# Securing Elastic Search single node

**URL:** <https://discuss.elastic.co/t/securing-elastic-search-single-node/198069>\
**Category:** Elasticsearch\
**Created:** [September 4, 2019, 3:31pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069 "2019-09-04T15:31:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joseph\_Mak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_mak/32/42230_2.png) [@Joseph\_Mak](https://discuss.elastic.co/u/Joseph_Mak)\
**Post date:** [September 4, 2019, 3:31pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069/1 "2019-09-04T15:31:40Z")

</div>

I have a single node Elastic Search 6.4, and trying to see if I can add some security on it, like adding a user/password. Trying to follow this guide here

> **[Configure security in Elasticsearch | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-security.html)**

I also have Kibana installed. But I do not see Management-\>Users? I only see Elasticsearch and Kibana management. How do I enable Management Users in Kibana?

So I am having similar question as this post.

> [@How to enable Elastic-Search Security on one node Single cluster](https://discuss.elastic.co/t/how-to-enable-elastic-search-security-on-one-node-single-cluster/186470):
>
> Hey everyone ! I'm currently following these two tutorial to enable elasticsearch security which is now free, but in these two tutorials, it's specified only for two node-cluster and i only have one, my default elastic-search directory is located at /usr/share/elasticsearch/ and the configuration file like the elasticsearch.yml is located at /etc/elasticsearch I tried to adapt the tutorial as i could, but when i had to execute bin/elasticsearch and bin/elasticsearch-setup-password auto, i g…

And yes, my localhost:9200 says Elastic Search is running.

Trying to run: elasticsearch-setup-passwords interactive, and I get the following. How do I set this x-pack?

```
Unexpected response code [404] from calling GET http://localhost:9200/_xpack/security/_authenticate?pretty
It doesn't look like the X-Pack security feature is available on this Elasticsearch node.
Please check if you have installed a license that allows access to X-Pack Security feature.

ERROR: X-Pack Security is not available.

```

---

<div class="post-metadata">

**Author:** ![Preakness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/preakness/32/35560_2.png) [@Preakness](https://discuss.elastic.co/u/Preakness)\
**Post date:** [September 5, 2019, 1:31pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069/2 "2019-09-05T13:31:08Z")

</div>

Hi Joseph, The guide you're following is for Elasticsearch 7.3.

Once xpack is enabled in Kibana you will be presented with a login box for kibana and Elasticsearch api calls will require you to supply a username and password.

Instead follow this guide for 6.4 to enable xpack in Elasticsearch [https://www.elastic.co/guide/en/elasticsearch/reference/6.4/configuring-security.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/configuring-security.html)

Then follow this guide to enable xpack in kibana  
[https://www.elastic.co/guide/en/kibana/6.4/using-kibana-with-security.html](https://www.elastic.co/guide/en/kibana/6.4/using-kibana-with-security.html)

If you run into issues after following these two guides, post your elasticsearch.yml and kibana.yml config files along with your elasticsearch and kibana log files to diagnose.

One important note, when xpack security is enabled, use https instead of http.

---

<div class="post-metadata">

**Author:** ![Joseph\_Mak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_mak/32/42230_2.png) [@Joseph\_Mak](https://discuss.elastic.co/u/Joseph_Mak)\
**Post date:** [September 5, 2019, 2:20pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069/3 "2019-09-05T14:20:02Z")

</div>

Thank you @Preakness

---

<div class="post-metadata">

**Author:** ![Joseph\_Mak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_mak/32/42230_2.png) [@Joseph\_Mak](https://discuss.elastic.co/u/Joseph_Mak)\
**Post date:** [September 9, 2019, 5:35pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069/4 "2019-09-09T17:35:39Z")

</div>

I installed Elastic Search using Windows Installer MSI... and I do not see elasticsearch.yml (I do see kibana.yml). How do I tweak elasticsearch.yml if installed this way?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2019, 5:36pm UTC](https://discuss.elastic.co/t/securing-elastic-search-single-node/198069/5 "2019-10-07T17:36:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
