# How to create different roles for same index?

**URL:** <https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 30, 2015, 6:29am UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599 "2015-06-30T06:29:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [June 30, 2015, 6:29am UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599/1 "2015-06-30T06:29:06Z")

</div>

Im having index named "logs". Im getting all databses and application and server logs in the same index. How can i create different roles so that one can monitor only database and one can monitor only application?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 30, 2015, 7:59am UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599/2 "2015-06-30T07:59:01Z")

</div>

Ideally you should put these into their own indices, this is a data hygiene thing as much as a security one.

Are you ingesting these with Logstash? Are you defining a specific \_type or applying a tag?

---

<div class="post-metadata">

**Author:** ![Akhilesh\_Anb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akhilesh_anb/32/4343_2.png) [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Post date:** [June 30, 2015, 8:02am UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599/3 "2015-06-30T08:02:13Z")

</div>

Im using packetbeat for the logs from database and server logs. so im getting alll logs in same index.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 30, 2015, 8:30am UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599/4 "2015-06-30T08:30:23Z")

</div>

If you have fields in your data that can be used to determine who should be able to see what data, you can create filtered aliases on top of the index and secure these.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/how-to-create-different-roles-for-same-index/24599/5 "2017-07-06T13:49:03Z")

</div>


