# Report logged in user stats in kibana

**URL:** <https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532>\
**Category:** Kibana\
**Created:** [September 2, 2015, 2:41pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532 "2015-09-02T14:41:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [September 2, 2015, 2:41pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/1 "2015-09-02T14:41:09Z")

</div>

Hi,

I've been asked to integrate our logstash setup with LDAP authentication. So I think I'll need to add shield to our 3 ES nodes. Logstash lives on the first ES node. Can someone please confirm if I need to use shield to integrate logstash into LDAP?

Also I've been asked to find out if there's a way to report what users have logged in via LDAP in kibana. We'd need to be able to gain visibility in into what logs they are using.

So how can we report logstash usage from logged in LDAP users in Kibana?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 2, 2015, 4:04pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/2 "2015-09-02T16:04:39Z")

</div>

This question is really a Kibana question. I don't see how it's related to Logstash at all.

> Can someone please confirm if I need to use shield to integrate logstash into LDAP?

Perhaps, it depends on your requirements. You could certainly put Kibana behind a reverse proxy that deals with the authentication but that wouldn't give you the fine-grained ACLs that I believe you get with Shield.

> Also I've been asked to find out if there's a way to report what users have logged in via LDAP in kibana. We'd need to be able to gain visibility in into what logs they are using.

If you're just using a reverse proxy you can log the name of the users who log in, and if you also have Elasticsearch behind a reverse proxy you can log which indexes are being queried. I don't know what Shield provides in this area.

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [September 2, 2015, 4:08pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/3 "2015-09-02T16:08:41Z")

</div>

Hi Magnus,

Sure that's great. Right now I'm keeping kibana behind nginx using basic auth. So really what I'll need to figure out is how to tie that into LDAP. And log what users have logged in from there. Then feed that log into logstash/kibana. That all makes sense to you?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 2, 2015, 5:07pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/4 "2015-09-02T17:07:35Z")

</div>

Sure, although this isn't the best place to ask about nginx LDAP authentication. But once that works just make sure the logs contain the name of the authenticated user and configure Logstash to read and parse those logs.

---

<div class="post-metadata">

**Author:** ![bluethundr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bluethundr/32/409_2.png) [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Post date:** [September 3, 2015, 6:02pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/5 "2015-09-03T18:02:28Z")

</div>

Yep! Sounds good. And I realize that this may not the best place to ask about that. But thanks anyway! I appreciate your answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:13pm UTC](https://discuss.elastic.co/t/report-logged-in-user-stats-in-kibana/28532/6 "2017-07-06T14:13:47Z")

</div>


