# Sniffing Kibana data behind proxy

**URL:** <https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773>\
**Category:** Kibana\
**Created:** [March 15, 2017, 10:32pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773 "2017-03-15T22:32:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cuneyt](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cuneyt](https://discuss.elastic.co/u/cuneyt)\
**Post date:** [March 15, 2017, 10:32pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/1 "2017-03-15T22:32:16Z")

</div>

I have configured a reverse proxy for Kibana using NginX and a simple NodeJs script that restricts Kibana access with user/pass. It works as expected. Kibana is proxied through NodeJS script. But I would also like to sniff this flowing data. But for some reason I cannot read the HTML that is generated when I proxy Kibana. If I proxy a simple website I can see the code. I use the same code for both.

This is what I see when I proxy a simple web page:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d5c56d687fd6d6c2a1fd9394dbe7a28acc458dd3.png)

But when I proxy the Kibana I see a very weird encoding:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/4/243c431580d212d6fab4b0b1fa45aed95ac6c45f.png)

What I expect to see is some HTML code that's being sent to the client/browser, Is this an encoding issue? What kind of encoding does Kibana use? Or is it because the data is encrypted? Is it possible to read this?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 16, 2017, 12:09pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/2 "2017-03-16T12:09:25Z")

</div>

@cuneyt do you have Kibana itself running over http or https? If you try to access Kibana directly without going through your proxy, you should be able to determine whether it's http or https.

---

<div class="post-metadata">

**Author:** ![cuneyt](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cuneyt](https://discuss.elastic.co/u/cuneyt)\
**Post date:** [March 16, 2017, 9:01pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/3 "2017-03-16T21:01:58Z")

</div>

Hi Brandon. I do the direct access using an address like [http://54.89.89.xxx:5601](http://54.89.89.xxx:5601) So it seems to be http. The thing I normally close port 5601 to direct access for the production environment. So I make sure that requests only go thru an authentication app.

The code is pretty simple. 5601 port is closed to access from outside. All kibana routes are directed to this nodejs app. It uses the http-proxy and a middleware function that sniffs the code. If I change "localhost:5601" to anything like "[google.com](http://google.com)", "[yahoo.com](http://yahoo.com)" I can actually see the generated HTML code of that websites. But for kibana website all I see is this weird encoding. So I think it's a Kibana question rather than a NodeJs question.

```
var transformerFunction = function (data, req, res) {
  console.log(data.toString('ascii'));
  return data;
};

var apiProxy = require('http-proxy').createProxyServer();

app.all("/ui/|/api/|/es_admin/|/elasticsearch/|/app/|/bundles/|/kibana|/kibana5|/status|/plugins", require('transformer-proxy')(transformerFunction), function(req, res) {
          apiProxy.web(req, res, { target: 'http://localhost:5601' });
    });
```

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 17, 2017, 1:12pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/4 "2017-03-17T13:12:11Z")

</div>

@cuneyt You probably want to be inspecting the response headers, as the Content-Type is `text/html; charset=UTF-8` so your `.toString('ascii')` isn't going to work.

---

<div class="post-metadata">

**Author:** ![cuneyt](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cuneyt](https://discuss.elastic.co/u/cuneyt)\
**Post date:** [March 19, 2017, 10:09pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/5 "2017-03-19T22:09:00Z")

</div>

Hi Thanks Brandon but I tried all possible encodings including all below but still the same ☹

ascii  
base64  
binary  
hex  
ucs2/ucs-2/utf16le/utf-16le  
utf8/utf-8

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [March 20, 2017, 2:24pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/6 "2017-03-20T14:24:09Z")

</div>

@cuneyt if the browser supports it, we're also using gzip to compress the data, it can be decompressed using something similar to the following

```auto
zlib.gunzip(data, function (err, result) {
    console.log(result.toString('utf8'));
});

```

The response headers should be used to determine whether it's gzipped and the encoding, as this can vary based on the request headers that the browser sets.

---

<div class="post-metadata">

**Author:** ![cuneyt](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@cuneyt](https://discuss.elastic.co/u/cuneyt)\
**Post date:** [March 20, 2017, 9:12pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/7 "2017-03-20T21:12:32Z")

</div>

Thanks Brandon. Decompression! That is the solution. It works! Thanks many times.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2017, 9:12pm UTC](https://discuss.elastic.co/t/sniffing-kibana-data-behind-proxy/78773/8 "2017-04-17T21:12:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
