# Centralized beats configuration

**URL:** <https://discuss.elastic.co/t/centralized-beats-configuration/158969>\
**Category:** Beats\
**Created:** [November 30, 2018, 9:25pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969 "2018-11-30T21:25:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [November 30, 2018, 9:25pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/1 "2018-11-30T21:25:08Z")

</div>

I am trying to utilize the centralize beats feature but seems it requires to configure plain format of user credentials in filebeat.yml file.

```
#========================= Central Management =================================

# Beats is configured under central management, you can define most settings
# from the Kibana UI. You can update this file to configure the settings that
# are not supported by Kibana Beats management.

management:
  enabled: true
  period: 1m0s
  access_token: ${management.accesstoken}
  kibana:
    protocol: https
    host: <kibana-url>
    path: ""
    space.id: ""
    username: ""
    password: ""
    ssl: null
    timeout: 10s
    ignoreversion: true

```

Is there anyway to hide credentials because agents are going to be in all places and thats security concern.

1. Also, seems I cannot configure multiple modules using this feature

---

<div class="post-metadata">

**Author:** ![mladen](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mladen](https://discuss.elastic.co/u/mladen)\
**Post date:** [December 3, 2018, 8:39pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/2 "2018-12-03T20:39:46Z")

</div>

Hi @rpendela please see my [post](https://discuss.elastic.co/t/setup-output-to-elasticsearch-through-centralized-management/157881/16)

BR,  
Mladen

---

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [December 4, 2018, 9:27pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/3 "2018-12-04T21:27:59Z")

</div>

Hey @mladen thanks for reply and I tried like this but didn't work until I enter credentials in plain text

```
#================================ Keystore ==========================================

# Location of the Keystore containing the keys and their sensitive values.

keystore.path: "${path.config}/filebeat.keystore"

# are not supported by Kibana Beats management.

management:
  enabled: true
  period: 1m0s
  access_token: ${management.accesstoken}
  kibana:
    protocol: https
    host: <kibana-url>
    path: ""
    space.id: ""
    username: "username"
    password: ""{$Password}" ----> (which I created using keystore
    ssl: null
    timeout: 10s
    ignoreversion: true

```

Also,  
It seems I need to go back to original server where beat installed to configure below things (which defeats the centralize config purpose), I may be missing on how to do

1. I am not able to go further if I configure output logstash (I see option output logstash but when I enter logstash hosts and save then continues it's not going further or not giving any error)
2. No extra configurations like where to store the logs
3. X-pack monitoring settings

---

<div class="post-metadata">

**Author:** ![rpendela](https://avatars.discourse-cdn.com/v4/letter/r/3be4f8/32.png) [@rpendela](https://discuss.elastic.co/u/rpendela)\
**Post date:** [December 10, 2018, 5:46pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/4 "2018-12-10T17:46:44Z")

</div>

Can anyone help here?

---

<div class="post-metadata">

**Author:** ![mladen](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mladen](https://discuss.elastic.co/u/mladen)\
**Post date:** [December 15, 2018, 12:04pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/5 "2018-12-15T12:04:37Z")

</div>

Hello @rpendela, sorry for my late response. When enroll agent in metricbeat you have only token for that agent. To setup output to elasticsearch use the folowing steps:

Add password to keystore:

`metricbeat keystore add ES_PWD`

I enter password for metricbeat\_internal.

Go to kibana and change output for Elasticsearch:

```
user: metricbeat_internal
password: ${ES_PWD}

```

and save changes.

After this restart metricbeat service.

Now if you check your management.yml user and pass should be like this:

```
elasticsearch:
        hosts:
        - testelastic:9200
        password: ${ES_PWD}
        username: metricbeat_internal

```

BR,  
Mladen

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2019, 2:14pm UTC](https://discuss.elastic.co/t/centralized-beats-configuration/158969/6 "2019-01-12T14:14:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
