# Kibana Authentication Accounts

**URL:** <https://discuss.elastic.co/t/kibana-authentication-accounts/253026>\
**Category:** Kibana\
**Created:** [October 22, 2020, 2:59pm UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026 "2020-10-22T14:59:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 22, 2020, 2:59pm UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/1 "2020-10-22T14:59:57Z")

</div>

Hi,  
How can I create accounts on Kibana for other people to access it? Currently, it goes straight into the dashboard when browsing to the URL. It is the Basic version so no AD integration possible.

Also, if adding this authentication, does this then mean I need to change configuration files for Elastic, Logstash, Beats when sending data through?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 23, 2020, 5:02am UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/2 "2020-10-23T05:02:43Z")

</div>

Hello Craig,

Elastic supports two ways of user storage when not connected to an ActiveDirectory or any other service: [File Based](https://www.elastic.co/guide/en/elasticsearch/reference/current/file-realm.html) and [Native](https://www.elastic.co/guide/en/elasticsearch/reference/current/native-realm.html). I would choose the native storage because it is very easy to maintain the users in Kibana.

> [@Craig2188](#):
>
> does this then mean I need to change configuration files for Elastic, Logstash, Beats when sending data through?

Yes, if you want to use authentication this is enabled for any access. This means you have to update Elasticsearch to enable authentication and updating Kibana, LogStash, Beats for accessing the secured cluster.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 23, 2020, 12:22pm UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/3 "2020-10-23T12:22:16Z")

</div>

Sweet got that working... Kibana authentication setup, and logstash also setup with authentication to Elastic  
Beats points to Logstash directly and not Elastic, does that man Beats doesnt need to add in any username or password for logstash output?  
Or, would it need authentication to be added under Kibana.endpoint section?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 26, 2020, 6:07am UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/4 "2020-10-26T06:07:48Z")

</div>

Hello Craig,

LogStash does not support user/password authentication(unfortunately). So Beats does not need to provide credentials to LogStash. If you would want to authenticate Beats too you would have to implement [client certificates in Beats](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-ssl_verify_mode).

The Kibana endpoint section is used for loading dashboards, visualizations and others into Kibana. It is not used to import data at runtime.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 26, 2020, 8:47am UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/5 "2020-10-26T08:47:07Z")

</div>

Yeah found that out thanks!

I have been asked now to make the Kibana logins more secure via TLS rather than plain text. I found this URL to do this:  
[Setting up TLS on a cluster | Elasticsearch Reference [7.9] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ssl-tls.html)

Would it be as simple as doing steps 1 through 5?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 26, 2020, 9:38am UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/6 "2020-10-26T09:38:42Z")

</div>

> [@Craig2188](#):
>
> Would it be as simple as doing steps 1 through 5?

Yes, this should be it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2020, 9:38am UTC](https://discuss.elastic.co/t/kibana-authentication-accounts/253026/7 "2020-11-23T09:38:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
