# User based access control in kibana using Nginx+ lua

**URL:** <https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881>\
**Category:** Kibana\
**Created:** [July 20, 2015, 8:25am UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881 "2015-07-20T08:25:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [July 20, 2015, 8:25am UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/1 "2015-07-20T08:25:21Z")

</div>

Hi,

Is there any way of kibana access control using ngix+lua ?  
i came to know it is possible , if yes is there getting start stuff available ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 20, 2015, 9:37am UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/2 "2015-07-20T09:37:26Z")

</div>

For Kibana 3 (and general direct access to ES) there's [https://www.elastic.co/blog/playing-http-tricks-nginx](https://www.elastic.co/blog/playing-http-tricks-nginx). Maybe some of that can apply to Kibana 4 as well?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [July 20, 2015, 12:56pm UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/3 "2015-07-20T12:56:45Z")

</div>

There is some discussion on the subject on this thread: [Kibana 4 dashboards access control with Shield](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151)

What type of access control are you trying to achieve?

---

<div class="post-metadata">

**Author:** ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Post date:** [July 21, 2015, 5:42am UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/4 "2015-07-21T05:42:07Z")

</div>

hi @tbragin

My requirment is if a user has less privilege that user should not able to see all the dashboard, if super user comes then only all the dashboard should get dispaly, i do not have much acquaintance about user access in kibana , so any reference ?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [July 21, 2015, 1:31pm UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/5 "2015-07-21T13:31:22Z")

</div>

At the moment, the main way I've see users do what you describe is setting up different Kibana instances for different user groups. Other DYI ideas are describe in the thread above.

Longer term, we do plan to introduce fine-grained view-level access control in Kibana: [https://github.com/elastic/kibana/issues/4453](https://github.com/elastic/kibana/issues/4453)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:16pm UTC](https://discuss.elastic.co/t/user-based-access-control-in-kibana-using-nginx-lua/25881/6 "2017-07-06T14:16:08Z")

</div>


