# Automatically configuring Kibana settings (indexes, visualizations, dashboards) on ECE

**URL:** <https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Tags:** elastic-stack-security\
**Created:** [April 8, 2020, 3:42pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169 "2020-04-08T15:42:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertiansweetman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robertiansweetman/32/65933_2.png) [@robertiansweetman](https://discuss.elastic.co/u/robertiansweetman)\
**Post date:** [April 8, 2020, 3:42pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/1 "2020-04-08T15:42:02Z")

</div>

Hi team

I have used the elasticsearch superuser (elastic) credentials to automatically set up a bunch of elasticsearch indexes by sending the index-file.json contents to the Elastic API endpoint.

My struggle is that I would very much like to do the same with the Kibana settings _because there are a lot more of them_ but I am having some challenges understanding whether this is even possible from the ECE documentation...

If I use the Kibana Endpoint and the elastic (superuser) username and password as credentials I only ever receive a 401 (unauthorized) response. If I use the Elastic endpoint base url this doesn't _appear_ to work with any of the Kibana API endpoints... which is not entirely a suprise...

Is this process documented anywhere with some good examples? Do I need to create a new user in Kibana with some sort of other permissions? I really want to avoid having to upload all the kibana saved objects manually every time we make a change or acquire a new customer.

Really appreciate any help with this

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 8, 2020, 4:18pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/2 "2020-04-08T16:18:11Z")

</div>

Can you give an example of a (sanitized) API endpoint call that is returning 401?

Using `elastic` should allow you to do anything (on a recent cluster - older - 12+ months - ones had some additional restrictions)

Also `401` is normally "wrong password", `403` is what you get when you're not allowed to do something

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 8, 2020, 4:21pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/3 "2020-04-08T16:21:53Z")

</div>

Ah I just re-read .. I suspect the problem is that your Kibana isn't configured to support basic auth?

~~Do you have a config for `xpack.security.authc.providers` in your Kibana YAML? (It defaults to allowing basic)~~

~~[https://www.elastic.co/guide/en/kibana/7.x/kibana-authentication.html](https://www.elastic.co/guide/en/kibana/7.x/kibana-authentication.html)~~

EDIT: see below

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 8, 2020, 4:23pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/4 "2020-04-08T16:23:26Z")

</div>

Oh in fact, some more digging ... looks like Kibana API only allows token based auth: [https://www.elastic.co/guide/en/kibana/7.6/using-api.html](https://www.elastic.co/guide/en/kibana/7.6/using-api.html)

---

<div class="post-metadata">

**Author:** ![robertiansweetman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robertiansweetman/32/65933_2.png) [@robertiansweetman](https://discuss.elastic.co/u/robertiansweetman)\
**Post date:** [April 8, 2020, 4:38pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/5 "2020-04-08T16:38:30Z")

</div>

Thanks @Alex_Piggott

Actually it get's a bit more interesting than that 😉

I'm using PowerShell with the ElasticAPI endpoints and if I create a PSCredential object for Invoke-RestMethod that works fine...

```auto
$secpasswd = ConvertTo-SecureString $Password -AsPlainText -Force
$ElasticCreds = New-Object System.Management.Automation.PSCredential ($Username, $secpasswd)

```

This approach doesn't work with the Kibana endpoints

HOWEVER if I go back to something like this which is (possibly) more like curl...

```auto
$base64AuthInfo = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes(("{0}:{1}" -f $username,$password)))
 $Headers = @{Authorization=("Basic {0}" -f $base64AuthInfo)}

```

Then this works with [https://KibanaAPIendpoint/api/status](https://KibanaAPIendpoint/api/status)

I have set xpack.security.authc.providers: [basic] in the Kibana.yml backend via the user setting over-rides.

Any ideas why one approach would work with Elasticsearch but doesn't with Kibana?

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [April 8, 2020, 5:07pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/6 "2020-04-08T17:07:10Z")

</div>

This maybe explains it: [PowerShell's Invoke-RestMethod equivalent of curl -u (Basic Authentication) - Stack Overflow](https://stackoverflow.com/a/24678979/10483457)

> As noted in the comments, this method will not send the Authorization header on the initial request. It waits for a challenge response then re-sends the request with the Authorization header. This will not work for services that require credentials on the initial request.

I guessing the Kibana API falls into that category and ES API doesn't? Probably worth posting over in the Kibana forum to discuss the gory details 🙂

---

<div class="post-metadata">

**Author:** ![robertiansweetman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robertiansweetman/32/65933_2.png) [@robertiansweetman](https://discuss.elastic.co/u/robertiansweetman)\
**Post date:** [April 8, 2020, 5:25pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/7 "2020-04-08T17:25:38Z")

</div>

Aha! That's super useful to know Alex - thanks

Yes, I will put this in the Kibana forum tomorrow 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2020, 5:25pm UTC](https://discuss.elastic.co/t/automatically-configuring-kibana-settings-indexes-visualizations-dashboards-on-ece/227169/8 "2020-04-22T17:25:39Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
