# Kibana/Elastic user restricted to specific index

**URL:** <https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567>\
**Category:** Kibana\
**Created:** [April 25, 2017, 12:30pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567 "2017-04-25T12:30:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![groyee](https://avatars.discourse-cdn.com/v4/letter/g/b19c9b/32.png) [@groyee](https://discuss.elastic.co/u/groyee)\
**Post date:** [April 25, 2017, 12:30pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567/1 "2017-04-25T12:30:01Z")

</div>

Hi,

Is it possible to create a kibana/elastic user limited to a specific index?

I would like that this user will be able to perform all readonly operations on a specific index. He must not see any other indices in the cluster.

I did create a user with a role that is limited to specific index but it didn't work with an error:

_ **you need the privileges granted by both the `kibana user` and `monitoring user` roles.** _

So I added these roles as well to the user but now this user can see other indices.

Thanks.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 25, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567/2 "2017-04-25T13:34:10Z")

</div>

Your user can see that the other indices are there, but can't see any data from them, correct?

If that's your issue, you can't fix that in Kibana. The list of index patterns is stored in the .kibana index which the user has to have access to.

Lee

---

<div class="post-metadata">

**Author:** ![groyee](https://avatars.discourse-cdn.com/v4/letter/g/b19c9b/32.png) [@groyee](https://discuss.elastic.co/u/groyee)\
**Post date:** [April 25, 2017, 2:21pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567/3 "2017-04-25T14:21:36Z")

</div>

This is correct.

Sounds really strange that this is the user management in Kibana. What type of security is it?

Do you think something like this can solve this?

> <https://github.com/floragunncom/search-guard-docs/blob/master/multitenancy.md>

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [April 25, 2017, 2:46pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567/4 "2017-04-25T14:46:23Z")

</div>

We are actively working on improved security. Even with the multitenancy i don't think you'll be able to work around the issue you are describing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 3:00pm UTC](https://discuss.elastic.co/t/kibana-elastic-user-restricted-to-specific-index/83567/5 "2017-05-23T15:00:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
