# Kibana 4 dashboards access control with Shield

**URL:** <https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 8, 2015, 5:07pm UTC](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151 "2015-06-08T17:07:15Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![palmerabollo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palmerabollo/32/44772_2.png) [@palmerabollo](https://discuss.elastic.co/u/palmerabollo)\
**Post date:** [July 13, 2015, 6:42am UTC](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151/9 "2015-07-13T06:42:35Z")

</div>

Thanks @matt . I'm particularly interested in how you intercept the AJAX calls from the frontend (kibana\_index) and how you solved [Kibana 4.x with multiple indexes](https://discuss.elastic.co/t/kibana-4-x-with-multiple-indexes/23991).

If I'm not wrong, kibana passes the index name in different (inconsistent) ways. Sometimes in the **body** :

```
POST http://localhost:9200/_mget?timeout=0&ignore_unavailable=true&preference=1436769679508
BODY:
{"docs":[{"_index":".kibana","_type":"index-pattern","_id":"[myindex-]YYYY.MM.DD"}]}

```

Other times in the **URL** itself:

```
POST http://localhost:9200/.kibana/index-pattern/_search?fields=
BODY:
{"query":{"match_all":{}},"size":2147483647}
```

---

_[View the full topic](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151)._
