# Expose part of a ELK document to another index/user

**URL:** <https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [August 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028 "2022-08-26T14:51:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sylvain35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain35/32/110194_2.png) [@Sylvain35](https://discuss.elastic.co/u/Sylvain35)\
**Post date:** [August 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/1 "2022-08-26T14:51:52Z")

</div>

Hello everyone !

I have a streaming process that feeds an ELK index (one new index each day)  
The object send is a JSON with multiple level and fields. I have a complex mapping on this Index.

I want to expose a limited part of this object to another index. How can I do that ? can I use an ingest pipeline to copy a part of the object to another index each time one is write ? Is there something like a "sql view" ?

The goal is to expose a limited object to some Kibana user.  
I know that you can have permission for each field but I don't want to manage permission field by field. (too many of them)

thanks for your guidance.

Regards.  
Sylvain.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [September 6, 2022, 2:51pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/2 "2022-09-06T14:51:02Z")

</div>

You can create [aliases](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-aliases.html) to select which documents an alias could expose. That would be like a `WHERE` clause on SQL.

But to filter the fields I'm afraid you can only do this [reindexing](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) the data, so you can do both select the documents and the fields you want to copy to the destination index. The other option would be to index your data twice at ingest time.

To be honest, I think the best option is to use the [field level security system](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-level-security.html).

---

<div class="post-metadata">

**Author:** ![Sylvain35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain35/32/110194_2.png) [@Sylvain35](https://discuss.elastic.co/u/Sylvain35)\
**Post date:** [September 7, 2022, 12:57pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/3 "2022-09-07T12:57:54Z")

</div>

Thanks a lot for your answer, I was hoping that I have miss an option 😛  
Seems not, we will manage with one of this option. Thanks again.

Best regards.  
ROBERT Sylvain

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 7, 2022, 1:02pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/4 "2022-09-07T13:02:57Z")

</div>

How are you indexing it?

It is easier to make this during the indexing process, in one index you would send the full document and to the other index you would send the limited document.

If you are using Logstash this can be done easily.

---

<div class="post-metadata">

**Author:** ![Sylvain35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain35/32/110194_2.png) [@Sylvain35](https://discuss.elastic.co/u/Sylvain35)\
**Post date:** [September 7, 2022, 2:21pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/5 "2022-09-07T14:21:18Z")

</div>

It's a JAVA code running on a kubernetes cluster, so it's using the java api client

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 7, 2022, 3:08pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/6 "2022-09-07T15:08:51Z")

</div>

You would need to add this logic to your java code then.

Basically you will create two independent indices, one with your full document and other with the limited document so you need to see if it is worth to do that.

---

<div class="post-metadata">

**Author:** ![Sylvain35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain35/32/110194_2.png) [@Sylvain35](https://discuss.elastic.co/u/Sylvain35)\
**Post date:** [September 8, 2022, 12:05pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/7 "2022-09-08T12:05:22Z")

</div>

thanks for your answer, I was looking for a solution that avoid me to duplicate data but it's doesn't seems possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2022, 12:05pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028/8 "2022-10-06T12:05:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
