# How does ES protect users' private information

**URL:** <https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544>\
**Category:** Elasticsearch\
**Created:** [June 30, 2022, 9:01am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544 "2022-06-30T09:01:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yeziblo](https://avatars.discourse-cdn.com/v4/letter/y/74df32/32.png) [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Post date:** [June 30, 2022, 9:01am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/1 "2022-06-30T09:01:39Z")

</div>

We have a user management system that stores some user information, such as email, telephone and so on.

Now I want to protect this information from possible hacking attacks.

Does ES have any good protection for fields?

I have a idea, we can set the \_source property of fields which store the private information to false so that we can still query that data, but we can't get it directly.

Is this approach possible? Is there a better solution?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 9:16am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/2 "2022-06-30T09:16:18Z")

</div>

Is your cluster secure - [Secure the Elastic Stack | Elasticsearch Guide [8.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-cluster.html)?

---

<div class="post-metadata">

**Author:** ![yeziblo](https://avatars.discourse-cdn.com/v4/letter/y/74df32/32.png) [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Post date:** [June 30, 2022, 9:25am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/3 "2022-06-30T09:25:19Z")

</div>

Yes, but even though we did security for cluster, we still wanted to make sure that some fields were ’more secure‘.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2022, 9:33am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/4 "2022-06-30T09:33:30Z")

</div>

Then definitely check out field and document level security.

---

<div class="post-metadata">

**Author:** ![yeziblo](https://avatars.discourse-cdn.com/v4/letter/y/74df32/32.png) [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Post date:** [June 30, 2022, 11:34am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/5 "2022-06-30T11:34:24Z")

</div>

Is there any way to ensure that some fields can only be used for queries and not be seen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2022, 11:34am UTC](https://discuss.elastic.co/t/how-does-es-protect-users-private-information/308544/6 "2022-07-28T11:34:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
