# Hide some dashboards in Kibana with doc level security

**URL:** <https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 3, 2018, 3:18pm UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912 "2018-10-03T15:18:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rapha](https://avatars.discourse-cdn.com/v4/letter/r/8dc957/32.png) [@Rapha](https://discuss.elastic.co/u/Rapha)\
**Post date:** [October 3, 2018, 3:18pm UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912/1 "2018-10-03T15:18:46Z")

</div>

Hi,

I have 3 users using the same Kibana instance, so i would like to use document level security to prevent a user from seeing others users's dashboards.

So for "user1" I try to filter the .kibana index on documents whose name is "user1\_\*".

But when I log with user1 account, he still see all dashboards in the kibana dashboard list.

I use 1 role for user1 with these items :

Kibana Privilege : read  
Index Privilege : .kibana =\> read  
granted document query : {"match":{"dashboard.title":"user1\_\*"}}

Do you think this syntax is correct, or maybe it is not possible to filter the kibana dashboard list this way... ?

Thanks everybody 🙂

Regards,

Rapha

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [October 3, 2018, 5:44pm UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912/2 "2018-10-03T17:44:38Z")

</div>

Hi @Rapha,

I am not authoritative on this, but I think `user1` should not have any privileges for the `.kibana` index. Dashboard entries and other kibana objects are managed by kibana itself, using the  
`.kibana` index, but not in the way you have pointed out. That is, other types of privileges, and not document level security ones, are used to limit scope. This privileges are managed by the kibana process itself (stored in the `.kibana` index) and atm they don't not rely on elasticsearch.

I suppose what you are looking for is [Kibana Spaces](https://www.elastic.co/guide/en/kibana/master/xpack-spaces.html) . Have you tried it? This is the proper way to authorize on kibana objects.

Hope that helps to get a perspective on things,  
Albert

---

<div class="post-metadata">

**Author:** ![Rapha](https://avatars.discourse-cdn.com/v4/letter/r/8dc957/32.png) [@Rapha](https://discuss.elastic.co/u/Rapha)\
**Post date:** [October 4, 2018, 8:14am UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912/3 "2018-10-04T08:14:57Z")

</div>

Hi @Albert_Zaharovits ,

Thanks a lot for your answer. Kibana spaces is exactly the solution I was looking for.

Hope this feature will be released soon. Do you have any informations about that ?

Regards,

Rapha.

---

<div class="post-metadata">

**Author:** ![Albert\_Zaharovits](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/albert_zaharovits/32/24390_2.png) [@Albert\_Zaharovits](https://discuss.elastic.co/u/Albert_Zaharovits)\
**Post date:** [October 4, 2018, 9:52am UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912/4 "2018-10-04T09:52:48Z")

</div>

Hi @Rapha,

I though it was released already, but it obviously was not.  
Should be very soon but we're not allowed to commit to timelines on public forums.

Regards,  
Albert

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2018, 10:02am UTC](https://discuss.elastic.co/t/hide-some-dashboards-in-kibana-with-doc-level-security/150912/5 "2018-11-01T10:02:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
