# General Question regarding specific use-case

**URL:** <https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [June 7, 2016, 8:29am UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038 "2016-06-07T08:29:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ckayay](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@ckayay](https://discuss.elastic.co/u/ckayay)\
**Post date:** [June 7, 2016, 8:29am UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038/1 "2016-06-07T08:29:24Z")

</div>

Hi All,

I am newbie for ES and Shield. I am searching the possibility of doing the following use-case:

- I have XML logs that will be ingested by Logstash
- Logstash will store the data in ES.
- I need to secure specific fields on the XML data (such as Customer Details) and it should rest as such in ES.
- I will use Shield to present the results to users through Kibana based on user roles. And if the user is allowed, they will need to see the encrypted data as decrypted. Otherwise, they will not be able to see the contents of that specific field on Kibana.

Can anyone shed some light on this and how that be achieved using ELK?

Thx a lot.  
cengiz

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2016, 9:22am UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038/2 "2016-06-07T09:22:30Z")

</div>

You can use field level security for this - [https://www.elastic.co/guide/en/shield/current/setting-up-field-and-document-level-security.html](https://www.elastic.co/guide/en/shield/current/setting-up-field-and-document-level-security.html)

Note though, Shield does not encrypt the data in ES.

---

<div class="post-metadata">

**Author:** ![ckayay](https://avatars.discourse-cdn.com/v4/letter/c/d07c76/32.png) [@ckayay](https://discuss.elastic.co/u/ckayay)\
**Post date:** [June 7, 2016, 11:31am UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038/3 "2016-06-07T11:31:38Z")

</div>

Thx for the answer. Yes the only issue is keeping the field encrypted in ES as it can be sensitive data such as Passport Number. Can it be stored encrypted and decrypted on the fly when being accessed to data over ES/Kibana?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 7, 2016, 8:55pm UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038/4 "2016-06-07T20:55:27Z")

</div>

You need to use FS level encryption, at the moment there is no document encryption native to ES.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/general-question-regarding-specific-use-case/52038/5 "2017-07-06T13:44:13Z")

</div>


