# \#elastic-stack-security

**URL:** https://discuss.elastic.co/tag/elastic-stack-security/8.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [SAN required in cert?](https://discuss.elastic.co/t/san-required-in-cert/390541)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 7:06pm UTC](https://discuss.elastic.co/t/san-required-in-cert/390541 "2026-09-20T19:06:49Z")

</div>

I am trying to use an ES service from a remote machine, using the cert copied from the container: podman cp app:/usr/share/elasticsearch/config/certs But simply doing a client.info() I am getting a elastic\_transport.Co…

---

## [Security labs documentation via API call - ignoreSecurityLabs](https://discuss.elastic.co/t/security-labs-documentation-via-api-call-ignoresecuritylabs/389948)

<div class="topic-metadata">

**Author:** [@novst](https://discuss.elastic.co/u/novst)\
**Replies:** 2\
**Last updated:** [September 3, 2026, 2:25pm UTC](https://discuss.elastic.co/t/security-labs-documentation-via-api-call-ignoresecuritylabs/389948 "2026-09-03T14:25:11Z")

</div>

Hello, I am trying to automate installation for the customer and I want to install "Elastic documentation" and "Security labs" under http://localhost:5601/app/management/ai/genAiSettings According to documentation Crea…

---

## [Elastic Defend Endpoint Protection Complete message](https://discuss.elastic.co/t/elastic-defend-endpoint-protection-complete-message/389934)

<div class="topic-metadata">

**Author:** [@jpedersm](https://discuss.elastic.co/u/jpedersm)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 2:48pm UTC](https://discuss.elastic.co/t/elastic-defend-endpoint-protection-complete-message/389934 "2026-08-26T14:48:20Z")

</div>

In a lab, I am trying to make a switch on the settings in Elastic Defend. The default is set to protect and notify on items from Malware to ransomware. When changing the settings from Protect to Detect and disabling no…

---

## [ES, kibana both having ca.crt issues?](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 12\
**Last updated:** [August 21, 2026, 10:13am UTC](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738 "2026-08-21T10:13:56Z")

</div>

I'm not able to start up either the ES or kibana containers and I suspect the root cause has to do with ca-cert issues. i'm attaching my compose file below for reference with ES, the log shows this error: "@timestamp"…

---

## [Recommended Resources](https://discuss.elastic.co/t/recommended-resources/389231)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar8](https://discuss.elastic.co/u/Rahul_Kumar8)\
**Replies:** 1\
**Last updated:** [August 18, 2026, 7:45am UTC](https://discuss.elastic.co/t/recommended-resources/389231 "2026-08-18T07:45:29Z")

</div>

I could not find any public documentation stating recommended resources for my kibana, elastic and logstash. What would the resource guide be if i had 100GB/day logs ?

---

## [Ubuntu 26.04 LTS Support Timeline — Open Source Elasticsearch 8.19.19](https://discuss.elastic.co/t/ubuntu-26-04-lts-support-timeline-open-source-elasticsearch-8-19-19/388964)

<div class="topic-metadata">

**Author:** [@Rex\_Rajat](https://discuss.elastic.co/u/Rex_Rajat)\
**Replies:** 2\
**Last updated:** [August 5, 2026, 7:25am UTC](https://discuss.elastic.co/t/ubuntu-26-04-lts-support-timeline-open-source-elasticsearch-8-19-19/388964 "2026-08-05T07:25:25Z")

</div>

Hi Elastic team, We run open-source Elasticsearch (self-managed) on Ubuntu 24.04 LTS and are evaluating a move to Ubuntu 26.04 LTS. The official Support Matrix doesn't yet list 26.04. Could you share: Expected timelin…

---

## [Elastic for MSSP: What is the impact of a new space on kibana?](https://discuss.elastic.co/t/elastic-for-mssp-what-is-the-impact-of-a-new-space-on-kibana/388732)

