# Simple way to deploy Elastic Security

**URL:** <https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910>\
**Category:** Elastic Security\
**Tags:** docker\
**Created:** [July 28, 2021, 8:28pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910 "2021-07-28T20:28:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lisa99](https://avatars.discourse-cdn.com/v4/letter/l/a88e4f/32.png) [@lisa99](https://discuss.elastic.co/u/lisa99)\
**Post date:** [July 28, 2021, 8:28pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910/1 "2021-07-28T20:28:18Z")

</div>

I am trying to install the Elastic Stack locally on a single VM to keep the setup simple.

The use case is Security, which requires installing ELK as well as many configurations here and there to enable features like Elastic Agent (like security / tls / user roles) .

Although the documentation does cover the steps, I am finding it tedious to get the configuration right. I was wondering if other installation options are there, like pre-made Virtual Machine, docker, or install scripts that automate the deployment and especially the configurations required for a functional Elastic Security ?

P.S : I know that cloud provides the simplicity I am looking for, but unfortunately I am bound to deploy Elastic Security locally.

---

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [July 29, 2021, 5:45pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910/2 "2021-07-29T17:45:51Z")

</div>

Hi @lisa99, welcome to the forum!

Elastic has official Docker images for the parts of the Stack, I'd check them out:

- [GitHub - elastic/dockerfiles: Dockerfiles for the official Elastic Stack images](https://github.com/elastic/dockerfiles)
- [Install Elasticsearch with Docker | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html)
- [Install Kibana with Docker | Kibana Guide [7.13] | Elastic](https://www.elastic.co/guide/en/kibana/current/docker.html)

If you need to override default config files, and there's a lot of configuration, one option would be to build your own Dockerfiles on top of the official ones.

For a simple local setup, I'd personally use docker-compose and include both Elasticsearch and Kibana instances there. You can even build a multi-node ES and KIbana cluster that way, where all the nodes would still work on the same machine.

If you are familiar with Kubernetes or need a more advanced setup, another option would be to spin up Elastic Stack in a K8s cluster. Elastic has Helm charts, seems like not every component of the Stack is there, but still:

- [GitHub - elastic/helm-charts: You know, for Kubernetes](https://github.com/elastic/helm-charts)

For even more fancy deployments there's an option to use Elastic Cloud on Kubernetes:

- [GitHub - elastic/cloud-on-k8s: Elastic Cloud on Kubernetes](https://github.com/elastic/cloud-on-k8s)
- [Overview | Elastic Cloud on Kubernetes [1.6] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/1.6/k8s-overview.html)

As for configuring your data sources like Elastic Agent and Endpoint Security, probably the easiest way would be to do it via Fleet (your Agents should be enrolled in your Fleet, so you could have a centralised control over them from Kibana):

- [Fleet | Kibana Guide [7.13] | Elastic](https://www.elastic.co/guide/en/kibana/current/fleet.html)
- [Fleet and Elastic Agent overview | Fleet User Guide [7.13] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)
- [Configure and install the Elastic Endpoint integration | Elastic Security Solution [7.13] | Elastic](https://www.elastic.co/guide/en/security/7.13/install-endpoint.html)

Elastic Security app requires some configuration to be done upfront for production environments, make sure to read this documentation:

- [Get started with Elastic Security | Elastic Security Solution [7.13] | Elastic](https://www.elastic.co/guide/en/security/7.13/getting-started.html)
- for example, detection rules require some index-level privileges to be granted [Detections prerequisites and requirements | Elastic Security Solution [7.13] | Elastic](https://www.elastic.co/guide/en/security/7.13/detections-permissions-section.html)

Sorry, at this point we don't have any automation of the things specifically required by Elastic Security.

For a simple local setup you could log in as a superuser (make sure to give your user the role named `superuser`) and expect most of the functionality working.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 29, 2021, 8:51pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910/3 "2021-07-29T20:51:57Z")

</div>

Hi @lisa99 Welcome to the Community

I have a Quick How To for a Secure Elastic Stack on a Single VM you can take a look it it [here](https://github.com/bvader/howtos/tree/master/basic-security-elasticsearch) btw `bvader` thats me.

I did for just such a case (POC, Initial Look) etc.

---

<div class="post-metadata">

**Author:** ![georgii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/georgii/32/78076_2.png) [@georgii](https://discuss.elastic.co/u/georgii)\
**Post date:** [July 29, 2021, 10:01pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910/4 "2021-07-29T22:01:18Z")

</div>

@stephenb this is awesome! Thank you for sharing this guide!

@lisa99 let us know if this helps you. I know it may be a little bit frustrating to not having a simple one-click deploy-everything solution, but hopefully we'll get there at some point in the future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 26, 2021, 10:01pm UTC](https://discuss.elastic.co/t/simple-way-to-deploy-elastic-security/279910/5 "2021-08-26T22:01:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
