# Kibana User access

**URL:** <https://discuss.elastic.co/t/kibana-user-access/64104>\
**Category:** Kibana\
**Created:** [October 27, 2016, 7:17am UTC](https://discuss.elastic.co/t/kibana-user-access/64104 "2016-10-27T07:17:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [October 27, 2016, 7:17am UTC](https://discuss.elastic.co/t/kibana-user-access/64104/1 "2016-10-27T07:17:52Z")

</div>

Hello All,

I am planning to implement ELK stack on my organization for application teams to visualize their respective logs via Kibana UI. Now my question is,

I have installed ELK on server, and using filebeat i am shipping logs to thiis ELK server from 2 different applications for example.

As I am shipping logs from 2 different applications, I want to restrict the users in one application viewing logs of other application and vice versa. I find shield can be used to restrict user login and secure. But not exactly sure how can i configure to restrict Application 1 log file view access to App1 users only , Application 2 log file view access to App2 users only.

Please advice.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [October 27, 2016, 3:26pm UTC](https://discuss.elastic.co/t/kibana-user-access/64104/2 "2016-10-27T15:26:50Z")

</div>

Hi Manoj,

You could use our commercial security plugin. One plugin installs in Elasticsearch and the other plugin installs in Kibana.

For pre-5.0 products it's called Shield. In 5.0 its the Security plugin which is part of X-Pack [https://www.elastic.co/products/x-pack](https://www.elastic.co/products/x-pack). It's easier to set up on 5.0.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![manojvenkat](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Post date:** [October 27, 2016, 3:28pm UTC](https://discuss.elastic.co/t/kibana-user-access/64104/3 "2016-10-27T15:28:44Z")

</div>

Thanks LeeDr. Yes I did refer documents on xpack. But not getting an idea for my above query. Restricting user to view specific logs. Some guidance appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 28, 2016, 12:33am UTC](https://discuss.elastic.co/t/kibana-user-access/64104/4 "2016-10-28T00:33:32Z")

</div>

You can use document and field level security for that - [https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html)

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [October 28, 2016, 6:00pm UTC](https://discuss.elastic.co/t/kibana-user-access/64104/5 "2016-10-28T18:00:17Z")

</div>

Hi Manoj, I'm not an expert on our permissions setup, but I believe you can configure Roles with access to different fields, documents, and indices, and then assign these Roles to different Users. Can you take a look at [https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html) and let me know if this helps you?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/kibana-user-access/64104/6 "2017-07-06T13:35:15Z")

</div>


