# ./bin/kibana-keystore add elastic.apm.secretToken does nothing

**URL:** <https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577>\
**Category:** APM\
**Tags:** docker, fleet, ui\
**Created:** [December 18, 2023, 4:06pm UTC](https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577 "2023-12-18T16:06:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [December 18, 2023, 4:06pm UTC](https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577/1 "2023-12-18T16:06:47Z")

</div>

I can't seem to get the `./bin/kibana-keystore` to work for the field `elastic.apm.secretToken`.

I started by making sure Kibana can work with APM. This `kibana.yml` file works perfectly:

```auto
elastic:
  apm:
    active: true
    serverUrl: "http://fleet-server:8200"
    secretToken: "supersecrettoken"
server.host: "0.0.0.0"
telemetry.enabled: "true"
xpack.fleet.packages:
  - name: fleet_server
    version: latest
  - name: system
    version: latest
  - name: elastic_agent
    version: latest
  - name: apm
    version: latest
xpack.fleet.agentPolicies:
  - name: Fleet-Server-Policy
    id: fleet-server-policy
    namespace: default
    monitoring_enabled:
      - logs
      - metrics
    package_policies:
      - name: fleet_server-1
        package:
          name: fleet_server
      - name: system-1
        package:
          name: system
      - name: elastic_agent-1
        package:
          name: elastic_agent
      - name: apm-1
        package:
          name: apm
        inputs:
        - type: apm
          enabled: true
          vars:
          - name: host
            value: 0.0.0.0:8200
          - name: secret_token
            value: "supersecrettoken"

```

After I configure Fleet Server, I can see `kibana` listed as a service in my web browser at `https://192.168.0.22:5601/app/apm/services`.

However, if I delete just the one line `elastic.apm.secretToken`, and repeat the whole set up with

```auto
echo "supersecrettoken"| /usr/share/kibana/bin/kibana-keystore add elastic.apm.secretToken -x;

```

Then this breaks the connection between Kibana and APM. I'm pretty confident that my `./bin/kibana-keystore` is working for every other field. It is properly setting fields like `xpack.security.encryptionKey, xpack.encryptedSavedObjects.encryptionKey, xpack.reporting.encryptionKey`.

The only fields it can't seem to set are:

```auto
 /usr/share/kibana/bin/kibana-keystore add elastic.apm.secretToken
/usr/share/kibana/bin/kibana-keystore add xpack.fleet.agentPolicies[0].package_policies[3].inputs[0].vars[1].value

```

Is this a known issue?

**Kibana version** :

8.8.2

**Elasticsearch version** :

8.8.2

**APM Server version** :

8.8.2

**Original install method (e.g. download page, yum, deb, from source, etc.) and version**:

I'm using docker-compose and I'm starting from this github project:

> **[GitHub - elkninja/elastic-stack-docker-part-two](https://github.com/elkninja/elastic-stack-docker-part-two)**
>
> Contribute to elkninja/elastic-stack-docker-part-two development by creating an account on GitHub.

> **[Getting started with the Elastic Stack and Docker Compose: Part 2](https://www.elastic.co/blog/getting-started-with-the-elastic-stack-and-docker-compose-part-2)**
>
> In this blog, build on our previous cluster and implement additional features such as Fleet, Agent, APM, and a demo application for your POC delight! Remember, Docker Compose is not recommended for production, even if the cluster sizing is larger.

**Fresh install or upgraded from other version?**

**Is there anything special in your setup?** For example, are you using the Logstash or Kafka outputs? Are you using a load balancer in front of the APM Servers? Have you changed index pattern, generated custom templates, changed agent configuration etc.

No, i'm just trying to use kibana keystore to save APM secret Tokens.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2024, 4:07pm UTC](https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577/2 "2024-01-15T16:07:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
