# X-Pack Security :: Role Index Restriction with Regexp

**URL:** <https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908>\
**Category:** Elasticsearch\
**Created:** [December 21, 2017, 11:04pm UTC](https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908 "2017-12-21T23:04:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aaronloesattv](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@aaronloesattv](https://discuss.elastic.co/u/aaronloesattv)\
**Post date:** [December 21, 2017, 11:04pm UTC](https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908/1 "2017-12-21T23:04:09Z")

</div>

We have an ES cluster we're using for logs. We have many indexes that are prefixed with "log-". I'm trying to create two roles, one which has access to all log indexes which is easy enough, but another that has access to all log indexes except a few. I've tried using the lucene regex to exclude index patterns that contain certain phrases but i'm having no luck. I've found little to no documentation or examples on how to do various regex based tasks with lucene. I've gone through the Elasticsearch regexp syntax but that also is not getting me to what i want. Am i stuck whitelisting all indexes by name or can i solve this with a regexp and am just not knowing what to do?

Example use case, given the following indexes:

log-widget-alpha-2017.01  
log-doodad-wubwub-2017.01  
log-widget-alpha-2017.02  
log-doodad-wubwub-2017.02  
log-wuble-wamwam-2017.01  
log-monkey-2017.01

i want a role that can only have read access to all but "log-wuble-wamwam-_" and "log-monkey-_". if i were using standard-ish regex, i would do something like this:

```
POST /_xpack/security/role/untrusted-user
{
  "indices": [
    {
      "names": ["/log-((?!wuble-wamwam|monkey).*?)-[0-9]{4}\.[0-9]{2}/" ],
      "privileges": ["read"]
    }
  ]
}

```

[https://regex101.com/r/4WyyKu/1](https://regex101.com/r/4WyyKu/1)

but this clearly doesn't work. Any suggestions? Any solutions is helpful as long as i dont have to individually list out every index pattern individually.

Thank you

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 22, 2017, 2:35am UTC](https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908/2 "2017-12-22T02:35:02Z")

</div>

You can do this with regular expressions, but the syntax isn't super-obvious.  
We use [Lucene RegExp](http://lucene.apache.org/core/6_0_0/core/org/apache/lucene/util/automaton/RegExp.html) syntax for this, which is powerful, but slightly different to standard java Patterns.

This is what you want:

```auto
POST /_xpack/security/user/test
{
  "password": "changeme",
  "roles": ["untrusted-user"],
  "enabled": true
}

```

```auto
POST /_xpack/security/role/untrusted-user
{
  "indices": [
    {
      "names": ["/log-@&~(log-wuble-wamwam-@|log-monkey-@)/"],
      "privileges": ["read"]
    }
  ]
}

```

Then as user _test_

```auto
GET /_xpack/security/user/_has_privileges
{
  "index" : [
    {
      "names": [
        "log-widget-alpha-2017.01",
        "log-doodad-wubwub-2017.01",
        "log-widget-alpha-2017.02",
        "log-doodad-wubwub-2017.02",
        "log-wuble-wamwam-2017.01",
        "log-monkey-2017.01",
        "log-log-monkey-2017.01",
        "not-log-widget-alpha-2017.02"
        ],
      "privileges": ["read"]
    }
  ]
}
---
{
  "username" : "test",
  "has_all_requested" : false,
  "cluster" : { },
  "index" : {
    "log-widget-alpha-2017.01" : {
      "read" : true
    },
    "log-doodad-wubwub-2017.01" : {
      "read" : true
    },
    "log-widget-alpha-2017.02" : {
      "read" : true
    },
    "log-doodad-wubwub-2017.02" : {
      "read" : true
    },
    "log-wuble-wamwam-2017.01" : {
      "read" : false
    },
    "log-monkey-2017.01" : {
      "read" : false
    },
    "log-log-monkey-2017.01" : {
      "read" : true
    },
    "not-log-widget-alpha-2017.02" : {
      "read" : false
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![aaronloesattv](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@aaronloesattv](https://discuss.elastic.co/u/aaronloesattv)\
**Post date:** [December 22, 2017, 5:20pm UTC](https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908/3 "2017-12-22T17:20:16Z")

</div>

I found that lucene javadoc on regex but it wasn't particularly helpful for me. your response and this page were much more helpful.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html)

with your response, i was able to achieve what i needed.

many thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2018, 5:20pm UTC](https://discuss.elastic.co/t/x-pack-security-role-index-restriction-with-regexp/112908/4 "2018-01-19T17:20:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
