# Kibana external plugin does not work after enabling security

**URL:** <https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301>\
**Category:** Kibana\
**Created:** [December 18, 2019, 10:31am UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301 "2019-12-18T10:31:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [December 18, 2019, 10:31am UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301/1 "2019-12-18T10:31:28Z")

</div>

Hello,

I have wazuh plugin running in kibana, After I have enabled security the wazuh plugin no longer works. in the logs I am getting the following error message.

```
2001 - [security_exception] action [indices:data/read/search] is unauthorized for user [kibana] (/elastic/apis)

```

But the kibana user is a system user and I cannot modify it so that I would give it access to the api.  
Is there a workaround for this?

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [December 18, 2019, 6:56pm UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301/2 "2019-12-18T18:56:52Z")

</div>

Hi @zozo6015,

I have found this similar issue that might help: [https://github.com/wazuh/wazuh-kibana-app/issues/968](https://github.com/wazuh/wazuh-kibana-app/issues/968)

Thanks,  
Liza

---

<div class="post-metadata">

**Author:** ![zozo6015](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zozo6015/32/12117_2.png) [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Post date:** [December 18, 2019, 8:28pm UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301/3 "2019-12-18T20:28:48Z")

</div>

Configuring the elastic user into kibana.yml instead of the kibana user did the trick however that's not the proper way to configure it because elastic user gives too much power to the kibana. Would make sense to properly assign rights to the kibana role to have access to the elastic api.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [December 18, 2019, 8:38pm UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301/4 "2019-12-18T20:38:50Z")

</div>

Hey @zozo6015, you're right that you really should be setting `elasticsearch.username: elastic` in the `kibana.yml`. This is rather insecure as it allows the Kibana system itself to be a "superuser" and perform actions it shouldn't be able to perform.

The `kibana` user is reserved, and it can't be modified. However, the `kibana` user has the `kibana_system` role, which you can assign to a custom user. I'd recommend asking the Wazuh maintainers which additional privileges the Kibana server needs, creating an additional role which grants those privileges, and then creating a new user which has both the `kibana_system` role and the wazuh privileges.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2020, 8:44pm UTC](https://discuss.elastic.co/t/kibana-external-plugin-does-not-work-after-enabling-security/212301/5 "2020-01-15T20:44:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
