# How to filter graph data based on a user attribute

**URL:** <https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692>\
**Category:** Kibana\
**Created:** [February 3, 2020, 8:49pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692 "2020-02-03T20:49:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mallali](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mallali](https://discuss.elastic.co/u/mallali)\
**Post date:** [February 3, 2020, 8:49pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/1 "2020-02-03T20:49:01Z")

</div>

I would like to publish my Kibana dashboard to the end-users and have them see the visualizations based on their data. I was thinking about adding a filter to the visualization based on some user attribute (e.g specific SAML claim). Because of the number of users, it's not feasible to build a dashboard per user.

I was wondering if such a use-case would be possible with the Elastic Stack.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 3, 2020, 10:50pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/2 "2020-02-03T22:50:18Z")

</div>

Hey @mallali, for a user to use a Dashboard they need "Elasticsearch privileges" to read from the indices which contain the data represented in the various visualizations; and they need "Kibana privileges" to access the Dashboard application and the Dashboards themselves.

Are you intending to limit the data which shows up within the Dashboard's visualizations, saved-searches, etc.? If so, when you're creating a custom role you can create give them Elasticsearch privileges so they're only able to see data in a subset of the indices, or even use [DLS](https://www.elastic.co/guide/en/elasticsearch/reference/current/document-level-security.html)

---

<div class="post-metadata">

**Author:** ![mallali](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mallali](https://discuss.elastic.co/u/mallali)\
**Post date:** [February 4, 2020, 1:19pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/3 "2020-02-04T13:19:57Z")

</div>

Hi Brandon, thanks for the reply. That sounds promising.  
Do you mean that I need to assign a custom role to every user, so that the visualizations are updated according to their data?  
How can the lookup field from the index be coupled to a user attribute (a claim attribute from the SAML from example)?  
By the way, I don't know all the users in advance. I plan to use an external identity provider such as ADFS.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [February 4, 2020, 2:33pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/4 "2020-02-04T14:33:44Z")

</div>

Using document level security, you can [template a role query](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-and-document-access-control.html#templating-role-query) based on the attributes of the currently authenticated user. This will prevent you from having to create roles for all of these situations.

Elasticsearch supports SSO using [OpenID Connect](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-guide.html) and [SAML](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide.html), which should both work with ADFS.

---

<div class="post-metadata">

**Author:** ![mallali](https://avatars.discourse-cdn.com/v4/letter/m/da6949/32.png) [@mallali](https://discuss.elastic.co/u/mallali)\
**Post date:** [February 4, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/5 "2020-02-04T14:49:30Z")

</div>

Thanks again Brandon 👍🏻 . Templating role query in combination with the \_user.metadata seems indeed the solution. I will give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-filter-graph-data-based-on-a-user-attribute/217692/6 "2020-03-03T14:49:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
