# Need help starting browser session with Kibana

**URL:** <https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009>\
**Category:** Kibana\
**Created:** [March 26, 2019, 8:41pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009 "2019-03-26T20:41:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ricwhitney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ricwhitney/32/43043_2.png) [@ricwhitney](https://discuss.elastic.co/u/ricwhitney)\
**Post date:** [March 26, 2019, 8:41pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/1 "2019-03-26T20:41:38Z")

</div>

I have a fesh install of Wazuh and Kibana on a VM in the office. The first time I tried any kind of browser session with kibana I get the heretofore mentioned 504 error after accepting the invalid (self-signed) certificate which tells me something is trying to load.

nginx error log:  
2019/03/26 13:27:50 [error] 65695#65695: \*6 upstream timed out (110: Connection timed out) while connecting to upstream, client: 192.168.0.22, server: , request: "GET / HTTP/1.1", upstream: "[http://pub.lic.ip:5601/](http://pub.lic.ip:5601/)", host: "192.168.0.92"

I get the security warning (self-signed cert) but get a 504 error after that  
I have server\_host set at "0.0.0.0" in /etc/kibana/kibana.yml  
should I have this set at something else for internal network only?  
Don't want localhost

any ideas from above error log?

Of course, this is behind our firewall at the office

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![LizaD](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lizad/32/51074_2.png) [@LizaD](https://discuss.elastic.co/u/LizaD)\
**Post date:** [March 26, 2019, 9:04pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/2 "2019-03-26T21:04:46Z")

</div>

@Brandon_Kobel any thoughts ?

---

<div class="post-metadata">

**Author:** ![ricwhitney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ricwhitney/32/43043_2.png) [@ricwhitney](https://discuss.elastic.co/u/ricwhitney)\
**Post date:** [March 26, 2019, 9:08pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/3 "2019-03-26T21:08:13Z")

</div>

Have I even described he scenario well enough?  
@LizaD thanks for the nudge

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 26, 2019, 9:29pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/4 "2019-03-26T21:29:23Z")

</div>

By default, Kibana only listens on `localhost`, this can be configured by setting the `server.host` in your `kibana.yml`. If you set `server.host: 0.0.0.0` in your `kibana.yml`, Kibana will listen on all network interfaces. It's generally better to only listen on the explicit network interface which you expect to receive HTTP requests from. To verify this is configured correctly, you'll want to do the equivalent of a `curl http://your-public-kibana-interface:5601` to ensure that you're able to connect to Kibana from the server that is running nginx. If after setting the `server.host` you're still unable to communicate with Kibana from the server running nginx, there might be a firewall running on your Kibana server that is dropping this request.

I'm not following the part about your self-signed cert, are you setting `server.ssl.*` in your kibana.yml to have Kibana self-host SSL? If you are, you'll have to use "https://" in your nginx configuration and ensure that nginx trusts the certificates that you're using with Kibana.

---

<div class="post-metadata">

**Author:** ![ricwhitney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ricwhitney/32/43043_2.png) [@ricwhitney](https://discuss.elastic.co/u/ricwhitney)\
**Post date:** [March 26, 2019, 9:36pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/5 "2019-03-26T21:36:06Z")

</div>

thanks @Brandon_Kobel

with curl -L [http://192.168.0.92:5601](http://192.168.0.92:5601) I got a lot of html output in the terminal - I'm guessing that's expected? I should probably try it in the browser without https?  
Well I'll be! Just loading it without https worked a charm. Must be something misconfigured with the certs - did you say there was a setting in the kibana file if using self-signed certs?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 26, 2019, 10:16pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/6 "2019-03-26T22:16:19Z")

</div>

To have the Kibana server itself use HTTPS, you can enable this with the following (substituting your own paths):

```auto
server.ssl.enabled: true
server.ssl.certificate: /some/path/to/your/cert.crt
server.ssl.key: /some/path/to/your/cert.key

```

However, when using a reverse-proxy in front of Kibana, it's rather common to do SSL off-loading at the reverse-proxy and have Kibana itself using HTTP, and in that situation you wouldn't configure the aforementioned settings. If you want to take this approach, you'll want to make sure that the reverse-proxy is only accessible by the users which you want to be requiring to use HTTPS and they can't skip the reverse-proxy and hit the Kibana server directly on HTTP. The specifics of this really depends on your network configuration.

---

<div class="post-metadata">

**Author:** ![ricwhitney](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ricwhitney/32/43043_2.png) [@ricwhitney](https://discuss.elastic.co/u/ricwhitney)\
**Post date:** [March 26, 2019, 10:30pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/7 "2019-03-26T22:30:20Z")

</div>

Thank you! I will dig a little deeper as I have fallen back on http for the time being

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2019, 10:30pm UTC](https://discuss.elastic.co/t/need-help-starting-browser-session-with-kibana/174009/8 "2019-04-23T22:30:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
