# Using token to enrol kibana without a local browser

**URL:** <https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426>\
**Category:** Kibana\
**Created:** [April 14, 2022, 12:18pm UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426 "2022-04-14T12:18:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [April 14, 2022, 12:18pm UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/1 "2022-04-14T12:18:18Z")

</div>

Hi,

I have two virtual machines, one running Elasticsearch, one running kibana. I have generated a token to enrol kibana, but have been unable to apply it. I start kibana and can see the link generated to apply the token which is something like [http://localhost:5601?code=dsgfgds](http://localhost:5601?code=dsgfgds) .... but I don't have a local browser to load the link as I'm on a CLI-only VM.

Should kibana load when using the FQDN of the VM host? I think not as kibana isn't ready?

Is there another method of applying the token and enrolling kibana without the browser?

I have not used tokens to enrol kibana and nodes before, is it possible to configure Elasticsearch and Kibana without tokens as I did prior to 8.1?

Thanks.

---

<div class="post-metadata">

**Author:** ![grfneto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grfneto/32/125776_2.png) [@grfneto](https://discuss.elastic.co/u/grfneto)\
**Post date:** [April 14, 2022, 5:41pm UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/2 "2022-04-14T17:41:12Z")

</div>

Hi @gunlomboy

In Elastic Stack 8.x, security is enabled by default. If you want to configure your own security, it is possible, just do the manual process before installing it according to the guide:

> **[Set up basic security for the Elastic Stack | Elasticsearch Guide \[8.1\] |...](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/security-basic-setup.html)**

best regards

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [April 14, 2022, 9:52pm UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/3 "2022-04-14T21:52:54Z")

</div>

Many thanks @grfneto

It's good to know that we can still manually configure security, and that's probably what I will end up doing.

I would still be interested to know if there is a method to enrol kibana without a browser on the host machine. Having looked further, I can see that without completing the enrolment process the device is only listening locally on port 5601, which is no good if I don't have a local browser.

Surely, there's a command line option to enrol kibana?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 15, 2022, 4:22am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/4 "2022-04-15T04:22:57Z")

</div>

You can run

```auto
bin/kibana-setup --enrollment-token <your enrollment token here>

```

I don't think we do a good job documenting this, we will amend that.

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [April 16, 2022, 12:15am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/5 "2022-04-16T00:15:33Z")

</div>

Thanks @ikakavas

It worked like a charm 🙂

I agree regarding the documentation. Your advice is exactly what I was looking for but I couldn't find it anywhere.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 16, 2022, 6:16am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/6 "2022-04-16T06:16:36Z")

</div>

No worries, thanks for bringing this up. We have added the docs already in [[DOCS] Add detached mode for enrolling Kibana by lockewritesdocs · Pull Request #85933 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/85933) and you can see the updated instructions live in [Start the Elastic Stack with security enabled | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/configuring-stack-security.html#stack-start-with-security)

---

<div class="post-metadata">

**Author:** ![gunlomboy](https://avatars.discourse-cdn.com/v4/letter/g/c0e974/32.png) [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Post date:** [April 17, 2022, 6:53am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/7 "2022-04-17T06:53:02Z")

</div>

@ikakavas Perfect. Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2022, 6:53am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426/8 "2022-05-15T06:53:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
