# Integrating ELK with SSO (CA Siteminder)

**URL:** <https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809>\
**Category:** Elasticsearch\
**Created:** [January 23, 2015, 8:50pm UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809 "2015-01-23T20:50:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [January 23, 2015, 8:50pm UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809/1 "2015-01-23T20:50:27Z")

</div>

Hello, I am new to the ELK stack technology, and had a question. My  
organization uses Siteminder to authenticate against their AD environment.  
In order to have this work with ELK, I was going to do the following:

1. Send log data to 1 of 5 different indices, based on source
2. Configure a separate Apache vhost and configure each based on what is  
accessible, i.e. using the LIMIT directives to limit everything except GET  
and POST for a certain index, for example.
3. Configure Siteminder for each vhost, allowing a certain subset of users  
access to each vhost based on what their permissions to each index should  
be (IE security gets access to the vhost that can send all methods, Network  
group can access the vhost that can only send GET and POST to the  
networking index, etc)

I am in the process of testing this, and I got port 80 to work, but I can't  
get another port to work (in my test environment, I do not have access to  
the DNS server yet so I've been using IP vhosts). I've allowed CORS to  
wildcard, I believe, and I've configured ES to bind to the localhost and  
use reverse proxy via apache. It all works on port 80, but when I go on  
port 8080 for example I get the Kibana-ES "Connection Failed" error.

Here are my configs (rough draft, not complete):  
elasticsearch.yml:  
http.cors.enabled: true  
http.cors.allow-origin: "/.\*/"  
network.host:"127.0.0.1"

httpd-vhosts.conf:  
\<VirtualHost _:80\>  
DocumentRoot "/usr/local/data/www/docs/apache/"  
CustomLog "logs/access\_log" combined  
ProxyRequests off  
ProxyPreserveHost on  
ServerName ServerIP  
ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
ProxyPassReverse /elasticsearch /  
\<LocationMatch "//(\_all)/._$"\>  
  
Deny from all  
  
  
\<LocationMatch "//(sec)/._$"\>_  
   
_Deny from all_  
   
   
_\<LocationMatch "//(eng)/._$"\>  
  
Deny from all

\<VirtualHost \*:8080\>  
DocumentRoot "/usr/local/data/www/docs/apache/"  
CustomLog "logs/access\_log" combined  
ProxyRequests off  
#ProxyPreserveHost on  
ServerName _ServerIP_  
ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
ProxyPassReverse /elasticsearch /

Does anybody have any feedback, and know why port 8080 isn't working to  
communicate with ES?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 23, 2015, 10:08pm UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809/2 "2015-01-23T22:08:27Z")

</div>

Can you post the applicable line from your kibana config that points to ES?

On 24 January 2015 at 07:50, Scott Lee [slee@navteca.com](mailto:slee@navteca.com) wrote:

> Hello, I am new to the ELK stack technology, and had a question. My  
> organization uses Siteminder to authenticate against their AD environment.  
> In order to have this work with ELK, I was going to do the following:
> 
> 1. Send log data to 1 of 5 different indices, based on source
> 2. Configure a separate Apache vhost and configure each based on what is  
> accessible, i.e. using the LIMIT directives to limit everything except GET  
> and POST for a certain index, for example.
> 3. Configure Siteminder for each vhost, allowing a certain subset of users  
> access to each vhost based on what their permissions to each index should  
> be (IE security gets access to the vhost that can send all methods, Network  
> group can access the vhost that can only send GET and POST to the  
> networking index, etc)
> 
> I am in the process of testing this, and I got port 80 to work, but I  
> can't get another port to work (in my test environment, I do not have  
> access to the DNS server yet so I've been using IP vhosts). I've allowed  
> CORS to wildcard, I believe, and I've configured ES to bind to the  
> localhost and use reverse proxy via apache. It all works on port 80, but  
> when I go on port 8080 for example I get the Kibana-ES "Connection Failed"  
> error.
> 
> Here are my configs (rough draft, not complete):  
> elasticsearch.yml:  
> http.cors.enabled: true  
> http.cors.allow-origin: "/.\*/"  
> network.host:"127.0.0.1"
> 
> httpd-vhosts.conf:  
> \<VirtualHost _:80\>  
> DocumentRoot "/usr/local/data/www/docs/apache/"  
> CustomLog "logs/access\_log" combined  
> ProxyRequests off  
> ProxyPreserveHost on  
> ServerName ServerIP  
> ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> ProxyPassReverse /elasticsearch /  
> \<LocationMatch "//(\_all)/._$"\>  
>   
> Deny from all  
>   
>   
> \<LocationMatch "//(sec)/._$"\>_  
>    
> _Deny from all_  
>    
>    
> _\<LocationMatch "//(eng)/._$"\>  
>   
> Deny from all
> 
> \<VirtualHost \*:8080\>  
> DocumentRoot "/usr/local/data/www/docs/apache/"  
> CustomLog "logs/access\_log" combined  
> ProxyRequests off  
> #ProxyPreserveHost on  
> ServerName _ServerIP_  
> ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> ProxyPassReverse /elasticsearch /
> 
> Does anybody have any feedback, and know why port 8080 isn't working to  
> communicate with ES?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X97sqHvMuxVyyVB8vX9X%2BLXDO0P1BbKY4Dr\_eZAqg\_9Bg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X97sqHvMuxVyyVB8vX9X%2BLXDO0P1BbKY4Dr_eZAqg_9Bg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [January 26, 2015, 1:20pm UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809/3 "2015-01-26T13:20:15Z")

