# Security settings for Elastic SIEM on-prem

**URL:** https://discuss.elastic.co/t/security-settings-for-elastic-siem-on-prem/245738
**Category:** Elastic Security
**Tags:** elastic-stack-security
**Created:** [August 20, 2020, 9:48am UTC](https://discuss.elastic.co/t/security-settings-for-elastic-siem-on-prem/245738 "2020-08-20T09:48:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![john7](https://avatars.discourse-cdn.com/v4/letter/j/e68b1a/32.png) [@john7](https://discuss.elastic.co/u/john7)
#### Post date: [August 20, 2020, 9:48am UTC](https://discuss.elastic.co/t/security-settings-for-elastic-siem-on-prem/245738/1 "2020-08-20T09:48:42Z")

</div>

Hi everyone,

I'm working on setting up a small Elastic Cluster as a proof of concept for a SIEM.  
Consisting of 3 elastic nodes, one kibana node and one logstash node.  
I managed to get a working cluster without the security configurations for the elastic and kibana nodes. So my next step was to secure the setup and get the full functionality of the SIEM working.

After reading the documentation, I'm wondering what settings I need for a minimum setup, as a lot of these settings seem optional?

[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-settings.html)  
[https://www.elastic.co/guide/en/kibana/7.9/security-settings-kb.html](https://www.elastic.co/guide/en/kibana/7.9/security-settings-kb.html)

The blog post on a small business/home setup gave some great insight on how to setup roll based access for Kibana, but since it uses the cloud instance it doesn't explain the settings needed to secure the elastic cluster on an on-prem setup.

> **[Elastic SIEM for small business and home: Securing cluster access](https://www.elastic.co/blog/elastic-siem-for-small-business-and-home-2-securing-cluster-access)**
>
> Monitoring your servers and workstations does not have to be difficult or expensive. Elastic SIEM is a great way to provide security analytics and monitoring capabilities to small businesses and homes. Check out Part 2 of this blog series to find out...

Is there any guide or blog post that covers the minimum settings needed to get a working on-prem SIEM?

---

<div class="post-metadata">

### Author: ![Mike\_Paquette](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_paquette/32/119011_2.png) [@Mike\_Paquette](https://discuss.elastic.co/u/Mike_Paquette)
#### Post date: [August 20, 2020, 12:08pm UTC](https://discuss.elastic.co/t/security-settings-for-elastic-siem-on-prem/245738/2 "2020-08-20T12:08:14Z")

</div>

Hi Johan, great to see that you're building a POC for Elastic SIEM.

Yes, as you noted, there are some Elasticsearch and Kibana security requirements in order to run this on-premises.

This section of the product documentation provides a good overview of what's needed:  
[https://www.elastic.co/guide/en/security/current/sec-requirements.html](https://www.elastic.co/guide/en/security/current/sec-requirements.html)

(Note: that URL defaults to the latest Elastic Stack software version, currently 7.9. If you're using an older version, you can use this URL: [https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html#detections-permissions), where you can just select your version at the top of that page to get the correct instructions for your version.)

You will see that in some of the subsections, it has additional requirements for on-prem deployments like yours.

FYI, here is a blog that contains a 7-minute video about enabling security on your Elastic Stack deployment. I found this really helpful in understanding what needs to be done and how to do it.

> **[Securing Elasticsearch: How to prevent an Elasticsearch server breach](https://www.elastic.co/blog/how-to-prevent-elasticsearch-server-breach-securing-elasticsearch)**
>
> Read about how data breaches come about and how users can best protect against them in the context of Elasticsearch. Learn how to secure your Elasticsearch clusters, so your data isn't part of an Elasticsearch server breach

Looking forward to your feedback once you get the SIEM up and running!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2022, 8:10am UTC](https://discuss.elastic.co/t/security-settings-for-elastic-siem-on-prem/245738/3 "2022-11-04T08:10:48Z")

</div>


