# \[security 6.2.2\] hide some visualizations and index patterns

**URL:** https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399
**Category:** Elasticsearch
**Created:** [April 2, 2018, 9:08am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399 "2018-04-02T09:08:10Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)
#### Post date: [April 2, 2018, 9:08am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399/1 "2018-04-02T09:08:10Z")

</div>

Hello,

I want to grant access to some users in kibana (security in x-pack). I create a role my\_role with some index pattern I allow to my users.

I create some users with my\_role+kibana\_user+machine\_learning\_user

Now, the problem is that if I create some visualizations on other indices (with an other role), the users can see them. When they open it they are empty, but at least they see the name.

It is the same for the list of index patterns. They can see the full list, event the indices they do not have rights on.

How can I avoid this?

---

<div class="post-metadata">

### Author: ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)
#### Post date: [April 3, 2018, 8:52am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399/2 "2018-04-03T08:52:27Z")

</div>

Do you want I reformulate?

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [April 4, 2018, 1:58am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399/3 "2018-04-04T01:58:08Z")

</div>

> [@dao](#):
>
> Now, the problem is that if I create some visualizations on other indices (with an other role), the users can see them. When they open it they are empty, but at least they see the name.
> 
> It is the same for the list of index patterns. They can see the full list, event the indices they do not have rights on.
> 
> How can I avoid this?

There is no way to avoid this in current versions of Kibana. Segregation of visualisations is a planned feature, but at the moment the only per-user security is on the underlying data, not the dashboards & visualisations, etc.

---

<div class="post-metadata">

### Author: ![dao](https://avatars.discourse-cdn.com/v4/letter/d/a6a055/32.png) [@dao](https://discuss.elastic.co/u/dao)
#### Post date: [April 4, 2018, 7:44am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399/4 "2018-04-04T07:44:53Z")

</div>

Is it possible to deploy 2 instances of kibana with different `kibana.index` ? would it work modifying this property only?

in that case, the users and roles of x-pack are shared?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 2, 2018, 7:45am UTC](https://discuss.elastic.co/t/security-6-2-2-hide-some-visualizations-and-index-patterns/126399/5 "2018-05-02T07:45:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
