Kibana credential exposure (ESA-2018-17) fix clarification

Hi, do we need to stop the kibana service before updating the kibana.yml file ? we have 3 node cluster ? how can plan for the update ? update all 3 nodes and then restart the kibana service ?

If you are unable to upgrade, yes stop Kibana service, apply xpack.reporting.enabled: false to kibana.yml, and restart Kibana.

You can reference our Upgrade documentation when you're ready to upgrade your stack.