# ELK APM Security (RUM agents)

**URL:** <https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158>\
**Category:** APM\
**Tags:** rum\
**Created:** [March 21, 2023, 11:07am UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158 "2023-03-21T11:07:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shalinicts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shalinicts/32/81251_2.png) [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Post date:** [March 21, 2023, 11:07am UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/1 "2023-03-21T11:07:38Z")

</div>

Hi Team,  
Hi Team,

APM server - is implemented in a Linux server.  
APM agent - RUM.JS  
AWS Loadbalancer URL (https:x.x.x.x) is implemented between APM agents and APM server.  
APM agent send data to this loadbalancing URL which inturn send data to APM and further to Elastic server.  
Since we are using RUM with anonymous authentication, how can we make sure we have a secure connection with agents and APM server.  
Since the browser based application will be accessed by customers all over internet and the information gets into APM server we need some security layer placed .  
Can anyone guide on this please.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [March 21, 2023, 11:50am UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/2 "2023-03-21T11:50:46Z")

</div>

The guide about [anonymous auth](https://www.elastic.co/guide/en/apm/guide/current/anonymous-auth.html) refers to how you can configure the apm server to allow incoming requests without auth token from configured apm agents, while in general using auth via [api keys](https://www.elastic.co/guide/en/apm/guide/current/api-key.html) or [secret token](https://www.elastic.co/guide/en/apm/guide/current/secret-token.html) for any other apm agents.

---

<div class="post-metadata">

**Author:** ![Shalinicts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shalinicts/32/81251_2.png) [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Post date:** [March 21, 2023, 12:31pm UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/3 "2023-03-21T12:31:21Z")

</div>

Thanks Silvia .  
I think in 7.17 version of Elastic with RUM JS as APM agent we dont have option to configure any security with anonymous authentication.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [March 21, 2023, 12:57pm UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/4 "2023-03-21T12:57:10Z")

</div>

Anonymous auth was also supported in `7.17`, just nested under a different key; check out [7.17-anonymous-auth](https://www.elastic.co/guide/en/apm/guide/7.17/secure-communication-unauthenticated.html) for more details.

---

<div class="post-metadata">

**Author:** ![Shalinicts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shalinicts/32/81251_2.png) [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Post date:** [March 21, 2023, 1:27pm UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/5 "2023-03-21T13:27:40Z")

</div>

Thanks 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2023, 9:27am UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158/6 "2023-04-11T09:27:41Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
