# Multi tenancy

**URL:** <https://discuss.elastic.co/t/multi-tenancy/162443>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 30, 2018, 11:17am UTC](https://discuss.elastic.co/t/multi-tenancy/162443 "2018-12-30T11:17:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [December 30, 2018, 11:17am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/1 "2018-12-30T11:17:31Z")

</div>

hi all  
i am using x-pack to have security feature.  
suppose, i have two indices in the discover part of kibana console. i have superuser access and want to define access for other users. for example there are user1 and user2. i want to give read and search access to user1 so that can login into kibana and watch logs of index1 and can search and filter them. also, i want to access user2 so that can search, watch and filter logs of index 2. notably user1 should not access to index2 logs and user2 should not access to index1 logs. how can i do this? what roles should be defined in kibana console?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 31, 2018, 5:49am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/2 "2018-12-31T05:49:35Z")

</div>

Roles are documented here:

- [https://www.elastic.co/guide/en/elastic-stack-overview/6.5/defining-roles.html](https://www.elastic.co/guide/en/elastic-stack-overview/6.5/defining-roles.html)

If you want to have 2 different users with different indices, then you will need define 2 new roles, and assign 1 to each user.

The 2 roles will need to refer to different indices in the "Indices Privileges" section:

- [https://www.elastic.co/guide/en/elastic-stack-overview/6.5/defining-roles.html#roles-indices-priv](https://www.elastic.co/guide/en/elastic-stack-overview/6.5/defining-roles.html#roles-indices-priv)

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [December 31, 2018, 7:20am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/3 "2018-12-31T07:20:04Z")

</div>

thanks

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [December 31, 2018, 8:34am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/4 "2018-12-31T08:34:34Z")

</div>

Dear Tim,  
i defined roles and users successfully.  
I have an index which consists of two types of tag (tag1 and tag2), is it possible to control access of users based on the tags? for example user1 just can see data related to tag1 of index and user2 can see data related to tag2.  
we can select tags in granted fields, but how can i set an specific tag to the user? means, select for example tag1 for user1

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [December 31, 2018, 10:52am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/5 "2018-12-31T10:52:31Z")

</div>

it has been done, thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2019, 10:52am UTC](https://discuss.elastic.co/t/multi-tenancy/162443/6 "2019-01-28T10:52:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
