# Methods to Enroll Kibana

**URL:** <https://discuss.elastic.co/t/methods-to-enroll-kibana/338164>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [July 12, 2023, 4:22am UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164 "2023-07-12T04:22:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [July 12, 2023, 4:22am UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/1 "2023-07-12T04:22:12Z")

</div>

Hi there,  
Is there a way to enroll kibana other than the mentioned 2 below:-

1. bin/elasticsearch-create-enrollment-token
2. copy the enrollment token from the elasticsearch stdout

**Note** : I am using docker to deploy these two.

But the issue is, due to some reasons I cannot use both these 2 methods.  
Is there any other method to get the enrollment token through API.  
I tried with Kibana enroll API but it's not working.

Also Can I set the password for the `kibana_system` manually by sttting some env variables to get to the login page of kibana UI.

thanks

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 12, 2023, 9:00pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/2 "2023-07-12T21:00:04Z")

</div>

> Is there any other method to get the enrollment token through API.

`bin/elasticsearch-create-enrollment-token` uses an HTTP connection to connect to the cluster to submit API requests to Elasticsearch. Since using the _default_ connection doesn't work for you, you could also use the command from any other Elasticsearch directory and pass the `--url` parameter to specify the base URL that the tool uses. This command does not have to be run in docker or in the local node:

```auto
bin/elasticsearch-create-enrollment-token -s kibana --url "https://my_deployment:9200"

```

> Can I set the password for the `kibana_system` manually by sttting some env variables to get to the login page of kibana UI.

You can set the `elastic` user's password using the `ELASTIC_PASSWORD` environment variable, which [bootstraps the elastic password](https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-users.html#bootstrap-elastic-passwords). Then, you can use a curl command authenticated by the `elastic` user to set the password of the `kibana_system` user.

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [July 13, 2023, 3:07am UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/3 "2023-07-13T03:07:23Z")

</div>

Hi @tsullivan ,  
The thing is due to some reason I do not have access to the docker container directories.  
This is why I am trying to use kibana enroll API `_security/enroll/kibana` to generate enrollment token.  
Is this possible?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 13, 2023, 2:36pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/4 "2023-07-13T14:36:00Z")

</div>

You can download Elasticsearch to your workstation to access the `bin/elasticsearch-create-enrollment-token.` command. Run the command from your workstation using the `--url` flag, and you won't have to access the Docker container directories.

---

<div class="post-metadata">

**Author:** ![ANUBHAV\_GUPTA](https://avatars.discourse-cdn.com/v4/letter/a/7ea924/32.png) [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Post date:** [July 13, 2023, 3:14pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/5 "2023-07-13T15:14:45Z")

</div>

Thanks for the suggestion @tsullivan but It does not fit my use-case.  
Just want to know if the enrollment can be done using `/_security/enroll/kibana` [Enroll Kibana API | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-kibana-enrollment.html)  
Please throw some light on this.

Thanks

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 13, 2023, 6:12pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/6 "2023-07-13T18:12:03Z")

</div>

Hi @ANUBHAV_GUPTA , as it says in the documentation you've linked to, that API is intended for internal use only by Kibana. Because of that, you should not call it directly in your workflow.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2023, 6:12pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164/7 "2023-08-10T18:12:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
