# How to enable kibana\_system user for kibana application

**URL:** https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949
**Category:** Kibana
**Tags:** elastic-stack-security
**Created:** [February 11, 2021, 5:20am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949 "2021-02-11T05:20:30Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![kasim123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kasim123/32/58684_2.png) [@kasim123](https://discuss.elastic.co/u/kasim123)
#### Post date: [February 11, 2021, 5:20am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/1 "2021-02-11T05:20:31Z")

</div>

Hi Team,

We have one EFK stack running on 7.4.X version with X-pack security enabled and we defined `elastic` user for kibana application and everything works so far. Now we are trying to use 7.9 version of EFK with same configuration in one of the POC env and noticed few warning messages in kibana pod. It says to use `kibana_system` user instead of `elastic` user for kibana application. My question is, do I have to explicitly define the `kibana_system` user in kibana.yaml file? If yes, how would I set the password for `kibana_system` user password. Earlier, I created secret for `elastic` user and defined password for him. Do I have to follow the same steps for `kibana_system` user for setting new password.

```auto
kubectl --kubeconfig /root/k8s_iac/kubeconfig create secret generic elastic-credentials --from-literal=password=XXXXXX --from-literal=username=elastic 

```

Here are the error messages found in kibana pod.

```auto
{"type":"log","@timestamp":"2021-02-08T13:17:11Z","tags":["warning","config","deprecation"],"pid":6,"message":"Setting [elasticsearch.username] to \"elastic\" is deprecated. You should use the \"kibana_system\" user instead."}
{"type":"log","@timestamp":"2021-02-08T13:17:11Z","tags":["warning","config","deprecation"],"pid":6,"message":"Config key [monitoring.cluster_alerts.email_notifications.email_address] will be required for email notifications to work in 8.0.\""}
{"type":"log","@timestamp":"2021-02-08T13:17:11Z","tags":["warning","config","deprecation"],"pid":6,"message":"Setting [monitoring.username] to \"elastic\" is deprecated. You should use the \"kibana_system\" user instead."}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["warning","plugins","reporting","config"],"pid":6,"message":"Generating a random key for xpack.reporting.encryptionKey. To prevent sessions from being invalidated on restart, please set xpack.reporting.encryptionKey in kibana.yml"}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["warning","plugins","encryptedSavedObjects","config"],"pid":6,"message":"Generating a random key for xpack.encryptedSavedObjects.encryptionKey. To be able to decrypt encrypted saved objects attributes after restart, please set xpack.encryptedSavedObjects.encryptionKey in kibana.yml"}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["warning","plugins","ingestManager"],"pid":6,"message":"Fleet APIs are disabled due to the Encrypted Saved Objects plugin using an ephemeral encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in kibana.yml."}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["warning","plugins","actions","actions"],"pid":6,"message":"APIs are disabled due to the Encrypted Saved Objects plugin using an ephemeral encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in kibana.yml."}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["warning","plugins","alerts","plugins","alerting"],"pid":6,"message":"APIs are disabled due to the Encrypted Saved Objects plugin using an ephemeral encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in kibana.yml."}
{"type":"log","@timestamp":"2021-02-08T13:17:12Z","tags":["info","plugins","monitoring","monitoring"],"pid":6,"message":"config sourced from: production cluster"}
{"type":"log","@timestamp":"2021-02-08T13:17:13Z","tags":["info","savedobjects-service"],"pid":6,"message":"Waiting until all Elasticsearch nodes are compatible with Kibana before starting saved objects migrations..."}
{"type":"log","@timestamp":"2021-02-08T13:17:13Z","tags":["warning","plugins","reporting","config"],"pid":6,"message":"Chromium sandbox provides an additional layer of protection, but is not supported for Linux Centos 7.8.2003 OS. Automatically setting 'xpack.reporting.capture.browser.chromium.disableSandbox: true'."}
{"type":"log","@timestamp":"2021-02-08T13:17:13Z","tags":["info","savedobjects-service"],"pid":6,"message":"Starting saved objects migrations"}

```

---

<div class="post-metadata">

### Author: ![kasim123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kasim123/32/58684_2.png) [@kasim123](https://discuss.elastic.co/u/kasim123)
#### Post date: [February 11, 2021, 12:02pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/2 "2021-02-11T12:02:10Z")

</div>

Pls help me out how to setup kibana to use `kibana_system` user.

---

<div class="post-metadata">

### Author: ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)
#### Post date: [February 11, 2021, 1:58pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/3 "2021-02-11T13:58:44Z")

</div>

Hi @kasim123,

please follow this guide: [Add the built-in user to Kibana | Elasticsearch Reference [7.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/get-started-kibana-user.html)

---

<div class="post-metadata">

### Author: ![kasim123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kasim123/32/58684_2.png) [@kasim123](https://discuss.elastic.co/u/kasim123)
#### Post date: [February 11, 2021, 4:37pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/4 "2021-02-11T16:37:22Z")

</div>

@dosant thanks for the reply. When I use `elasticsearch-setup-passwords` command to set password for `kibana_system`, it changes the password for `elastic` user somethink like shown as below. Can I set password for only `kibana_system` user instead of all users.

```auto
bash-4.4$ ./elasticsearch-setup-passwords auto
Initiating the setup of passwords for reserved users elastic,apm_system,kibana,kibana_system,logstash_system,beats_system,remote_monitoring_user.
The passwords will be randomly generated and printed to the console.
Please confirm that you would like to continue [y/N]y

Changed password for user apm_system
PASSWORD apm_system = KMPYqXNUsOT4vldW528T

Changed password for user kibana_system
PASSWORD kibana_system = FpOa6OdF1xfyVvywPlA3

Changed password for user kibana
PASSWORD kibana = FpOa6OdF1xfyVvywPlA3

Changed password for user logstash_system
PASSWORD logstash_system = I30jrjmlg93xmoFXKBbD

Changed password for user beats_system
PASSWORD beats_system = zVK99Atv1O6YTK11FFGU

Changed password for user remote_monitoring_user
PASSWORD remote_monitoring_user = Z5Y3M1oMpacRSBYIpx0N

Changed password for user elastic
PASSWORD elastic = lNEy28mCbXg2P4eHwJ1M

```

---

<div class="post-metadata">

### Author: ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)
#### Post date: [February 11, 2021, 10:07pm UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/5 "2021-02-11T22:07:43Z")

</div>

That’s not possible. The tool always configure passwords for all users. Can I ask why you don’t want other users’ password being set?

---

<div class="post-metadata">

### Author: ![kasim123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kasim123/32/58684_2.png) [@kasim123](https://discuss.elastic.co/u/kasim123)
#### Post date: [February 12, 2021, 2:54am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/6 "2021-02-12T02:54:25Z")

</div>

I can go with another user, since the log messages of kibana pod saysto use `kibana_system` instead of `elastic` user. How would I create new user?

---

<div class="post-metadata">

### Author: ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)
#### Post date: [February 12, 2021, 5:20am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/7 "2021-02-12T05:20:00Z")

</div>

You can [create your own user](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-put-user.html) and give it the `kibana_system` role. But it's recommended to use the builtin user.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 12, 2021, 5:20am UTC](https://discuss.elastic.co/t/how-to-enable-kibana-system-user-for-kibana-application/263949/8 "2021-03-12T05:20:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