<div class="topic-metadata">

**Author:** [@ArgoAdvisory](https://discuss.elastic.co/u/ArgoAdvisory)\
**Replies:** 4\
**Last updated:** [July 24, 2026, 4:39pm UTC](https://discuss.elastic.co/t/elastic-for-mssp-what-is-the-impact-of-a-new-space-on-kibana/388732 "2026-07-24T16:39:53Z")

</div>

Hello! Our main goal: As an MSSP, we want to create a multi-tenant subdivision for our customers. Each customer has an internal IT team who wants access to their Elastic Security Space. Useful information: Elastic …

---

## [Security update ESA-2026-08](https://discuss.elastic.co/t/security-update-esa-2026-08/388361)

<div class="topic-metadata">

**Author:** [@Peter\_Misovic](https://discuss.elastic.co/u/Peter_Misovic)\
**Replies:** 1\
**Last updated:** [July 15, 2026, 12:36pm UTC](https://discuss.elastic.co/t/security-update-esa-2026-08/388361 "2026-07-15T12:36:46Z")

</div>

Hello, please, I currently have ELK v 9.2.2, Kibana 8.19.10, 9.1.10, 9.2.4 Security Update (ESA-2026-08) says "The issue is resolved in version 8.19.10, 9.1.10, 9.2.4.", please, what about 9.4.2 or 9.4.3? Shall I upgra…

---

## [Elastic Agent Go update to v0.52.0](https://discuss.elastic.co/t/elastic-agent-go-update-to-v0-52-0/388334)

<div class="topic-metadata">

**Author:** [@rdmorris1914](https://discuss.elastic.co/u/rdmorris1914)\
**Replies:** 0\
**Last updated:** [July 14, 2026, 2:59pm UTC](https://discuss.elastic.co/t/elastic-agent-go-update-to-v0-52-0/388334 "2026-07-14T14:59:05Z")

</div>

There are several CVE's covered in the May 22 release of Go v0.52.0 which are not covered in the latest agent. When will Go be updated? The following CVEs are all present in the Linux Agent 9.4.3: CVE-2026-46595 CVE-20…

---

## [RBAC - Manage spaces - how to disable it?](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881)

<div class="topic-metadata">

**Author:** [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Replies:** 6\
**Last updated:** [July 2, 2026, 7:26am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881 "2026-07-02T07:26:56Z")

</div>

In elastic stack 9.4 we want to disable /enable "Manage spaces" functionality. I found only this in the documentation: "An example of a built-in role is kibana\_admin. Assigning this role to your users will grant access…

---

## [False Positive Report — 4K\_Render\_Automation.exe — Malicious (high Confidence)](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586)

<div class="topic-metadata">

**Author:** [@Qu\_c\_Chau](https://discuss.elastic.co/u/Qu_c_Chau)\
**Replies:** 4\
**Last updated:** [June 4, 2026, 2:23pm UTC](https://discuss.elastic.co/t/false-positive-report-4k-render-automation-exe-malicious-high-confidence/386586 "2026-06-04T14:23:14Z")

</div>

Reporting a false positive for Elastic's malware detection engine. File: 4K\_Render\_Automation.exe SHA256: 8e8ab81e34a69221ff50b5b94f033cc31969cc39214efd0346f06a48957b991f Detection: Malicious (high Confidence) VT lin…

---

## [Kaspersky Logs for SOC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695)

<div class="topic-metadata">

**Author:** [@breno.bazaga](https://discuss.elastic.co/u/breno.bazaga)\
**Replies:** 0\
**Last updated:** [June 3, 2026, 1:49pm UTC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695 "2026-06-03T13:49:51Z")

</div>

Hello everyone, I currently work in a SOC environment and I am working on a use case involving monitoring and ingestion of Kaspersky logs into Elastic for managed security services. During the integration process, I no…

