# The elasticsearch system user

**URL:** <https://discuss.elastic.co/t/the-elasticsearch-system-user/276629>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 22, 2021, 9:45am UTC](https://discuss.elastic.co/t/the-elasticsearch-system-user/276629 "2021-06-22T09:45:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alipujaistopo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alipujaistopo/32/50791_2.png) [@alipujaistopo](https://discuss.elastic.co/u/alipujaistopo)\
**Post date:** [June 22, 2021, 9:45am UTC](https://discuss.elastic.co/t/the-elasticsearch-system-user/276629/1 "2021-06-22T09:45:22Z")

</div>

hello everyone. is the elasticsearch's user has a password? if not is there any documentation about this?

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/baf32779b2b239052d070e2ddff8cdfc6b525e1c.png)

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 22, 2021, 1:06pm UTC](https://discuss.elastic.co/t/the-elasticsearch-system-user/276629/2 "2021-06-22T13:06:40Z")

</div>

It's common for Linux services to not have a Linux password. The nologin shell is specified in your example.

The passwords for elastic API users is set differently:

> **[Set up minimal security for Elasticsearch | Elasticsearch Guide \[7.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-minimal-setup.html#security-create-builtin-users)**

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 23, 2021, 1:53am UTC](https://discuss.elastic.co/t/the-elasticsearch-system-user/276629/3 "2021-06-23T01:53:44Z")

</div>

Please don't post pictures of text or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2021, 1:53am UTC](https://discuss.elastic.co/t/the-elasticsearch-system-user/276629/4 "2021-07-21T01:53:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
