# Managing field access from kibana

**URL:** <https://discuss.elastic.co/t/managing-field-access-from-kibana/52092>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 7, 2016, 2:38pm UTC](https://discuss.elastic.co/t/managing-field-access-from-kibana/52092 "2016-06-07T14:38:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![batzos](https://avatars.discourse-cdn.com/v4/letter/b/9fc348/32.png) [@batzos](https://discuss.elastic.co/u/batzos)\
**Post date:** [June 7, 2016, 2:38pm UTC](https://discuss.elastic.co/t/managing-field-access-from-kibana/52092/1 "2016-06-07T14:38:34Z")

</div>

Could you comment on the following points?

1. If you have not installed shield in Kibana, but only in Elasticsearch, you connect without authentification to Kibana and when you run a query from Kibana, you are asked to provide your credentials in order to connect to Elasticsearch.
2. The users and the roles are all defined in the shield plugin in Elasticsearch. The only reason to install shield also in Kibana is to have the authentication before you connect to Kibana.
3. The example given in the documentation for defining a role for Kibana is the following:

my\_kibana\_user:  
cluster:

- monitor  
indices:
- names: 'logstash-\*'  
privileges:
- view\_index\_metadata
- read
- names: '.kibana\*'  
privileges:
- manage
- read
- index

Is there Field Level Security possible as it is for elasticsearch users? Can we define the fields of the indices where the Kibana user can have access like the following one for the fields "title", "body":

POST /\_shield/role/my\_fls\_role  
{  
"indices": [  
{  
"names": ["index1", "index2"],  
"privileges": ["read"],  
"fields": ["title", "body"]  
}  
]  
}

Thank you in advance.

Kind regards,

Dimitrios

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 10, 2016, 11:33am UTC](https://discuss.elastic.co/t/managing-field-access-from-kibana/52092/2 "2016-06-10T11:33:51Z")

</div>

I believe that this should work. One thing to be aware of is that Kibana may still expose the names of other fields that a user does not have access to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/managing-field-access-from-kibana/52092/3 "2017-07-06T13:44:07Z")

</div>


