# How to allow user search exact fields?

**URL:** <https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498>\
**Category:** Graylog Central (peer support)\
**Created:** [November 5, 2018, 11:48am UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498 "2018-11-05T11:48:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![merceskoba](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@merceskoba](https://community.graylog.org/u/merceskoba)\
**Post date:** [November 5, 2018, 11:48am UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/1 "2018-11-05T11:48:09Z")

</div>

Hello dear,  
I am setting permissions in Graylog2.  
However, i can give permission `search` through `Stream`.  
When i press Play button in Dashboard and redirect it into `http://IP:PORT/search?rangetype=relative..........` after that, i got `Page not found`.  
Is it possible to set a user can do search for exact path ?  
For example, user Writer can do search `/var/log/writer/access.log` and `/var/log/nginx/access.log`.  
I find Streams and Dashboard settings in permission settings.  
Thank you

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [November 5, 2018, 5:48pm UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/2 "2018-11-05T17:48:20Z")

</div>

you need to seperate the information a user should be able to search at in a stream. You can not give permissions on specific content of fields.

---

<div class="post-metadata">

**Author:** ![merceskoba](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@merceskoba](https://community.graylog.org/u/merceskoba)\
**Post date:** [November 5, 2018, 11:52pm UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/3 "2018-11-05T23:52:41Z")

</div>

Ahhh i had thought Streams for it.  
Would you like to help me pls ?  
How do i create multiple files as a stream source ?  
Example, /var/log/test/blabla.log, /var/log/nginx/blabla.log, /var/log/nginx/error.log  
Should i use `&&` or `AND` ?  
Look at this screenshot

 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/5/5e69771252bc51fd99deb4a8f5e6b7958b214bb9.png)

---

<div class="post-metadata">

**Author:** ![merceskoba](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@merceskoba](https://community.graylog.org/u/merceskoba)\
**Post date:** [November 6, 2018, 4:25am UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/4 "2018-11-06T04:25:26Z")

</div>

hmm… or i should use Add rules ?  
so, first rule /var/log/user/id.access.log  
second rule /var/log/nginx/id.access.log  
third rule /var/log/nginx/id.error.log in same stream  
right ?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [November 6, 2018, 7:24am UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/5 "2018-11-06T07:24:47Z")

</div>

I would go the second route - make debugging and modification easier.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 20, 2018, 7:24am UTC](https://community.graylog.org/t/how-to-allow-user-search-exact-fields/7498/6 "2018-11-20T07:24:48Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
