# Kibana user session tracking

**URL:** <https://discuss.elastic.co/t/kibana-user-session-tracking/186226>\
**Category:** Kibana\
**Created:** [June 18, 2019, 10:56am UTC](https://discuss.elastic.co/t/kibana-user-session-tracking/186226 "2019-06-18T10:56:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yungyoung\_Ok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yungyoung_ok/32/43465_2.png) [@Yungyoung\_Ok](https://discuss.elastic.co/u/Yungyoung_Ok)\
**Post date:** [June 18, 2019, 10:56am UTC](https://discuss.elastic.co/t/kibana-user-session-tracking/186226/1 "2019-06-18T10:56:09Z")

</div>

I have three questions.

I want to track user actions in Kibana.  
However, the session ID is changed for each request.  
(I use Kibana6.7.0)

First,  
The session id seems to be encrypted, is that correct?  
If so, how should I decrypt it?

Is the value of xpack.security.encryptionKey in kibana.yml the key to encrypt the session?  
If so, where should I decrypt from function in Kibana?

Second,  
How does access browser cookies in react.js?  
Can I get a user session when I access cookies?

Last,  
If I can not track the user through the session value, can I track it using different values?

Please let me know your answer....!!!!!

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [June 24, 2019, 8:58pm UTC](https://discuss.elastic.co/t/kibana-user-session-tracking/186226/2 "2019-06-24T20:58:25Z")

</div>

@Larry_Gregory or @Brandon_Kobel can get to this q when they get some time.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [June 25, 2019, 12:58pm UTC](https://discuss.elastic.co/t/kibana-user-session-tracking/186226/3 "2019-06-25T12:58:26Z")

</div>

@Yungyoung_Ok,

Yes, session information is encrypted via the `xpack.security.encryptionKey` that you define in your `kibana.yml`. We don't intend for this to be decrypted on your own though, and we make no guarantees as to the contents of the session data.

You can access browser cookies in react the way you would in any JavaScript based application: [`document.cookie`](https://developer.mozilla.org/en-US/docs/Web/API/Document/cookie). Keep in mind that this won't give you access to Kibana's session cookie, as its [HttpOnly flag](https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#Secure_and_HttpOnly_cookies) is set. You'll only be able to access cookies that aren't protected via `HttpOnly`.

You can set your own cookies to track user sessions if that's something you'd like to do.

If you want to get access to the current user, you can make a `GET` request to `http://localhost:5601/api/security/v1/me` (replacing localhost with your kibana instance). A word of caution though: this is not considered a public API, and is subject to change without warning between releases in ways that may not be backwards compatible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 12:58pm UTC](https://discuss.elastic.co/t/kibana-user-session-tracking/186226/4 "2019-07-23T12:58:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
