# Profiling access to Uptime

**URL:** <https://discuss.elastic.co/t/profiling-access-to-uptime/261765>\
**Category:** Synthetics\
**Created:** [January 21, 2021, 10:25am UTC](https://discuss.elastic.co/t/profiling-access-to-uptime/261765 "2021-01-21T10:25:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dantonag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dantonag/32/44130_2.png) [@dantonag](https://discuss.elastic.co/u/dantonag)\
**Post date:** [January 21, 2021, 10:25am UTC](https://discuss.elastic.co/t/profiling-access-to-uptime/261765/1 "2021-01-21T10:25:36Z")

</div>

Hello,  
is it possible within Kibana 7.10.2, to differentiate what users see and what they can do in the Uptime module?  
For example, if I configure a ping for site A and site B, I'd like user A to see only site A in Uptime, and user B to see only site B.  
Thanks

---

<div class="post-metadata">

**Author:** ![jkambic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkambic/32/53306_2.png) [@jkambic](https://discuss.elastic.co/u/jkambic)\
**Post date:** [January 21, 2021, 1:31pm UTC](https://discuss.elastic.co/t/profiling-access-to-uptime/261765/2 "2021-01-21T13:31:30Z")

</div>

Hi @dantonag, yes you can configure Uptime to do this in 7.10. There are a few steps to achieve what you're asking.

1. Configure Heartbeat(s) to write to different indices for your different groups
2. Set up a space for each group of users
3. Create roles for each group of users

Configure your heartbeat(s) to write to the index you want your "User A" to see, `heartbeat-A`, etc.

You can set up [spaces](https://www.elastic.co/guide/en/kibana/master/xpack-spaces.html) in Kibana. For each group of users you want to use Uptime, you can configure a new space; so "user A" will get access to "Space A". As a user with write access for Uptime, you can configure which index Uptime will look for in the given space from the settings page:

 ![spaces](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8cfdae8381c805b2e26e50de6f494137c4944ff.png)

Lastly, create a [role](https://www.elastic.co/guide/en/kibana/current/kibana-role-management.html) to assign to "User A". This role should have read access to the index you used for "Space A" (i.e. `heartbeat-A`), and read-only access to the Uptime app under Kibana privileges:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a5d4780e5aae471d17f4c8b00071d0e706d2da3e.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/956fe6859af39d3a4504ea41202d6246664b3ad8.png)

* * *

**NOTE: be careful that the indices you grant for are unique to the names you use for each group.** If you grant a role access to _heartbeat\*_, and you use _heartbeat-A_ and _heartbeat-B_ for your index names, the role with have access to _both_ indices. The permissions must correlate to the pattern you intend for each role.

* * *

Add your new role to "User A" (find them under `Stack Management/Security/Users`) and now, when they navigate to Uptime they will only see the contents of your `heartbeat-A` index. If you configured them as `Read` access, they can see the settings but not modify them:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eed88bc0c8cc0c711113375104653e8b01dc0e20.png)

Reply back should you have any follow-up questions, we're here to help.

EDIT - I added a section to underline the importance of paying extra attention to index names when granting permissions to roles.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [January 21, 2021, 1:57pm UTC](https://discuss.elastic.co/t/profiling-access-to-uptime/261765/3 "2021-01-21T13:57:03Z")

</div>

@dantonag as a note, this will separate the monitors in the UI, but you'll need to set index level permissions to fully ensure that users can't read indexes they aren't supposed to have access to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2021, 1:57pm UTC](https://discuss.elastic.co/t/profiling-access-to-uptime/261765/4 "2021-02-14T13:57:16Z")

</div>

This topic was automatically closed 24 days after the last reply. New replies are no longer allowed.
