53507_2.png) [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Post date:** [January 21, 2020, 9:55am UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/1 "2020-01-21T09:55:41Z")

</div>

Imagine the following scenario:

You want to deploy Filebeat using Elastic Cloud in some servers that are managed by a 3rd party company.

Is there any way to do that without using the Elastic Cloud global credentials?  
As those credentials are the same for accessing Kibana / ElasticSearch, that 3rd part company could use them to access all the other servers logs.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 21, 2020, 5:05pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/2 "2020-01-21T17:05:28Z")

</div>

Hi @gerard1,

You can define a different user with permissions in some specific indexes for the 3rd party company. You could use these credentials to configure Filebeat in their instances and keep the global credentials only for yourself.

---

<div class="post-metadata">

**Author:** ![gerard1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard1/32/53507_2.png) [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Post date:** [January 21, 2020, 5:51pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/3 "2020-01-21T17:51:31Z")

</div>

But then, if I'm using one global index (filebeat), they could be read the whole index with those credentials, correct? Or is it possible only to write, but not read?

The solution I'm thinking would be to setup a Logstash in between, but then I guess it will require some adjustments in the Filebeat setup.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 21, 2020, 6:02pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/4 "2020-01-21T18:02:11Z")

</div>

> [@gerard1](#):
>
> But then, if I'm using one global index (filebeat), they could be read the whole index with those credentials, correct? Or is it possible only to write, but not read?

It is possible to give write privileges only. You can find here the full list of possible privileges: [Security privileges | Elasticsearch Guide [7.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/security-privileges.html)

In any case it can make sense to use different indexes for different parties.

> [@gerard1](#):
>
> The solution I'm thinking would be to setup a Logstash in between, but then I guess it will require some adjustments in the Filebeat setup.

Yes, this could be another option. You can find more information about that in [this guide](https://www.elastic.co/guide/en/elastic-stack-get-started/7.5/get-started-elastic-stack.html#logstash-setup), and in the documentation about the [Beats input](https://www.elastic.co/guide/en/logstash/7.5/plugins-inputs-beats.html) in Logstash, and the [Logstash output](https://www.elastic.co/guide/en/beats/filebeat/7.5/logstash-output.html) in Filebeat.

---

<div class="post-metadata">

**Author:** ![gerard1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gerard1/32/53507_2.png) [@gerard1](https://discuss.elastic.co/u/gerard1)\
**Post date:** [January 30, 2020, 3:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/5 "2020-01-30T15:40:17Z")

</div>

> [@jsoriano](#):
>
> It is possible to give write privileges only. You can find here the full list of possible privileges: [Security privileges | Elasticsearch Guide [7.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.5/security-privileges.html)

But the write permissions also include update and delete, so is not an option from security perspective

> [@jsoriano](#):
>
> In any case it can make sense to use different indexes for different parties.
> 
> ![](https://us1.discourse-cdn.com/elastic/original/3X/7/0/703a4aad22c377043ba90283576579c5005bc284.jpeg) gerard1:

Then I will lose some of the features, such as the ISMS.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2020, 3:40pm UTC](https://discuss.elastic.co/t/elastic-cloud-output-on-shared-non-trusted-environments/215855/6 "2020-02-27T15:40:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