</div>

Sure it's:  
elasticsearch: "/elasticsearch/",

On Friday, January 23, 2015 at 5:08:59 PM UTC-5, Mark Walkom wrote:

> Can you post the applicable line from your kibana config that points to ES?
> 
> On 24 January 2015 at 07:50, Scott Lee \<[sl...@navteca.com](mailto:sl...@navteca.com) \<javascript:\>\>  
> wrote:
> 
> > Hello, I am new to the ELK stack technology, and had a question. My  
> > organization uses Siteminder to authenticate against their AD environment.  
> > In order to have this work with ELK, I was going to do the following:
> > 
> > 1. Send log data to 1 of 5 different indices, based on source
> > 2. Configure a separate Apache vhost and configure each based on what is  
> > accessible, i.e. using the LIMIT directives to limit everything except GET  
> > and POST for a certain index, for example.
> > 3. Configure Siteminder for each vhost, allowing a certain subset of  
> > users access to each vhost based on what their permissions to each index  
> > should be (IE security gets access to the vhost that can send all methods,  
> > Network group can access the vhost that can only send GET and POST to the  
> > networking index, etc)
> > 
> > I am in the process of testing this, and I got port 80 to work, but I  
> > can't get another port to work (in my test environment, I do not have  
> > access to the DNS server yet so I've been using IP vhosts). I've allowed  
> > CORS to wildcard, I believe, and I've configured ES to bind to the  
> > localhost and use reverse proxy via apache. It all works on port 80, but  
> > when I go on port 8080 for example I get the Kibana-ES "Connection Failed"  
> > error.
> > 
> > Here are my configs (rough draft, not complete):  
> > elasticsearch.yml:  
> > http.cors.enabled: true  
> > http.cors.allow-origin: "/.\*/"  
> > network.host:"127.0.0.1"
> > 
> > httpd-vhosts.conf:  
> > \<VirtualHost _:80\>  
> > DocumentRoot "/usr/local/data/www/docs/apache/"  
> > CustomLog "logs/access\_log" combined  
> > ProxyRequests off  
> > ProxyPreserveHost on  
> > ServerName ServerIP  
> > ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> > ProxyPassReverse /elasticsearch /  
> > \<LocationMatch "//(\_all)/._$"\>  
> >   
> > Deny from all  
> >   
> >   
> > \<LocationMatch "//(sec)/._$"\>_  
> >    
> > _Deny from all_  
> >    
> >    
> > _\<LocationMatch "//(eng)/._$"\>  
> >   
> > Deny from all
> > 
> > \<VirtualHost \*:8080\>  
> > DocumentRoot "/usr/local/data/www/docs/apache/"  
> > CustomLog "logs/access\_log" combined  
> > ProxyRequests off  
> > #ProxyPreserveHost on  
> > ServerName _ServerIP_  
> > ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> > ProxyPassReverse /elasticsearch /
> > 
> > Does anybody have any feedback, and know why port 8080 isn't working to  
> > communicate with ES?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 26, 2015, 10:45pm UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809/4 "2015-01-26T22:45:32Z")

</div>

That doesn't look valid, it should be more like elasticsearch: "http://  
elasticsearch:9200",  
If elasticsearch is the DNS name of your node.

