# Elasticsearch: security concerns

**URL:** <https://discuss.elastic.co/t/elasticsearch-security-concerns/19769>\
**Category:** Elasticsearch\
**Created:** [September 13, 2014, 3:33am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769 "2014-09-13T03:33:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jigish\_thakar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jigish_thakar/32/753_2.png) [@jigish\_thakar](https://discuss.elastic.co/u/jigish_thakar)\
**Post date:** [September 13, 2014, 3:33am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769/1 "2014-09-13T03:33:30Z")

</div>

We are using elasticsearch as back-end for our in-house logging and  
monitoring system. We have multiple sites pouring in data to one ES cluster  
but in different index. e.g. abc-us has data from US site, abc-india has it  
from India site.  
Now concerns are we need some security checks before pushing in data to  
cluster.

1. data coming to index is coming from right IP address
2. incoming json request is of inserting new data and not delete/update
3. while reading we want certain IP should not be able to read data of  
other index.

Kindly let me know if its possible to achieve using elasticsearch.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vineeth_mohan_2/32/747_2.png) [@vineeth\_mohan\_2](https://discuss.elastic.co/u/vineeth_mohan_2)\
**Post date:** [September 13, 2014, 3:40am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769/2 "2014-09-13T03:40:01Z")

</div>

Hello Jigish ,

I dont think you can achieve all of these in Elasticsearch.  
You can restrict the HTTP methods to GET and POST in Elasticsearch.  
But for most of other tasks , Nginx would be a better option.  
Elasticsearch jetty plugin might also help you -

> **[GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)**
>
> Contribute to sonian/elasticsearch-jetty development by creating an account on GitHub.

Thanks  
Vineeth

On Sat, Sep 13, 2014 at 9:03 AM, jigish thakar [jigishpthakar@gmail.com](mailto:jigishpthakar@gmail.com)  
wrote:

> We are using elasticsearch as back-end for our in-house logging and  
> monitoring system. We have multiple sites pouring in data to one ES cluster  
> but in different index. e.g. abc-us has data from US site, abc-india has it  
> from India site.  
> Now concerns are we need some security checks before pushing in data to  
> cluster.
> 
> 1. data coming to index is coming from right IP address
> 2. incoming json request is of inserting new data and not delete/update
> 3. while reading we want certain IP should not be able to read data of  
> other index.
> 
> Kindly let me know if its possible to achieve using elasticsearch.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kjhd2C6Jrgy6RmRjsW\_-C-rN85yKBiYbnCyAGdb8h3Ag%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGdPd5kjhd2C6Jrgy6RmRjsW_-C-rN85yKBiYbnCyAGdb8h3Ag%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jigish\_thakar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jigish_thakar/32/753_2.png) [@jigish\_thakar](https://discuss.elastic.co/u/jigish_thakar)\
**Post date:** [September 13, 2014, 5:33am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769/3 "2014-09-13T05:33:16Z")

</div>

Thanks Vineeth. I will look into suggested plugin.

On Saturday, September 13, 2014 9:10:10 AM UTC+5:30, vineeth mohan wrote:

> Hello Jigish ,
> 
> I dont think you can achieve all of these in Elasticsearch.  
> You can restrict the HTTP methods to GET and POST in Elasticsearch.  
> But for most of other tasks , Nginx would be a better option.  
> Elasticsearch jetty plugin might also help you -  
> [GitHub - sonian/elasticsearch-jetty](https://github.com/sonian/elasticsearch-jetty)
> 
> Thanks  
> Vineeth
> 
> On Sat, Sep 13, 2014 at 9:03 AM, jigish thakar \<[jigish...@gmail.com](mailto:jigish...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > We are using elasticsearch as back-end for our in-house logging and  
> > monitoring system. We have multiple sites pouring in data to one ES cluster  
> > but in different index. e.g. abc-us has data from US site, abc-india has it  
> > from India site.  
> > Now concerns are we need some security checks before pushing in data to  
> > cluster.
> > 
> > 1. data coming to index is coming from right IP address
> > 2. incoming json request is of inserting new data and not  
> > delete/update
> > 3. while reading we want certain IP should not be able to read data  
> > of other index.
> > 
> > Kindly let me know if its possible to achieve using elasticsearch.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e7d86fe3-4bcb-49fc-9e18-dc8b1cd51eba%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e7d86fe3-4bcb-49fc-9e18-dc8b1cd51eba%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [September 13, 2014, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769/4 "2014-09-13T11:15:48Z")

</div>

1. The "right IP address" can be achieved with secure sockets between  
hosts. You have to write your own service for this, this is not possible on  
port 9200/9300. Use HTTPS on port 443 at a reverse proxy for this. Use  
only private subnets for ES cluster, i.e. block it from internet access.

2. You must use the \_create endpoint or add parameter create=true to all  
indexing requests:  
[Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/docs-index_.html#operation-type)

3. You must add to your HTTP reverse proxy a dispatcher which accepts only  
requests on certain endpoints and can translate endpoints to index aliases  
(your "certain IP" has exactly on index alias).

With nginx, these tasks are simple.

Jörg

On Sat, Sep 13, 2014 at 5:33 AM, jigish thakar [jigishpthakar@gmail.com](mailto:jigishpthakar@gmail.com)  
wrote:

> We are using elasticsearch as back-end for our in-house logging and  
> monitoring system. We have multiple sites pouring in data to one ES cluster  
> but in different index. e.g. abc-us has data from US site, abc-india has it  
> from India site.  
> Now concerns are we need some security checks before pushing in data to  
> cluster.
> 
> 1. data coming to index is coming from right IP address
> 2. incoming json request is of inserting new data and not delete/update
> 3. while reading we want certain IP should not be able to read data of  
> other index.
> 
> Kindly let me know if its possible to achieve using elasticsearch.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/b1ec03df-245a-4705-92ef-8c26002a7f82%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAKdsXoFgVGce9M7A7c-VEcEFRMugGryATR54HvFczv%3DOBMfUWw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAKdsXoFgVGce9M7A7c-VEcEFRMugGryATR54HvFczv%3DOBMfUWw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:02am UTC](https://discuss.elastic.co/t/elasticsearch-security-concerns/19769/5 "2017-07-06T01:02:35Z")

</div>


