# Kibana login page

**URL:** <https://discuss.elastic.co/t/kibana-login-page/138421>\
**Category:** Kibana\
**Created:** [July 3, 2018, 3:59pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421 "2018-07-03T15:59:12Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 3, 2018, 3:59pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/1 "2018-07-03T15:59:12Z")

</div>

Hi,  
Referred the video in this URL to set up the login account for Kibana UI(Version 6.3.0).  
[https://www.elastic.co/webinars/getting-started-kibana](https://www.elastic.co/webinars/getting-started-kibana)

I installed Kibana 6.3.0, **but not X-pack separately**. Since its not required for this version of Kibana.

In the above video, he installed the x-pack plugin using this command, bin/kibana-plugin install x-pack . If I run the command in terminal, It gave me this message  
"Kibana now contains X-Pack by default, there is no longer any need to install it as it is already present.".  
Does it mean that no need to install x-pack for Kibana 6.3.0? or Still need to install separately something like this in this guide?  
[https://www.elastic.co/guide/en/kibana/5.6/installing-xpack-kb.html](https://www.elastic.co/guide/en/kibana/5.6/installing-xpack-kb.html)

As mentioned in the demo,  
enabled the elasticserach.username : "user"  
elasticserach.password: "pass"

This was the one, when I saw the kibana.yml file.

After I start the cabin service using this command, bin/kibana the Kibana doesn't prompt for any username or password, directly teh home page loaded.

Am I missing any other setting in configuration files?

Can clarify what's wrong in the steps I did?

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 3, 2018, 5:24pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/2 "2018-07-03T17:24:58Z")

</div>

Can you clarify what License type are you on ? IF you have installed 6.3.0, it starts with Basic License first. You would have to go to management UI to start the trial license which gives you the login page.

whats the response of `GET /_xpack/license` if on Basic - you will not get a login screen.

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 4, 2018, 1:07am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/3 "2018-07-04T01:07:37Z")

</div>

HI,  
I updated the trial license yesterday. Bellow is the response that I got, while running GET /\_xpack/license

{  
"license": {  
"status": "active",  
"uid": "323b9023-5ade-4477-8a91-2fa5969f7be0",  
"type": "trial",  
"issue\_date": "2018-07-03T06:11:23.130Z",  
"issue\_date\_in\_millis": 1530598283130,  
"expiry\_date": "2018-08-02T06:11:23.130Z",  
"expiry\_date\_in\_millis": 1533190283130,  
"max\_nodes": 1000,  
"issued\_to": "elasticsearch",  
"issuer": "elasticsearch",  
"start\_date\_in\_millis": -1  
}  
}

Under the Management/License Management, can see this

"Your Trial license is active"  
Your license will expire on August 2, 2018 2:11 PM +08

Only thing is I enabled these two setting in kibana.yml file, as mentioned in that getting started video link  
[https://www.elastic.co/webinars/getting-started-kibana](https://www.elastic.co/webinars/getting-started-kibana)

elasticsearch.username: "user"  
elasticsearch.password: "pass"

FYI, I downloaded the MAC version of Kibana from this URL and installed.  
[https://www.elastic.co/downloads/kibana](https://www.elastic.co/downloads/kibana)

Noticed that there no folder under the installed location of Kibana. Is there anything wrong in my installation?

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 10, 2018, 3:17pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/4 "2018-07-10T15:17:59Z")

</div>

There seems nothing wrong in your installation. You are on Trial License which is valid for 30 days from the date of issue. Can you plz clarify what exactly are you looking for ?Everything seems fine.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 11, 2018, 12:59am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/5 "2018-07-11T00:59:50Z")

</div>

Hi Rashmi,

I want to have a login page only for Kibana but not for Elasticsearch.

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 11, 2018, 4:47am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/6 "2018-07-11T04:47:07Z")

</div>

Elasticsearch is an open-source, broadly-distributable, readily-scalable, enterprise-grade search engine. Accessible through an extensive and elaborate API, Elasticsearch can power extremely fast searches that support your data discovery applications.

Kibana is an open source data visualization plugin for Elasticsearch. It provides visualization capabilities on top of the content indexed on an Elasticsearch. So to answer your question , ES does not have an UI . Kibana is the UI visualization tool for the data indexed into ES and hence provides the login page with the correct license type.

Hope this makes sense.

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 11, 2018, 7:54am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/7 "2018-07-11T07:54:26Z")

</div>

Yes Rashmi, I understood.  
The thing is I need to have a login page for Kibana.  
But I am getting that login page, if I add pack.security.enabled: true in both elasticsearch.yml and kibana.yml

So whats happening, when I ping localhost:9200, the elastic search prompts username and pawssword. So my question is without adding the xpack.security.enabled: true in elasticsearch.yml, Can't get the login page in Kibana?

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 11, 2018, 6:42pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/8 "2018-07-11T18:42:26Z")

</div>

I think there is a misunderstanding how security works. kibana authentication and credentials are managed by Elasticsearch and Kibana is just passing that info on. I don't believe starting a trial has security enabled by default. Otherwise when you click the start trial button you would be locked out of Kibana and wouldn't be able to login. So to answer your question, you do need the settings in both kibana.yml and elasticsearch.yml

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 12, 2018, 1:42am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/9 "2018-07-12T01:42:58Z")

</div>

Ok. When I enabled the xpack security setting in both elasticsearch.yml and kibana.yml, the elasticsearch prompts for username and password.  
If I don't login, Kiabana fails to start the service.

What would be the username and password to login elasticsearch?

