# How to prevent access to specific indexes?

**URL:** <https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 27, 2015, 1:57pm UTC](https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083 "2015-09-27T13:57:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Damore](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@John\_Damore](https://discuss.elastic.co/u/John_Damore)\
**Post date:** [September 27, 2015, 1:57pm UTC](https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083/1 "2015-09-27T13:57:24Z")

</div>

For a user role, I would like to provide access to all indexes except specific indexes patterns can I do that?

Something like:

user:  
indices:  
'_': read  
'._': no access to these

Thanks

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [September 28, 2015, 10:22am UTC](https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083/2 "2015-09-28T10:22:50Z")

</div>

Hi John,

One way to achieve this is to use the support for regular expressions in the roles file. These regular expressions user the Lucene Regexp format; some [examples](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html) of this format can be be found in the elasticsearch documentation.

Do the indices that you don't want the user to access have a specific prefix or anything? If they do, you could define a regex like so:

```auto
user:
  indices:
    '/@$~(prefix.+)/': read

```

That example would allow any index that does not start with `prefix`.

---

<div class="post-metadata">

**Author:** ![John\_Damore](https://avatars.discourse-cdn.com/v4/letter/j/a87d85/32.png) [@John\_Damore](https://discuss.elastic.co/u/John_Damore)\
**Post date:** [September 28, 2015, 9:17pm UTC](https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083/3 "2015-09-28T21:17:00Z")

</div>

Thanks I used your example and just had to change the $ to a &  
so  
'/@&~(prefix.+)/': read

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/how-to-prevent-access-to-specific-indexes/30083/4 "2017-07-06T13:48:19Z")

</div>


