# Shield - The user can see everyhting?

**URL:** <https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 24, 2016, 6:57pm UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634 "2016-02-24T18:57:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![veve90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veve90/32/6517_2.png) [@veve90](https://discuss.elastic.co/u/veve90)\
**Post date:** [February 24, 2016, 6:57pm UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634/1 "2016-02-24T18:57:28Z")

</div>

Hello,

I need some help with Shield configuration..

Firstly I installed ELK and it worked perfectly. Then I wanted to add Shield. I created the roles, and 2 users that I wanted for Kibana. One that should have access to everything and one to only part of indices.

However, the one that should have access only to one part of the indices is visualizing everything and I wonder if this isn't because in the kibana.yml I have

kibana\_elasticsearch\_username: kibana4-user  
kibana\_elasticsearch\_password: kibana4-password

as it was suggested in the tutorial : [https://www.elastic.co/guide/en/kibana/current/production.html](https://www.elastic.co/guide/en/kibana/current/production.html)

...

Thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 25, 2016, 5:36am UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634/2 "2016-02-25T05:36:53Z")

</div>

Can you provide more details around the users you created and the roles?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [February 25, 2016, 8:15am UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634/3 "2016-02-25T08:15:49Z")

</div>

In this case, it looks like you will need 3 shield users.

User 1: The user for the Kibana server. This user must be granted only the `kibana4_server` role, and should be the user you configure in the `kibana.yml`. This user will perform administrative tasks on behalf of the Kibana server.  
User 2: This is the user that should have _read_ access to all indices. Grant this user the `kibana4` user role (which by default, has read access to all indices)  
User 3: This is the user that should have read access to _some but not all_ indices. For this user, create a new role, based on the `kibana4` role, but instead of granting access to `*` in the role, change that to reference only the specific indices you want this user to see.

Note that you will have to make sure that the users, roles and user role mapping files are in sync (identical) on all nodes in your Elasticsearch cluster. This will get easier in an upcoming release, where we will add a new configuration API that will automatically sync across the cluster. However, for now, you will need to keep these files in sync manually (or preferably with automation tools).

Thanks  
Steve

---

<div class="post-metadata">

**Author:** ![veve90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veve90/32/6517_2.png) [@veve90](https://discuss.elastic.co/u/veve90)\
**Post date:** [February 25, 2016, 10:15am UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634/4 "2016-02-25T10:15:31Z")

</div>

I have looked for hours,  
the mistake was that I created the 2 users but I gave to both of them the role admin...  
In order to check what roles you have a assigned to a user: bin/shield/esusers list

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/shield-the-user-can-see-everyhting/42634/5 "2017-07-06T13:46:26Z")

</div>