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 12, 2018, 2:48pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/10 "2018-07-12T14:48:59Z")

</div>

If you have configured Kibana to use the appropriate built-in user in `kibana.yml` , those would be the credentials for you to login to Elasticsearch .

```auto
elasticsearch.username: "kibana"
elasticsearch.password: "kibanapassword"

```

The password for the built-in kibana user is typically set as part of the X-Pack security configuration process on Elasticsearch. Ref: [https://www.elastic.co/guide/en/elastic-stack-overview/6.3/built-in-users.html](https://www.elastic.co/guide/en/elastic-stack-overview/6.3/built-in-users.html)

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 12, 2018, 3:10pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/11 "2018-07-12T15:10:10Z")

</div>

Here are some useful documentation which might help you understand better :

[https://www.elastic.co/guide/en/elasticsearch/reference/6.3/configuring-security.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/configuring-security.html)  
there are a number of steps that you must take to get security enabled on Elasticsearch, and then you need to setup all the usernames and passwords before moving on [https://www.elastic.co/guide/en/kibana/current/using-kibana-with-security.html](https://www.elastic.co/guide/en/kibana/current/using-kibana-with-security.html).

Also , You must set the passwords for all built-in users. Am thinking you likely missed this part `bin/elasticsearch-setup-passwords interactive`

you can run the command in an "interactive" mode, which prompts you to enter new passwords for the elastic, kibana, logstash\_system, and beats\_system users.

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 14, 2018, 3:58pm UTC](https://discuss.elastic.co/t/kibana-login-page/138421/12 "2018-07-14T15:58:15Z")

</div>

Yes, I also tried to set password for teh default users for elasticsearch. But Throws me newly error. I don't think I changed the password for Elasticsearch or bootstrap before.

I ran this:  
bin/elasticsearch-setup-passwords interactive

Error:  
Failed to authenticate user 'elastic' against [http://127.0.0.1:9200/\_xpack/security/\_authenticate?pretty](http://127.0.0.1:9200/_xpack/security/_authenticate?pretty)  
Possible causes include:

- The password for the 'elastic' user has already been changed on this cluster
- Your elasticsearch node is running against a different keystore  
This tool used the keystore at /Path to elasticsearch-6.3.0/config/elasticsearch.keystore

So I referred this thread....

> [@I lost the password that has been changed](https://discuss.elastic.co/t/i-lost-the-password-that-has-been-changed/91867/2):
>
> Note: These instructions are quite old. Newer instructions are available here [X-Pack Authentication issue](https://discuss.elastic.co/t/x-pack-authentication-issue/121632/7) It is possible to reset the elastic user password (see below) but from your description, it doesn't sound like this is necessarily what you need. The elastic user is a superuser. We don't recommend using it for any purpose other than administering the system. In particular, Kibana should not connect to Elasticsearch using the elastic user - by default it uses the kibana user, so the p…

Then created another user and tried to reset the password for elastic user as shown below:

curl -u my\_admin -XPUT '[http://localhost:9200/\_xpack/security/user/elastic/\_password?pretty](http://localhost:9200/_xpack/security/user/elastic/_password?pretty)' -H 'Content-Type: application/json' -d'  
{  
"password" : "my\_password"  
}'  
Enter host password for user 'my\_admin':  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "cluster\_block\_exception",  
"reason" : "blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"  
}  
],  
"type" : "cluster\_block\_exception",  
"reason" : "blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"  
},  
"status" : 403  
}

How to fix it?

Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 16, 2018, 2:01am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/13 "2018-07-16T02:01:22Z")

</div>

> [@Preethi](#):
>
> "reason" : "blocked by: [FORBIDDEN/12/index read-only / allow delete (api)];"

Your cluster is in a read only state.  
You are probably [low on disk space](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/disk-allocator.html#disk-allocator), but you should check your elasticsearch logs for more details.

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 16, 2018, 2:32am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/14 "2018-07-16T02:32:52Z")

</div>

Yes resolved it.  
I changed the password for built-in users such as elastic, kibana and logstash\_system successfully.  
Now I am able to login kibana. but the problem is I can connect to localhost:9200 in browser but not using curl command. When I run below command,

curl -XGET '[http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)'

getting this error:

{"error":{"root\_cause":[{"type":"security\_exception","reason":"missing authentication token for REST request [/\_cat/indices]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}}],"type":"security\_exception","reason":"missing authentication token for REST request [/\_cat/indices]","header":{"WWW-Authenticate":"Basic realm="security" charset="UTF-8""}},"status":401}

What would be the reason?  
Also I could get response from [http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices) in browser. But I am not able to view the created Elasticsearch index in Kibana. So couldn't create index-pattern.

Could you clarify?

Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 16, 2018, 3:22am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/15 "2018-07-16T03:22:03Z")

</div>

> [@Preethi](#):
>
> curl -XGET '[http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)'

You are not providing any credentials to that curl request. Use the `--user` option.

---

<div class="post-metadata">

**Author:** ![Preethi](https://avatars.discourse-cdn.com/v4/letter/p/f04885/32.png) [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Post date:** [July 16, 2018, 3:35am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/16 "2018-07-16T03:35:12Z")

</div>

Thanks for your reply. When I run below command, Its successfully lists down all the indices created in Elasticsearch.

curl --user \<user\_name\> -XGET '[http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)'

But when I try create the index-pattern in Kibana, the indices are not listed down in selection of teh index. Why?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2018, 3:35am UTC](https://discuss.elastic.co/t/kibana-login-page/138421/17 "2018-08-13T03:35:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
