# Restrict Kibana users to only see some APM service.environment in APM UI

**URL:** <https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784>\
**Category:** APM\
**Tags:** ui\
**Created:** [April 13, 2020, 2:52pm UTC](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784 "2020-04-13T14:52:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Agzem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/agzem/32/72303_2.png) [@Agzem](https://discuss.elastic.co/u/Agzem)\
**Post date:** [April 13, 2020, 2:52pm UTC](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784/1 "2020-04-13T14:52:40Z")

</div>

Hi, I would like to ask if there is a way to config Kibana's APM UI to restrict users to only see some environment in ELK 6.8?  
for example I have 3 APM indexes which are

- `*-apm-*`
- `foo-bar-apm-*`
- `jane-doe-apm-*`

these indexes getting data from 2 Java Apm-Agent's environment configuration which are sending to the same APM server as below

- service.environment : `foo-bar`
- service.environment: `jane-doe`

I configured Kibana config as below for APM UI

```auto
apm_oss:
      indexPattern: "*-apm-*"
      errorIndices: "*-apm-*"
      onboardingIndices: "*-apm-*"
      spanIndices: "*-apm-*"
      transactionIndices: "*-apm-*"

```

now if I want user-A to only see data from `foo-bar` and user-B to only see data from `jane-doe` environment in APM UI is this possible ❓

---

<div class="post-metadata">

**Author:** ![caue.marcondes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/caue.marcondes/32/61739_2.png) [@caue.marcondes](https://discuss.elastic.co/u/caue.marcondes)\
**Post date:** [April 14, 2020, 10:06am UTC](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784/2 "2020-04-14T10:06:53Z")

</div>

Hi @Agzem, how are you doing?

I believe you can achieve what you want by creating a new `Role` for each user and specifying the field `Grant read privileges to specific documents`, like the image below:

 ![Screenshot 2020-04-14 at 11.57.57](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bcfc1371a86f9b6ef84451a639e86165b052b497.png)

As you can see I created a new Role which grants read privileges to `apm-*` but only for `production` environment.

You can read more about it in the [document-level-security](https://www.elastic.co/guide/en/elasticsearch/reference/master/document-level-security.html) page.

---

<div class="post-metadata">

**Author:** ![Agzem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/agzem/32/72303_2.png) [@Agzem](https://discuss.elastic.co/u/Agzem)\
**Post date:** [April 16, 2020, 4:06pm UTC](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784/3 "2020-04-16T16:06:00Z")

</div>

Hey @caue.marcondes, doing great, thanks 😃

ah I see 🤦‍♂️ , I was searching in Kibana documents the whole time. thank you again, this is exactly what I was looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 7, 2020, 12:06pm UTC](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784/4 "2020-05-07T12:06:09Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