---

## [Elastic POC Sizing & Architecture](https://discuss.elastic.co/t/elastic-poc-sizing-architecture/386669)

<div class="topic-metadata">

**Author:** [@Sharmon](https://discuss.elastic.co/u/Sharmon)\
**Replies:** 0\
**Last updated:** [June 3, 2026, 3:58am UTC](https://discuss.elastic.co/t/elastic-poc-sizing-architecture/386669 "2026-06-03T03:58:56Z")

</div>

Hello Everyone, I recently joined in a Distributor for elastic and now we have to do POC, I am fairly new to Elastic and my main concern is if we have an estimated ingest of around 400 GB/Day how do we design the archi…

---

## [Kibana shows 500-Internal Server Error after upgrade from 9.3.1 to 9.4.1 when security is turend off](https://discuss.elastic.co/t/kibana-shows-500-internal-server-error-after-upgrade-from-9-3-1-to-9-4-1-when-security-is-turend-off/386504)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 1\
**Last updated:** [May 26, 2026, 2:53pm UTC](https://discuss.elastic.co/t/kibana-shows-500-internal-server-error-after-upgrade-from-9-3-1-to-9-4-1-when-security-is-turend-off/386504 "2026-05-26T14:53:46Z")

</div>

We have deployed Elasticsearch and Kibana on an internal network. The elasticsearch cluster has security and ML disabled xpack.security.enabled: false xpack.security.transport.ssl.enabled: false xpack.security.http.ssl.…

---

## [Some prebuilt security rules have missing fields](https://discuss.elastic.co/t/some-prebuilt-security-rules-have-missing-fields/386132)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 1\
**Last updated:** [May 3, 2026, 1:54pm UTC](https://discuss.elastic.co/t/some-prebuilt-security-rules-have-missing-fields/386132 "2026-05-03T13:54:18Z")

</div>

As the title suggests, some prebuilt security rules are failing due to some fields not being present in the Elastic Defend telemetry. From this example, the rule logic has process.command\_line , However, the file teleme…

---

## [Elastic - ESET AV integration](https://discuss.elastic.co/t/elastic-eset-av-integration/385971)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 12:25pm UTC](https://discuss.elastic.co/t/elastic-eset-av-integration/385971 "2026-04-22T12:25:04Z")

</div>

Good afternoon! Please tell me if anyone has configured the integration of ESET AntiVirus with ELASTIC. I deployed a Linux-based syslog server, specified the address and port 514 or 6514 in ESET, but there are no logs, …

---

## [Setting up self managed ELK stack with TLS/HTTPS issue](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102)

<div class="topic-metadata">

**Author:** [@BenNCSU](https://discuss.elastic.co/u/BenNCSU)\
**Replies:** 11\
**Last updated:** [March 5, 2026, 2:16am UTC](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102 "2026-03-05T02:16:44Z")

</div>

I’m trying to set up an ELK stack for SIEM doing a standard install. I installed Elasticsearch and Kibana, which worked fine using HTTP, but when I tried to set up TLS using a self-signed certificate from our CA, I can’…

---

## [Question about certificates and auto-generating configuration](https://discuss.elastic.co/t/question-about-certificates-and-auto-generating-configuration/385318)

<div class="topic-metadata">

**Author:** [@hairless\_mess](https://discuss.elastic.co/u/hairless_mess)\
**Replies:** 0\
**Last updated:** [March 3, 2026, 9:59am UTC](https://discuss.elastic.co/t/question-about-certificates-and-auto-generating-configuration/385318 "2026-03-03T09:59:36Z")

</div>

Hello everyone! I have some questions regarding the certificates used when deploying elasticsearch. Elasticsearch auto generates certificates for http and transport which work out of the box, however from my understand…

---

## [Elasticsearch classic plugin: problem with entitlements](https://discuss.elastic.co/t/elasticsearch-classic-plugin-problem-with-entitlements/385137)

<div class="topic-metadata">

**Author:** [@Peter\_van\_der\_Weerd](https://discuss.elastic.co/u/Peter_van_der_Weerd)\
**Replies:** 1\
**Last updated:** [February 20, 2026, 3:55pm UTC](https://discuss.elastic.co/t/elasticsearch-classic-plugin-problem-with-entitlements/385137 "2026-02-20T15:55:33Z")

