# Reporting encryptionKey vs multiple instances

**URL:** <https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843>\
**Category:** Kibana\
**Tags:** elastic-stack-reporting\
**Created:** [November 21, 2019, 9:29am UTC](https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843 "2019-11-21T09:29:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 21, 2019, 9:29am UTC](https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843/1 "2019-11-21T09:29:28Z")

</div>

Trying to get reporting working here.

Currently got multiple kibana instances using the same .kibana and .reporting index in the same elastic cluster, initially they used a random generated encryptionKey but now I've configured it like this:

```
xpack.reporting.encryptionKey: kibana-reports

```

But still seeing this on launch of kibana:

```
{"type":"log","@timestamp":"2019-11-21T09:17:38Z","tags":["warning","plugins","security","config"],"pid":2022,"message":"Generating a random key for xpack.security.encryptionKey. To prevent sessions from being invalidated on restart, please set xpack.security.encryptionKey in kibana.yml"}

```

Appreciate any hints on how to fix this, TIA!

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [November 21, 2019, 1:15pm UTC](https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843/2 "2019-11-21T13:15:04Z")

</div>

Hey @stefws,

Kibana is actually complaining about a different setting here:  
`xpack.security.encryptionKey`  
vs  
`xpack.reporting.encryptionKey`

There are a couple of different encryption keys that Kibana asks you to set. The security encryption key is used to encrypt the session cookies when users login to Kibana. You will want to set this to the same value on each Kibana instance, so that all instances know how to decrypt the session cookie, regardless of which instance initially created it.

The reporting encryption key is used to encrypt sensitive data in the `.reporting` index, and should likewise be the same across all of your Kibana instances that share the same `.reporting` index.

It's not necessary to set `xpack.reporting.encryptionKey` and `xpack.security.encryptionKey` to the same value though -- you can (and should) use distinct encryption keys for each of these settings, but they should be consistent across all of your instances.

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [November 21, 2019, 1:52pm UTC](https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843/3 "2019-11-21T13:52:52Z")

</div>

😉 thanks for pointing out the obviously hard to see

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2019, 1:52pm UTC](https://discuss.elastic.co/t/reporting-encryptionkey-vs-multiple-instances/208843/4 "2019-12-19T13:52:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
