# Elastic & Kibana Security

**URL:** <https://discuss.elastic.co/t/elastic-kibana-security/339870>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [August 1, 2023, 11:12pm UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870 "2023-08-01T23:12:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kumar\_Abhinav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumar_abhinav/32/122208_2.png) [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Post date:** [August 1, 2023, 11:12pm UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870/1 "2023-08-01T23:12:56Z")

</div>

We have successfully embedded the Kibana dashboard into the RTS (Real-Time System) UI Interface. This integration enables our customers to access the powerful analytics feature seamlessly within our platform.

To provide some context, each of our customers has their own individual login credentials for the RTS platform. Once logged in, they can easily navigate to the Analytics Tab, where they'll find the Kibana dashboard integrated for their convenience.

To enhance the user experience, we've implemented a method to bypass Kibana security without compromising its integrity. This means our users don't have to re-enter their credentials when accessing the dashboard. However, as security is of paramount importance, I want to ensure we take all necessary measures to maintain the security of Kibana and prevent any potential vulnerabilities that may arise due to the integration.

With that in mind, I'm seeking advice and expert insights on this. Are there any best practices or additional security measures we should consider to ensure the seamless and secure functioning of Kibana within our RTS platform?

Here are some relevant technical details:

- RTS version: 7
- Elastic Stack version: 8.7.1
- Security configurations already implemented: NO

Your expertise and guidance in this matter would be highly appreciated.

Sincerely,

---

<div class="post-metadata">

**Author:** ![Kumar\_Abhinav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kumar_abhinav/32/122208_2.png) [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Post date:** [August 4, 2023, 1:12am UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870/2 "2023-08-04T01:12:45Z")

</div>

Would appreciate if any one reply to this query too.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 4, 2023, 4:05am UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870/3 "2023-08-04T04:05:12Z")

</div>

> [@Kumar\_Abhinav](#):
>
> To enhance the user experience, we've implemented a method to bypass Kibana security without compromising its integrity. This means our users don't have to re-enter their credentials when accessing the dashboard.

It is not clear what you did here, are you using the [anymous access](https://www.elastic.co/guide/en/kibana/8.9/kibana-authentication.html#anonymous-authentication) to embed Kibana dashboards?

> [@Kumar\_Abhinav](#):
>
> - RTS version: 7
> - Elastic Stack version: 8.7.1
> - Security configurations already implemented: NO

Not sure what is RTS, but you disabled security for the Elastic Stack? It is not clear.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2023, 4:06am UTC](https://discuss.elastic.co/t/elastic-kibana-security/339870/4 "2023-09-01T04:06:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