</div>

I’m writing a classic plugin for a custom similarity. ES9.0.1. The plugin tries to load resources from its own jar: Enumeration\<java.net.URL\> resources = Utils.class.getClassLoader().getResources("META-INF/MANIFEST.MF"…

---

## [Kibana Instance Crashing During PDF/CSV Export on Elastic Cloud](https://discuss.elastic.co/t/kibana-instance-crashing-during-pdf-csv-export-on-elastic-cloud/384990)

<div class="topic-metadata">

**Author:** [@Hichem\_Blagui](https://discuss.elastic.co/u/Hichem_Blagui)\
**Replies:** 4\
**Last updated:** [February 12, 2026, 2:07pm UTC](https://discuss.elastic.co/t/kibana-instance-crashing-during-pdf-csv-export-on-elastic-cloud/384990 "2026-02-12T14:07:28Z")

</div>

Hi, I am experiencing frequent instance crashes when attempting to export default dashboards (PDF/PNG/CSV) from Kibana. I am currently using Elastic Cloud and do not have access to the underlying terminal or the physica…

---

## [Failed to check if maintenance windows are active](https://discuss.elastic.co/t/failed-to-check-if-maintenance-windows-are-active/384984)

<div class="topic-metadata">

**Author:** [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Replies:** 6\
**Last updated:** [February 11, 2026, 12:15pm UTC](https://discuss.elastic.co/t/failed-to-check-if-maintenance-windows-are-active/384984 "2026-02-11T12:15:26Z")

</div>

After the update of the on-premises deployment, this error appears. What could be the root cause?

---

## [Vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881)

<div class="topic-metadata">

**Author:** [@Ravinder07Sharma](https://discuss.elastic.co/u/Ravinder07Sharma)\
**Replies:** 1\
**Last updated:** [February 9, 2026, 10:09am UTC](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881 "2026-02-09T10:09:04Z")

</div>

we are running Elasticsearch-8.17.10 on 6 RHEL 8 servers. But we are getting vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server. log4j vulnera…

---

## [SentinelOne Integration with ELK](https://discuss.elastic.co/t/sentinelone-integration-with-elk/384924)

<div class="topic-metadata">

**Author:** [@Jayesh\_Auti](https://discuss.elastic.co/u/Jayesh_Auti)\
**Replies:** 4\
**Last updated:** [February 5, 2026, 1:22pm UTC](https://discuss.elastic.co/t/sentinelone-integration-with-elk/384924 "2026-02-05T13:22:13Z")

</div>

Hi Guys, I am integrating SentinelOne with ELK, after adding console URL and API key it showing me to add elastic agent. Elastic agent is required for these type of integrations? Can anyone help me with this? Than…

---

## [Upgrade from 8.19.1 to 9.2.3 failed because of .security-7 index](https://discuss.elastic.co/t/upgrade-from-8-19-1-to-9-2-3-failed-because-of-security-7-index/384755)

<div class="topic-metadata">

**Author:** [@Balait4](https://discuss.elastic.co/u/Balait4)\
**Replies:** 5\
**Last updated:** [January 29, 2026, 1:48pm UTC](https://discuss.elastic.co/t/upgrade-from-8-19-1-to-9-2-3-failed-because-of-security-7-index/384755 "2026-01-29T13:48:42Z")

</div>

Hi, I upgrade the cluster from 7.16.1 to 8.19.1 as per the upgrade guide. The kibana ugprade assistant did’t report anything. Now I’m upgrading to version 9.2.3 where getting the below issue for security index. The inde…

---

## [Kibana “Managed API keys” can be hidden/misclassified by editing metadata.managed (UI + Dev Tools)](https://discuss.elastic.co/t/kibana-managed-api-keys-can-be-hidden-misclassified-by-editing-metadata-managed-ui-dev-tools/384407)