On 27 January 2015 at 00:20, Scott Lee [slee@navteca.com](mailto:slee@navteca.com) wrote:

> Sure it's:  
> elasticsearch: "/elasticsearch/",
> 
> On Friday, January 23, 2015 at 5:08:59 PM UTC-5, Mark Walkom wrote:
> 
> > Can you post the applicable line from your kibana config that points to  
> > ES?
> > 
> > On 24 January 2015 at 07:50, Scott Lee [sl...@navteca.com](mailto:sl...@navteca.com) wrote:
> > 
> > > Hello, I am new to the ELK stack technology, and had a question. My  
> > > organization uses Siteminder to authenticate against their AD environment.  
> > > In order to have this work with ELK, I was going to do the following:
> > > 
> > > 1. Send log data to 1 of 5 different indices, based on source
> > > 2. Configure a separate Apache vhost and configure each based on what is  
> > > accessible, i.e. using the LIMIT directives to limit everything except GET  
> > > and POST for a certain index, for example.
> > > 3. Configure Siteminder for each vhost, allowing a certain subset of  
> > > users access to each vhost based on what their permissions to each index  
> > > should be (IE security gets access to the vhost that can send all methods,  
> > > Network group can access the vhost that can only send GET and POST to the  
> > > networking index, etc)
> > > 
> > > I am in the process of testing this, and I got port 80 to work, but I  
> > > can't get another port to work (in my test environment, I do not have  
> > > access to the DNS server yet so I've been using IP vhosts). I've allowed  
> > > CORS to wildcard, I believe, and I've configured ES to bind to the  
> > > localhost and use reverse proxy via apache. It all works on port 80, but  
> > > when I go on port 8080 for example I get the Kibana-ES "Connection Failed"  
> > > error.
> > > 
> > > Here are my configs (rough draft, not complete):  
> > > elasticsearch.yml:  
> > > http.cors.enabled: true  
> > > http.cors.allow-origin: "/.\*/"  
> > > network.host:"127.0.0.1"
> > > 
> > > httpd-vhosts.conf:  
> > > \<VirtualHost _:80\>  
> > > DocumentRoot "/usr/local/data/www/docs/apache/"  
> > > CustomLog "logs/access\_log" combined  
> > > ProxyRequests off  
> > > ProxyPreserveHost on  
> > > ServerName ServerIP  
> > > ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> > > ProxyPassReverse /elasticsearch /  
> > > \<LocationMatch "//(\_all)/._$"\>  
> > >   
> > > Deny from all  
> > >   
> > >   
> > > \<LocationMatch "//(sec)/._$"\>_  
> > >    
> > > _Deny from all_  
> > >    
> > >    
> > > _\<LocationMatch "//(eng)/._$"\>  
> > >   
> > > Deny from all
> > > 
> > > \<VirtualHost \*:8080\>  
> > > DocumentRoot "/usr/local/data/www/docs/apache/"  
> > > CustomLog "logs/access\_log" combined  
> > > ProxyRequests off  
> > > #ProxyPreserveHost on  
> > > ServerName _ServerIP_  
> > > ProxyPass /elasticsearch [http://127.0.0.1:9200](http://127.0.0.1:9200)  
> > > ProxyPassReverse /elasticsearch /
> > > 
> > > Does anybody have any feedback, and know why port 8080 isn't working to  
> > > communicate with ES?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%  
> > > [40googlegroups.com](http://40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/55240fdf-5ca8-457d-a342-a0ae4eb772dc%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3a6908b6-2080-4ff2-b55b-44bb26302868%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X93iO\_c-%3DOnLQmOes8vofY\_PL7LSHgez-3y%3D7Hb-C%2BwEw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X93iO_c-%3DOnLQmOes8vofY_PL7LSHgez-3y%3D7Hb-C%2BwEw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:36am UTC](https://discuss.elastic.co/t/integrating-elk-with-sso-ca-siteminder/21809/5 "2017-07-06T00:36:34Z")

</div>


