# SESSION\_EXPIRED after logging in another Kibana

**URL:** <https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [August 17, 2023, 11:36am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003 "2023-08-17T11:36:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![theo2](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@theo2](https://discuss.elastic.co/u/theo2)\
**Post date:** [August 17, 2023, 11:36am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/1 "2023-08-17T11:36:51Z")

</div>

Hello,

I have a cluster with 3 Elasticsearch on it, individually it works fine.  
But if I have an instance A connected, and I connect to instance B or C, I receive a SESSION\_EXPIRED timeout.  
I run kibana locally with docker, the same happens in chrome and firefox, they are each on separated ports (ES :9201 -\> KIB:5601 | ES :9202 -\> KIB: 5602 etc)  
Also, if I run A on chrome and B on firefox for example, it will work fine, but that's really inconvenient.

Kibana version match Elasticsearch's, being either 7.8.2 or 7.15.0

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [August 17, 2023, 12:05pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/2 "2023-08-17T12:05:39Z")

</div>

> [@theo2](#):
>
> I have a cluster with 3 Elasticsearch on it, individually it works fine.  
> But if I have an instance A connected, and I connect to instance B or C, I receive a SESSION\_EXPIRED timeout.

It sounds like you're using different session encryption keys for different Kibana instances. Check this doc out: [Use Kibana in a production environment | Kibana Guide [7.17] | Elastic](https://www.elastic.co/guide/en/kibana/7.17/production.html#load-balancing-kibana)

---

<div class="post-metadata">

**Author:** ![theo2](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@theo2](https://discuss.elastic.co/u/theo2)\
**Post date:** [August 17, 2023, 12:17pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/3 "2023-08-17T12:17:10Z")

</div>

Thank you for your reply,

I looked into it already, but how can it work separately then ? It is 3 different kibana dockers, each with their own ES, on 3 different ports, so I can quite figure out why it would matter that they do not share the same encryption keys

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [August 17, 2023, 12:36pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/4 "2023-08-17T12:36:47Z")

</div>

> [@theo2](#):
>
> It is 3 different kibana dockers, each with their own ES, on 3 different ports

Are you sure these 3 ES don't form a single cluster? Do you use different cluster names or ...?

---

<div class="post-metadata">

**Author:** ![theo2](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@theo2](https://discuss.elastic.co/u/theo2)\
**Post date:** [August 17, 2023, 12:39pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/5 "2023-08-17T12:39:49Z")

</div>

I am pretty sure, still new to ELK but I really don't think so, here are the infos of the the Elasticsearch :

Let's call this one A

```auto
{
  "name" : "logginges-master-0",
  "cluster_name" : "logginges",
  "cluster_uuid" : "redacted",
  "version" : {
    "number" : "7.15.0",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "redacted",
    "build_date" : "2021-09-16T03:05:29.143308416Z",
    "build_snapshot" : false,
    "lucene_version" : "8.9.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

this one B

```auto
{
  "name" : "datastore-master-1",
  "cluster_name" : "datastore",
  "cluster_uuid" : "redacted",
  "version" : {
    "number" : "7.10.2",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "redacted",
    "build_date" : "2021-01-13T00:42:12.435326Z",
    "build_snapshot" : false,
    "lucene_version" : "8.7.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

and this would be C

```auto
{
  "name" : "cdbes-master-0",
  "cluster_name" : "cdbes",
  "cluster_uuid" : "redacted",
  "version" : {
    "number" : "7.10.2",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "redacted",
    "build_date" : "2021-01-13T00:42:12.435326Z",
    "build_snapshot" : false,
    "lucene_version" : "8.7.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

---

<div class="post-metadata">

**Author:** ![theo2](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@theo2](https://discuss.elastic.co/u/theo2)\
**Post date:** [August 17, 2023, 12:51pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/6 "2023-08-17T12:51:02Z")

</div>

Also, they are all started off with a bash script.

The docker run goes like this :

> sudo docker run -d --rm --net=host --name loggingkibana -e SERVER\_PORT=$kibloggingeslocalport -e ELASTICSEARCH\_HOSTS=[http://localhost](http://localhost):$esloggingeslocalport -e ELASTICSEARCH\_USERNAME=${ELASTICSEARCH\_USERNAME} -e ELASTICSEARCH\_PASSWORD=${loggingespassword} [docker.io/elastic/kibana:$loggingesversion](http://docker.io/elastic/kibana:$loggingesversion)

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [August 17, 2023, 12:58pm UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/7 "2023-08-17T12:58:05Z")

</div>

Okay, good, thanks for confirming - these are all 3 different clusters. I think I know what's going on then.

You access all Kibana instances in the same browser using the same hostname (e.g. `localhost`) or IP address (e.g. `127.0.0.1`), but different ports (e.g. `5601`, `5602`), right? If so, check out this issue - [Kibana authentication troubleshooting guide · Issue #83914 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/83914#issue-747505065) and `Multi-tenancy using the same host name, but different ports` section specifically. Here's the excerpt:

> Per [RFC6265](https://tools.ietf.org/html/rfc6265) cookies for a given host are shared across all the ports on that host, even though the usual "same-origin policy" used by web browsers isolates content retrieved via different ports. That means that if you have multiple Kibana tenants (Kibana instances that use different `.kibana-x` indices) that are using the same host name, but different ports then the session cookies will be shared between them.

> This will lead to sporadic logouts if both tenants are opened in the same browsing context (same browser window) since if one tenant receives a session cookie that references to a session that lives in another tenant then the cookie will be treated as invalid and Kibana will clear it.

> The most correct solution is to never host different applications on the same hostname because of a cookie leak. If that's not possible then the workaround is to configure different session cookie names for every tenant with `xpack.security.cookieName` setting.

---

<div class="post-metadata">

**Author:** ![theo2](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@theo2](https://discuss.elastic.co/u/theo2)\
**Post date:** [August 18, 2023, 9:38am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/8 "2023-08-18T09:38:49Z")

</div>

It worked, so for anyone with the same issue, the best fix I could find is :

- Change your /etc/hosts config to declare another local adress with a custom name ie (`127.0.9.1 eslog`) and then connect to it in your browser ([http://eslog:5601/](http://eslog:5601/))

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [August 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/9 "2023-08-21T09:59:25Z")

</div>

Or, as the issue suggests, use different names for the session cookies.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2023, 9:59am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003/10 "2023-09-18T09:59:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
