# X-pack data masking

**URL:** <https://discuss.elastic.co/t/x-pack-data-masking/172824>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [March 18, 2019, 4:19pm UTC](https://discuss.elastic.co/t/x-pack-data-masking/172824 "2019-03-18T16:19:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 18, 2019, 4:19pm UTC](https://discuss.elastic.co/t/x-pack-data-masking/172824/1 "2019-03-18T16:19:50Z")

</div>

Hi there!

I'd like to show the values of a field only if it is equal to a certain value, otherwise an alias must be shown. This must work on a per-user basis.

It means:

I have a field car\_maker that can be equal to "BRAND1", "BRAND2", "BRAND3".  
If the admin (of another user with proper permissions) visualizes the data, he can see all the above-mentioned values.

If a user "customer" accesses the data, he can see the values with the explicit car\_maker field only if it is equal to "BRAND1", otherwise "unknown1", "unknown2" must replace "BRAND2" and "BRAND3".

This must be accomplished on the overall architecture (e.g. on both Discover and any Dashboard or Visualization) over several countries. So if the previous example refers to country Italy, if the "customer" user decides to see the Germany Dashboard (in Germany the car\_maker field can be "BRAND1", "BRAND4") again he must only be allowed to see the value if it is equal to "BRAND1" and see "unknown1" instead of "BRAND4".

Is there a way to accomplish such a task?

Thank you

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [March 18, 2019, 4:56pm UTC](https://discuss.elastic.co/t/x-pack-data-masking/172824/2 "2019-03-18T16:56:27Z")

</div>

Hi @Fabio-sama,

I feels like what you're looking for is [Document level security](https://github.com/elastic/stack-docs/edit/6.6/docs/en/stack/security/authorization/document-level-security.asciidoc) and [Field level security](https://github.com/elastic/stack-docs/edit/6.6/docs/en/stack/security/authorization/field-level-security.asciidoc). I'm not sure about changing "BRAND1" to "unknown" on the fly though but you can definitely limit docs that are available to a particular role based on the query (e.g. `customer` role gives access only to documents with `BRAND2`).

If you combine that with [Spaces](https://www.elastic.co/guide/en/kibana/6.7/xpack-spaces.html) you can organize and secure your data even better.

I'd encourage you to experiment with these features and get back if you still have any questions.

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2019, 4:56pm UTC](https://discuss.elastic.co/t/x-pack-data-masking/172824/3 "2019-04-15T16:56:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
