# Elastic Security Issues

**URL:** <https://discuss.elastic.co/t/elastic-security-issues/342900>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 13, 2023, 4:10am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900 "2023-09-13T04:10:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Phyo\_WaThone\_Win](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/phyo_wathone_win/32/125590_2.png) [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Post date:** [September 13, 2023, 4:10am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900/1 "2023-09-13T04:10:56Z")

</div>

Hello,

Firslty, sorry for my english. In my elastic panel, I see this error

```auto
In your Elasticsearch configuration (elasticsearch.yml), enable:

Elasticsearch security(opens in a new tab or window). Set xpack.security.enabled to true .
API key service(opens in a new tab or window). Set xpack.security.authc.api_key.enabled to true .

```

```auto
API key service(opens in a new tab or window). Set xpack.security.authc.api_key.enabled to true .

```

So, I research about of this error on internet. I see a lot of writeups for this error. But in my elasticsearch.yml file, I cannot  
see

> xpack.security.enabled: true

and

> xpack.security.authc.api\_key.enabled: true

Here is my elasticsearch.yml configuration file.

```auto
# ======================== Elasticsearch Configuration =========================
#
# NOTE: Elasticsearch comes with reasonable defaults for most settings.
# Before you set out to tweak and tune the configuration, make sure you
# understand what are you trying to accomplish and the consequences.
#
# The primary way of configuring a node is via this file. This template lists
# the most important settings you may want to configure for a production cluster.
#
# Please consult the documentation for further information on configuration options:
# https://www.elastic.co/guide/en/elasticsearch/reference/index.html
#
# ---------------------------------- Cluster -----------------------------------
#
# Use a descriptive name for your cluster:
#
#cluster.name: my-application
#
# ------------------------------------ Node ------------------------------------
#
# Use a descriptive name for the node:
#
#node.name: node-1
#
# Add custom attributes to the node:
#
#node.attr.rack: r1
#
# ----------------------------------- Paths ------------------------------------
#
# Path to directory where to store the data (separate multiple locations by comma):
#
path.data: /var/lib/elasticsearch
#
# Path to log files:
#
path.logs: /var/log/elasticsearch
#
# ----------------------------------- Memory -----------------------------------
#
# Lock the memory on startup:
#
#bootstrap.memory_lock: true
#
# Make sure that the heap size is set to about half the memory available
# on the system and that the owner of the process is allowed to use this
# limit.
#
# Elasticsearch performs poorly when the system is swapping the memory.
#
# ---------------------------------- Network -----------------------------------
#
# By default Elasticsearch is only accessible on localhost. Set a different
# address here to expose this node on the network:
#
network.host: localhost
#
# By default Elasticsearch listens for HTTP traffic on the first free port it
# finds starting at 9200. Set a specific HTTP port here:
#
#http.port: 9200
#
# For more information, consult the network module documentation.
#
# --------------------------------- Discovery ----------------------------------
#
# Pass an initial list of hosts to perform discovery when this node is started:
# The default list of hosts is ["127.0.0.1", "[::1]"]
#
#discovery.seed_hosts: ["host1", "host2"]
#
# Bootstrap the cluster using an initial set of master-eligible nodes:
#
#cluster.initial_master_nodes: ["node-1", "node-2"]
#
# For more information, consult the discovery and cluster formation module documentation.
#
# ---------------------------------- Various -----------------------------------
#
# Require explicit names when deleting indices:
#
#action.destructive_requires_name: true
#
# ---------------------------------- Security ----------------------------------
#
# ***WARNING***
#
# Elasticsearch security features are not enabled by default.
# These features are free, but require configuration changes to enable them.
# This means that users don’t have to provide credentials and can get full access
# to the cluster. Network connections are also not encrypted.
#
# To protect your data, we strongly encourage you to enable the Elasticsearch security features. 
# Refer to the following documentation for instructions.
#
# https://www.elastic.co/guide/en/elasticsearch/reference/7.16/configuring-stack-security.html

#xpack.security.enable: true

```

My ELK version is 7.17.13 and When I installation I use this methods [How To Install Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu 22.04 | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-22-04)

Please help me.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [September 13, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900/2 "2023-09-13T11:18:03Z")

</div>

Hi @Phyo_WaThone_Win,

Welcome to the community! I can see that you don't have those options added to your `elasticsearch.yml`. Can you add them to your configuration? That should get rid of the error and ensure you have the security settings enabled.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900/3 "2023-10-11T11:18:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
