# Exclude indices from role?

**URL:** <https://discuss.elastic.co/t/exclude-indices-from-role/73966>\
**Category:** Elasticsearch\
**Created:** [February 5, 2017, 5:56am UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966 "2017-02-05T05:56:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jakauppila](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakauppila/32/44935_2.png) [@Jakauppila](https://discuss.elastic.co/u/Jakauppila)\
**Post date:** [February 5, 2017, 5:56am UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966/1 "2017-02-05T05:56:02Z")

</div>

Is it possible to exclude indices from roles?

For example, say I have the following indices:

- logstash-access-iis-[date]
- logstash-access-tomcat-[date]
- logstash-application-log4net-[date]
- logstash-application-log4j-[date]

The average user gets read access to all indices via the following role:

```
kibana_user:
  cluster:
      - monitor
  indices:
    - names: 'logstash-*'
      privileges:
        - view_index_metadata
        - read

```

But now I'm adding a new index that I want to limit user access via a separate role to called:

- logstash-application-rabbitmq-[date]

Is there any way I can exclude this index pattern from the `kibana_user` role? Or do I need to change that role to:

```
kibana_user:
  cluster:
      - monitor
  indices:
    - names: 'logstash-access-*'
      privileges:
        - view_index_metadata
        - read
    - names: 'logstash-application-log4net-*'
      privileges:
        - view_index_metadata
        - read
    - names: 'logstash-application-log4j-*'
      privileges:
        - view_index_metadata
        - read
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 5, 2017, 8:15am UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966/2 "2017-02-05T08:15:32Z")

</div>

As a user can have multiple roles, why not just manage this index through a separate role that you only assign to the users allowed to access it?

---

<div class="post-metadata">

**Author:** ![Jakauppila](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakauppila/32/44935_2.png) [@Jakauppila](https://discuss.elastic.co/u/Jakauppila)\
**Post date:** [February 5, 2017, 1:54pm UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966/3 "2017-02-05T13:54:11Z")

</div>

Sorry, I should have clarified; the plan is to provision access to the new index via a new role:

```
rabbitmq_user:
  cluster:
      - monitor
  indices:
    - names: 'logstash-application-rabbitmq-*'
      privileges:
        - view_index_metadata
        - read

```

But since my current role specifies `- names: 'logstash-*'` I believe I would have to change it to what I specified above. Just wanted to make sure there wasn't some option like this available:

```
kibana_user:
  cluster:
      - monitor
  indices:
    - names: 'logstash-*'
      privileges:
        - view_index_metadata
        - read
    - excludes: 'logstash-application-rabbitmq-*'
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 5, 2017, 2:07pm UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966/4 "2017-02-05T14:07:18Z")

</div>

You will need to change your kibana\_user role to be more specific with respect to index names.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2017, 2:07pm UTC](https://discuss.elastic.co/t/exclude-indices-from-role/73966/5 "2017-03-05T14:07:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
