# Connect external Kibana to AWS Elasticsearch service

**URL:** <https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262>\
**Category:** Security\
**Created:** [February 22, 2020, 4:16pm UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262 "2020-02-22T16:16:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ahashem](https://avatars.discourse-cdn.com/v4/letter/a/58f4c7/32.png) [@ahashem](https://forum.opensearch.org/u/ahashem)\
**Post date:** [February 22, 2020, 4:16pm UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262/1 "2020-02-22T16:16:49Z")

</div>

Hi,

I appreciate OpenDistro for ES and the huge effort put into it.

I was glad to see that AWS Elasticsearch service now includes the security plugin starting Feb 11, so I started a test cluster with fine grain security and everything is really smooth.

Kibana that comes with AWS ES service is working fine, however, I’m trying to connect my own Kibana instance to AWS ES service. I have everything in place, but I don’t know what’s the equivalent for kibanaserver user for AWS ES service?

I tried pulling the security config by calling /\_opendistro/\_security/api/securityconfig from the working Kibana that comes with AWS ES, and it shows that kibana server\_username is AmazonESKibanaServerUser. I couldn’t find a way to get that user’s password to have my external Kibana up and running.

Any thoughts on that?

Thanks

---

<div class="post-metadata">

**Author:** ![greg](https://avatars.discourse-cdn.com/v4/letter/g/71c47a/32.png) [@greg](https://forum.opensearch.org/u/greg)\
**Post date:** [July 21, 2020, 3:48pm UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262/2 "2020-07-21T15:48:06Z")

</div>

This is the exact configuration I’m trying for. I am able to get the external Kibana to authenticate, and startup with authentication by setting these properties in kibana.yml

- elasticsearch.hosts: [“[https://vpc-blah-aosnasoiansoasi.us-east-1.es.amazonaws.com:443](https://vpc-blah-aosnasoiansoasi.us-east-1.es.amazonaws.com:443)”]

(This comes from your Amazon ES management dashboard) Also create a user in your internal user database in the Amazon ES Kibana, under the padlock icon.

- elasticsearch.username
- elasticsearch.password

Here’s my setup and goals:

1. I have a managed Amazon ES cluster up, with its own managed Kibana. It can’t run custom plugins, such as LogTrail, and neither can Amazon ES run XPack components like Logs (local app with real-time log updates)

2. I want to run my own Kibana (“Kibana2”) on an EC2 instance, and I am, and it authenticates. When I click ANYWHERE around in the app after its is up and green, I get:

> Blockquote  
> error [15:20:49.668] Error: Authentication Exception

```
at respond (/home/ec2-user/work/kibana-7.4.2-linux-x86_64/node_modules/elasticsearch/src/lib/transport.js:349:15)

at checkRespForFailure (/home/ec2-user/work/kibana-7.4.2-linux-x86_64/node_modules/elasticsearch/src/lib/transport.js:306:7)

at HttpConnector.<anonymous> (/home/ec2-user/work/kibana-7.4.2-linux-x86_64/node_modules/elasticsearch/src/lib/connectors/http.js:173:7)

at IncomingMessage.wrapper (/home/ec2-user/work/kibana-7.4.2-linux-x86_64/node_modules/elasticsearch/node_modules/lodash/lodash.js:4929:19)

at IncomingMessage.emit (events.js:194:15)

at endReadableNT (_stream_readable.js:1103:12)

at process._tickCallback (internal/process/next_tick.js:63:19)

```

Frustrations:

- It looks like the Kibana2 needs a PEM for SSL communications to the server (kibana.yml server.ssl.certificate)
- Amazon won’t let you generate an API token (“not allowed”)
- Amazon DOES let you set a custom key (KMS) for at-rest encryption, but Amazon DOES NOT let you “get into the server and generate a PEM and set it in there” like a random Apache etc…

Thanks in advance for any help on this. It seems like a good pattern, but, I’m wondering if I’m stepping on some “Amazon Only” configuration issue.

G.

---

<div class="post-metadata">

**Author:** ![lorenzo95](https://avatars.discourse-cdn.com/v4/letter/l/c57346/32.png) [@lorenzo95](https://forum.opensearch.org/u/lorenzo95)\
**Post date:** [November 19, 2020, 7:09pm UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262/3 "2020-11-19T19:09:10Z")

</div>

Hello, sorry for the late reply. I was thinking of trying the same setup due to plugins(wazuh) as well.  
Instead of getting a cert for kibana, can you get your hands on the root cert? That way you could use this in your kibana.yml

```
elasticsearch.ssl.verificationMode: full
elasticsearch.ssl.certificateAuthorities: ["path to ca.pem"]

```

if not, did you try  
`elasticsearch.ssl.verificationMode: none`

and see if it works?

Thank you,  
Gera

---

<div class="post-metadata">

**Author:** ![dtakis](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@dtakis](https://forum.opensearch.org/u/dtakis)\
**Post date:** [January 6, 2021, 1:31am UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262/4 "2021-01-06T01:31:30Z")

</div>

@lorenzo95 @greg  
I had the same scenario and noticed that with `elasticsearch.ssl.verificationMode: none`  
I have in my external kibana the following plugin failing and yellow state:  
[plugin:opendistro\_security@1.9.0.0](mailto:plugin:opendistro_security@1.9.0.0) Tenant indices migration failed

```
log [00:22:32.348] [info][OpenDistro Security Migration] Starting tenant migration
 error [00:22:32.371] [error][migration] AuthenticationError:
    at wrapElasticsearchError (/home/ubuntu/opendistroforelasticsearch-kibana/plugins/opendistro_security/lib/backend/errors/wrap_elasticsearch_error.js:36:12)
    at SecurityBackend.getTenantInfoWithInternalUser (/home/ubuntu/opendistroforelasticsearch-kibana/plugins/opendistro_security/lib/backend/opendistro_security.js:259:19)
    at process._tickCallback (internal/process/next_tick.js:68:7)
  log [00:22:32.393] [info][status][plugin:opendistro_security@1.9.0.0] Status changed from yellow to yellow - Tenant indices migration failed

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![dtakis](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@dtakis](https://forum.opensearch.org/u/dtakis)\
**Post date:** [January 7, 2021, 1:40am UTC](https://forum.opensearch.org/t/connect-external-kibana-to-aws-elasticsearch-service/2262/5 "2021-01-07T01:40:15Z")

</div>

Just to add: using Kibana Open Distro 1.9.0 on AWS Elasticsearch Open Distro 7.8
