# Only specified value of the field kibana "user" have privilege to view or query

**URL:** <https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560>\
**Category:** Kibana\
**Created:** [June 5, 2018, 8:25am UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560 "2018-06-05T08:25:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [June 5, 2018, 8:25am UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560/1 "2018-06-05T08:25:08Z")

</div>

Hi, I have a question that if I want many users in kibana has different privilege to fetch specified data such user1 can only access SRC\_IP field is in 192.168.0.0/16 or DST\_IP field is in 192.168.0.0/16 and user2 can only access SRC\_IP field is in 192.100.0.0/16 or DST\_IP field is in 192.100.0.0/16 .How can I do?

refer to the reference:  
[https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html](https://www.elastic.co/guide/en/x-pack/current/field-and-document-access-control.html)  
does an index can have different privilege to different users?

thank you in advance!

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 5, 2018, 2:25pm UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560/2 "2018-06-05T14:25:39Z")

</div>

Hey @f26227279 if you set up field level or document level security in Elasticsearch, when the user queries the data from Kibana those privileges will be respected, and you can filter the documents or fields that the user is able to see.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [June 6, 2018, 12:34am UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560/3 "2018-06-06T00:34:02Z")

</div>

yes, but I hope every user has their own dashboard and can't delete other people's dashboard module. Is it feasible?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 6, 2018, 11:12am UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560/4 "2018-06-06T11:12:06Z")

</div>

Currently, users can either have read-only access or write access to all of Kibana's "saved objects" which includes Dashboards/Visualizations/Saved-Searches/etc. There is an ongoing effort to implement a more granular approach to access control which is discussed [here](https://github.com/elastic/kibana/issues/18473)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2018, 11:12am UTC](https://discuss.elastic.co/t/only-specified-value-of-the-field-kibana-user-have-privilege-to-view-or-query/134560/5 "2018-07-04T11:12:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
