# Xpack settings on ES, Logstash and Kibana

**URL:** <https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440>\
**Category:** Kibana\
**Created:** [May 3, 2018, 11:19am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440 "2018-05-03T11:19:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![maheshm](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@maheshm](https://discuss.elastic.co/u/maheshm)\
**Post date:** [May 3, 2018, 11:19am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/1 "2018-05-03T11:19:21Z")

</div>

Hi,

Does unpacking of X-Pack bundle overwrites the existing config files of installed ELK setup?

Thanks!

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 3, 2018, 1:15pm UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/2 "2018-05-03T13:15:37Z")

</div>

Hi,

X-Pack installation will not overwrite your `elasticsearch.yml`, `kibana.yml` or `logstash.yml` respectively. In the case of Elasticsearch, it will also create an `x-pack` directory within your `$ES_CONFIG_PATH` with some x-pack related config files.

Hope this answers your question.

---

<div class="post-metadata">

**Author:** ![maheshm](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@maheshm](https://discuss.elastic.co/u/maheshm)\
**Post date:** [May 7, 2018, 9:16am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/3 "2018-05-07T09:16:05Z")

</div>

Thanks Ioannis. However, I learnt from elastic documentation that all X-Pack features are enabled (by default). Please confirm.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/4485a62596d9e4e7625be110402c24f1f76acb0c.png)

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 7, 2018, 9:27am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/4 "2018-05-07T09:27:05Z")

</div>

Hi,

I am sorry but I'm not sure I understand how your two posts are connected or what the actual question is. X-Pack features are enabled by default and X-Pack installation doesn't overwrite your existing config files.

---

<div class="post-metadata">

**Author:** ![maheshm](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@maheshm](https://discuss.elastic.co/u/maheshm)\
**Post date:** [May 7, 2018, 9:58am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/5 "2018-05-07T09:58:20Z")

</div>

okay, sorry to bother you here. Do you mean the implementer has to configure the respective YML files that do not have all the x-pack parameters?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79ce3db97900c2aa554a9c2c777c11e1712cd27b.png)

and if we have to configure – the implementer has to go through documentation, copy paste the parameters and configure them. There are too many factors that can possibly go wrong during copy/paste or typing in, as YML looks for proper indentation. Is this the way to set the x-pack features working? (such as alerting - watcher configuration, security - user & roles setup).

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 7, 2018, 10:56am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/6 "2018-05-07T10:56:59Z")

</div>

> [@maheshm](#):
>
> okay, sorry to bother you here.

You're not bothering anyone of us @maheshm, apologies if it felt this way.

You don't have to explicitly set any of the settings to true. These are true by default as the documentation you posted in the screenshot above also suggests. You don't have to go through them one by one and enable them. These are assumed true, unless explicitly set to false.

Does my answer cover this part of your question?

---

<div class="post-metadata">

**Author:** ![maheshm](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@maheshm](https://discuss.elastic.co/u/maheshm)\
**Post date:** [May 7, 2018, 11:28am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/8 "2018-05-07T11:28:19Z")

</div>

Okay. Thanks for clarifying.

Cheers,  
Mahesh.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 11:28am UTC](https://discuss.elastic.co/t/xpack-settings-on-es-logstash-and-kibana/130440/9 "2018-06-04T11:28:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