<div class="topic-metadata">

**Author:** [@Bolto](https://discuss.elastic.co/u/Bolto)\
**Replies:** 0\
**Last updated:** [January 7, 2026, 10:47am UTC](https://discuss.elastic.co/t/kibana-managed-api-keys-can-be-hidden-misclassified-by-editing-metadata-managed-ui-dev-tools/384407 "2026-01-07T10:47:20Z")

</div>

Hi Elastic team/community, While reviewing API Keys in Kibana, I noticed that the flag used to identify Managed API keys (created/used by Kibana background tasks) can be overwritten by a user by editing the API key meta…

---

## [Elastic Agent (Defender) – Public + On-Prem Deployment Question](https://discuss.elastic.co/t/elastic-agent-defender-public-on-prem-deployment-question/383515)

<div class="topic-metadata">

**Author:** [@Animate4498](https://discuss.elastic.co/u/Animate4498)\
**Replies:** 8\
**Last updated:** [January 5, 2026, 1:08pm UTC](https://discuss.elastic.co/t/elastic-agent-defender-public-on-prem-deployment-question/383515 "2026-01-05T13:08:11Z")

</div>

My goal is to deploy the Elastic Agent with the Defender integration as an XDR solution on our clients and forward all security alerts to our on-prem SIEM. Fleet and the rest of the Elastic components are reachable from …

---

## [API key does or does not rely on permissions from user that created it](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 14\
**Last updated:** [December 31, 2025, 10:08pm UTC](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663 "2025-12-31T22:08:43Z")

</div>

We had previously been creating API keys with our SSO user accounts. Then we found that after an SSO IdP provider change our users were effectively “different” such that we could no longer edit API keys (e.g. to add or r…

---

## [Forming an Elasticsearch cluster](https://discuss.elastic.co/t/forming-an-elasticsearch-cluster/384041)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [December 16, 2025, 7:57am UTC](https://discuss.elastic.co/t/forming-an-elasticsearch-cluster/384041 "2025-12-16T07:57:43Z")

</div>

Hello, I’m trying to add a second node to my ES cluster but I’m facing issues with SSL handshake. \[2025-12-14T15:38:54,881\]\[WARN \]\[o.e.t.TcpTransport \] \[SCPRLUWS05\] exception caught on transport layer \[Netty4TcpC…

---

## [My Status of Fleet Agent doesn't change from Updating to Heathy](https://discuss.elastic.co/t/my-status-of-fleet-agent-doesnt-change-from-updating-to-heathy/384003)

<div class="topic-metadata">

**Author:** [@duy270101](https://discuss.elastic.co/u/duy270101)\
**Replies:** 1\
**Last updated:** [December 12, 2025, 6:47am UTC](https://discuss.elastic.co/t/my-status-of-fleet-agent-doesnt-change-from-updating-to-heathy/384003 "2025-12-12T06:47:11Z")

</div>

My case. I set up for may lab. Please help me. Status don't change to Heathy. when install i added –insecure -f in the tail of command.

---

## [Is second wave of Shai-Hulud attack impacting Elastic Stack?](https://discuss.elastic.co/t/is-second-wave-of-shai-hulud-attack-impacting-elastic-stack/383724)

<div class="topic-metadata">

**Author:** [@hkw2pg1](https://discuss.elastic.co/u/hkw2pg1)\
**Replies:** 1\
**Last updated:** [December 1, 2025, 5:00pm UTC](https://discuss.elastic.co/t/is-second-wave-of-shai-hulud-attack-impacting-elastic-stack/383724 "2025-12-01T17:00:18Z")

</div>

The Shai-Hulud attack came back again with approximately 800 npm packages impacted. To which extend is this article still stand? → Navigating the Shai-Hulud worm: Elastic's proactive defense against npm supply chain com…

[Next page](https://discuss.elastic.co/tag/elastic-stack-security/8.md?match_all_tags=true&page=1&tags%5B%5D=elastic-stack-security)
