# Index security in kibana

**URL:** https://discuss.elastic.co/t/index-security-in-kibana/318428
**Category:** Kibana
**Created:** [November 8, 2022, 11:25am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428 "2022-11-08T11:25:38Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Petr.Simik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petr.simik/32/38082_2.png) [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)
#### Post date: [November 8, 2022, 11:25am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428/1 "2022-11-08T11:25:38Z")

</div>

if the user does not have access to the index, no message is displayed (insufficient privileges).  
but just doesn't display any data  
which confuses my users, and they call me saying the data is missing.

This is a situation where I have the correct index pattern in Space , but the user role cannot access it.  
I'm looking for a tip/hint to set Kibana in order it explains to the user that the reason they are not seeing any data is because of user permissions.  
Thank you for the advice

---

<div class="post-metadata">

### Author: ![tiagocosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tiagocosta/32/40045_2.png) [@tiagocosta](https://discuss.elastic.co/u/tiagocosta)
#### Post date: [November 8, 2022, 4:12pm UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428/2 "2022-11-08T16:12:36Z")

</div>

@azasypkin is this something we have planned to be working on or are you aware of a way to overcome this? 😃

---

<div class="post-metadata">

### Author: ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)
#### Post date: [November 9, 2022, 7:50am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428/3 "2022-11-09T07:50:15Z")

</div>

> @azasypkin is this something we have planned to be working on or are you aware of a way to overcome this? 😃

It's something that we need to improve for sure, but it might be a bit tricky since the general consensus in software security is to avoid information leakage and hence hide the difference between missing data and the data that users don't have access to (so that unauthorized users cannot figure out which indices exist based on the error message as it might be sensitive information).

Having said that, I think it'd make sense to expand the scope of [Confusing user experience with limited Kibana permissions · Issue #133727 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/133727) to include limited ES permissions as well. Ideally users\admins shouldn't deal with "Kibana security" and "Elasticsearch security" separately, but it's a significant change that is currently at the brainstorming stage.

@Petr.Simik would you mind posting your use case (voting) on the issue I mentioned above? More real demand might help Global Experience team to prioritize this work.

Thanks,  
Oleg

---

<div class="post-metadata">

### Author: ![Petr.Simik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petr.simik/32/38082_2.png) [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)
#### Post date: [November 10, 2022, 5:02am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428/4 "2022-11-10T05:02:06Z")

</div>

Thank you,  
This confusion stems from the fact that access to the Elastic index is separate from the KIbana index pattern, which is unaware of the Elastic security underneath.  
So the behavior actually makes sense.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 8, 2022, 5:02am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428/5 "2022-12-08T05:02:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
