# ELK Stack restrict access to some data

**URL:** <https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687>\
**Category:** Elasticsearch\
**Created:** [October 4, 2017, 11:14am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687 "2017-10-04T11:14:18Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 4, 2017, 11:14am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/1 "2017-10-04T11:14:19Z")

</div>

Now I'm touch a elk stack for a log collecting, also install xpack to kibana and elasticsearch. How I can restrict access to some logs group (any hosts) for any people? For log collecting I'm using logstash, listen some udp port, clients send logs with rsyslog. Critical for me is a don't change clients sending settings (rsyslog only).

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 4, 2017, 12:13pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/2 "2017-10-04T12:13:52Z")

</div>

This isn't really a Logstash question. I suggest you edit your post and move it to the X-Pack category.

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 4, 2017, 12:35pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/3 "2017-10-04T12:35:26Z")

</div>

Hi Magnus. Do you have any idea about this? x-pack give security features access to kibana. In my best is a take two or more indexes from one input and give accounts to teams

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 4, 2017, 12:40pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/4 "2017-10-04T12:40:17Z")

</div>

You can use the [role-based access controls](https://www.elastic.co/guide/en/x-pack/current/authorization.html) that X-Pack provides to control who has access to what. This can be done either directly at the index level, assuming you are storing different categories of data in different indices, or using [document level security](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html) if you tend to have all data in a single index and want to differentiate data based on the content.

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 4, 2017, 12:53pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/5 "2017-10-04T12:53:35Z")

</div>

Hi Christian. Document level security is a platinum feature, I can get only gold.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 4, 2017, 12:56pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/6 "2017-10-04T12:56:25Z")

</div>

If you have a limited number of log types you need to secure differently, you can store them in different indices. What level of granularity do you need?

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 4, 2017, 1:09pm UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/7 "2017-10-04T13:09:33Z")

</div>

I have only one type. My input block looks something like this:  
input {  
udp {  
port =\> 514  
type =\> syslog  
}  
}

for example we have a 3 teams and 4 server groups. Team1 must can see logs from grsrv2 and grsrv3  
team2 - grsrv1  
team3 - all server groups

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 5, 2017, 7:34am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/8 "2017-10-05T07:34:33Z")

</div>

I'm not sure, but something like this must be work.... or not 🙂  
input {  
if "%{host}" == "any\_host\_ip"  
udp {  
port =\> any\_port  
type =\> "index\_one"  
}   
} else {  
udp {  
port =\> any\_port  
type =\> "index\_two"  
}  
}

filter {  
if [type] == "%{type}" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:%{type}\_timestamp} %{SYSLOGHOST:%{type}\_hostname} %{DATA:%{type}\_program}(?:[%{POSIN$  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["%{type}\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{type}-%{+YYYY.MM.dd}"  
document\_type =\> "system\_logs"  
user =\> anyuser  
password =\> anypassword  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 5, 2017, 9:55am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/9 "2017-10-05T09:55:36Z")

</div>

You can not have conditionals in the input block, but you can set the index to write to based on the value of the `host` field, which indicates where the event comes from. You can do this using a simple conditional or through the translate plugin.

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 5, 2017, 10:11am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/10 "2017-10-05T10:11:40Z")

</div>

In grok I'm add a host field  
add\_field =\> ["received\_from", "%{host}"]

so, I can take out to elastic index with host filter?  
index =\> "any\_index-%{host}"  
Something like this?  
For example, I can create index any\_index-host\_name ? That's right?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 5, 2017, 10:19am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/11 "2017-10-05T10:19:25Z")

</div>

You may not want the host in the index name, but if you e.g. wanted to send events from `1.1.1.1` to a separate index you could do something like this:

```auto
if [host] =="1.1.1.1" {
  mutate {
    add_field => ["[@metadata][index]", "indexA" ]
  }
} else {
  mutate {
    add_field => ["[@metadata][index]", "indexB" ]
  }
}

```

Then use the `[@metadata][index]` field as index prefix in the elasticsearch output plugin.

```auto
elasticsearch {
  ...
  index => "%{[@metadata][index]}-%{+YYYY.MM.dd}"
  ...
}

```

If you have more complex requirement when it comes to mapping hosts to indices, you can use the translate plugin.

---

<div class="post-metadata">

**Author:** ![asyakovlev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asyakovlev/32/22802_2.png) [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Post date:** [October 5, 2017, 10:45am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/12 "2017-10-05T10:45:44Z")

</div>

Thank you, Christian!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2017, 4:02am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/13 "2017-10-06T04:02:41Z")

</div>

Also FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 4:05am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687/14 "2017-11-03T04:05:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
