# sg\_roles.yml setting to show only certain indices to certain users in Kibana?

**URL:** <https://forum.search-guard.com/t/sg-roles-yml-setting-to-show-only-certain-indices-to-certain-users-in-kibana/332>\
**Category:** Search Guard\
**Created:** [December 1, 2016, 5:09pm UTC](https://forum.search-guard.com/t/sg-roles-yml-setting-to-show-only-certain-indices-to-certain-users-in-kibana/332 "2016-12-01T17:09:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZillaYT](https://avatars.discourse-cdn.com/v4/letter/z/4da419/32.png) [@ZillaYT](https://forum.search-guard.com/u/ZillaYT)\
**Post date:** [December 1, 2016, 5:09pm UTC](https://forum.search-guard.com/t/sg-roles-yml-setting-to-show-only-certain-indices-to-certain-users-in-kibana/332/1 "2016-12-01T17:09:09Z")

</div>

I’m using ES v2.4.1 and corresponding SG+SSL and SG v2.4.1.x versions.

So I setup some logstash indices, and say I called them logstash-customer1, logstash-customer2, logstash-customerN. I’m able to set it up so user\_customer1 can view logstash-customer1 data ONLY, user\_customer2 for logstash-customer2 data, etc.

However, user\_customer1 can still see all the index patterns on the left pane. How can I set this so user\_customer1 ONLY sees logstash-customer1 index on left pane, user\_customer2 only sees logstash-customer2 index, etc?

---

<div class="post-metadata">

**Author:** ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)\
**Post date:** [December 1, 2016, 5:13pm UTC](https://forum.search-guard.com/t/sg-roles-yml-setting-to-show-only-certain-indices-to-certain-users-in-kibana/332/2 "2016-12-01T17:13:41Z")

</div>

Unfortunately due to limitations in Kibana that’s not possible. Index patterns, visualizations and dashboards are stored by the kibana server user in the “global” .kibana index. That means that albeit not all users have access to all indices, they still share all dashboards, visualizations etc.

True multi-tenancy support would require changing Kibana itself.

> **···**
>
> Am Donnerstag, 1. Dezember 2016 18:09:09 UTC+1 schrieb ZillaYT:
> 
> > I’m using ES v2.4.1 and corresponding SG+SSL and SG v2.4.1.x versions.
> 
> > So I setup some logstash indices, and say I called them logstash-customer1, logstash-customer2, logstash-customerN. I’m able to set it up so user\_customer1 can view logstash-customer1 data ONLY, user\_customer2 for logstash-customer2 data, etc.
> 
> > 
> 
> > However, user\_customer1 can still see all the index patterns on the left pane. How can I set this so user\_customer1 ONLY sees logstash-customer1 index on left pane, user\_customer2 only sees logstash-customer2 index, etc?

---

<div class="post-metadata">

**Author:** ![ZillaYT](https://avatars.discourse-cdn.com/v4/letter/z/4da419/32.png) [@ZillaYT](https://forum.search-guard.com/u/ZillaYT)\
**Post date:** [December 1, 2016, 5:24pm UTC](https://forum.search-guard.com/t/sg-roles-yml-setting-to-show-only-certain-indices-to-certain-users-in-kibana/332/3 "2016-12-01T17:24:52Z")

</div>

Thanks for the reply!

> **···**
>
> On Thursday, December 1, 2016 at 12:13:41 PM UTC-5, Jochen Kressin wrote:
> 
> > Unfortunately due to limitations in Kibana that’s not possible. Index patterns, visualizations and dashboards are stored by the kibana server user in the “global” .kibana index. That means that albeit not all users have access to all indices, they still share all dashboards, visualizations etc.
> 
> > True multi-tenancy support would require changing Kibana itself.
> > 
> > Am Donnerstag, 1. Dezember 2016 18:09:09 UTC+1 schrieb ZillaYT:
> > 
> > > I’m using ES v2.4.1 and corresponding SG+SSL and SG v2.4.1.x versions.
> 
> > > So I setup some logstash indices, and say I called them logstash-customer1, logstash-customer2, logstash-customerN. I’m able to set it up so user\_customer1 can view logstash-customer1 data ONLY, user\_customer2 for logstash-customer2 data, etc.
> 
> > >
> 
> > > However, user\_customer1 can still see all the index patterns on the left pane. How can I set this so user\_customer1 ONLY sees logstash-customer1 index on left pane, user\_customer2 only sees logstash-customer2 index, etc?
