# Multi-tenancy problem with Kibana

**URL:** <https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026>\
**Category:** Kibana\
**Created:** [June 7, 2018, 3:17pm UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026 "2018-06-07T15:17:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![riccardopierpaoli](https://avatars.discourse-cdn.com/v4/letter/r/f07891/32.png) [@riccardopierpaoli](https://discuss.elastic.co/u/riccardopierpaoli)\
**Post date:** [June 7, 2018, 3:17pm UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026/1 "2018-06-07T15:17:28Z")

</div>

Hello! This is my issue:  
I try to setup a multi-tenancy system in my Kibana, describe as follow:

**AS IS ENV**

Index: twitter\_index, .kibana

Dashboards: 1,2,3,4 (stored in .kibana)

**TO BE ENV** (I would like 2 different kibana users that will create different dashboards for future dashboards only users)

Index: twitter\_index, .kibana, .kibana-2, .kibana-3

Custom roles definitions:

kibana\_user\_role\_2 (Q: stored in .security-6?)

kibana\_user\_role\_3 (Q: stored in .security-6?)

User definitions:

**U** : marco **R** : kibana\_user\_role\_2

**U** : roberto **R** : kibana\_user\_role\_3

Dashboards: 1,2 (stored in .kibana-2), 3,4 (stored in .kibana-3)

So here are the steps I followed:

1. I created .kiban-a2 index with no mappings. **Q: should I do it or kibana will create it automatically later?**
2. I logged as elastic (superuser) and created kibana\_user\_role\_2 in this way (it’s like a default kibana\_user but with different index privileges):

 ![image002](https://us1.discourse-cdn.com/elastic/original/3X/4/8/481ca798c01afcaddfada2fe7085f29fd24973a7.png)

This is the output from security API:

"kibana\_user\_role\_2" : {

```
"cluster" : [],

"indices" : [

  {

    "names" : [

      ".kibana-2"

    ],

    "privileges" : [

      "manage",

      "read",

      "index",

      "delete"

    ],

    "field_security" : {

      "grant" : []

    }

  }

],

"run_as" : [],

"metadata" : { },

"transient_metadata" : {

  "enabled" : true

}

```

}

What I expect now is that marco user will be able to create and store dashboards inside .kibana-2 index, but when I login I get the following message when opening Discover tab:

Config: Error 403 Forbidden: action [indices:data/write/update] is unauthorized for user [marco]: [security\_exception] action [indices:data/write/update] is unauthorized for user [marco]

What am I missing?

Thanks!!

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [June 7, 2018, 9:04pm UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026/2 "2018-06-07T21:04:48Z")

</div>

Hi there, could you please clarify what you'd like to achieve, just to help me understand better?

It sounds like you want to have three tenants: two tenants will create dashboards, and one tenant will only read them. Is this correct?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![riccardopierpaoli](https://avatars.discourse-cdn.com/v4/letter/r/f07891/32.png) [@riccardopierpaoli](https://discuss.elastic.co/u/riccardopierpaoli)\
**Post date:** [June 8, 2018, 7:20am UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026/3 "2018-06-08T07:20:24Z")

</div>

Hi! First of all thank you for the quick response 😀

My goal is to create dedicated dashboards for specific users. I give you an example; I have 3 users for my kibana: superuser , user A and user B. I need to create 2 different dashboards(dashboard A and dashboard B) as superuser(but it is not a necessary condition for superuser to create them) where the first one it's visible only from user A and the second only from user B. So if user A log in to Kibana, he will see only the the dashboard A (ditto for user B and dashboard B).

From what I have understood I need to create dedicated indices .kibana for every users, like .kibana\_user\_A and .kibana\_user\_ B, and load the dedicated dashboards t here( load dashboard A into .kibana\_user\_A and dashboard B in .kibana\_user\_B), but I don't know how to load the specific .kibana index for the specific user when I log in.  
I know that exist a plug-in that do this but I'd like to know if exist a solution without proxy server and possibly for free 😉  
Thank You!

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [June 8, 2018, 9:18am UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026/4 "2018-06-08T09:18:02Z")

</div>

You will need multiple instances of Kibana to achieve this. Each instance will use one of those .kibana indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2018, 9:18am UTC](https://discuss.elastic.co/t/multi-tenancy-problem-with-kibana/135026/5 "2018-07-06T09:18:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
