You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助Search Guard认证的Kibana如何通过REST API连接?

Connecting to Kibana with Search Guard via REST API

Alright, let's break down how to connect to your Search Guard-protected Kibana instance via the REST API—there are a few reliable methods depending on your use case:

1. Basic Authentication (Most Common)

Search Guard typically enables HTTP Basic Auth by default for Kibana's API endpoints. This is the simplest approach for scripted or tool-based access.

To use it, include your Search Guard username and password in the request:

  • Using curl with direct credentials:
    curl -u "your-username:your-password" https://<kibana-host>:<kibana-port>/api/status
    
  • Alternatively, manually encode your credentials as Base64 and add the Authorization header:
    First, encode username:password (e.g., run echo -n "admin:admin" | base64 in your terminal), then use:
    curl -H "Authorization: Basic <base64-encoded-string>" https://<kibana-host>:5601/api/status
    

Notes for HTTPS: If your Kibana uses HTTPS (recommended for production), either ignore certificate validation for testing with -k, or specify your CA certificate for secure connections:

curl -u "admin:admin" --cacert /path/to/root-ca.pem https://<kibana-host>:5601/api/status

2. Search Guard API Keys

For a more secure, revocable alternative to static username/password pairs, use Search Guard's API key authentication:

Step 1: Create an API Key

First, generate an API key using a privileged user (like an admin):

curl -u "admin:admin" -X POST https://<kibana-host>:5601/_searchguard/api/v1/auth/keys/create \
  -H "Content-Type: application/json" \
  -d '{
    "username": "your-rest-user",
    "expiry": "30d",
    "metadata": {
      "description": "API key for automated REST access"
    }
  }'

The response will include an access_key and secret_key—save these securely, as they won't be displayed again.

Step 2: Use the API Key for Authentication

Treat the access_key as the username and secret_key as the password in a Basic Auth request:

curl -u "<access_key>:<secret_key>" https://<kibana-host>:5601/api/status

3. Session-Based Authentication (For Stateful Clients)

If you need to mimic a user's browser session (e.g., for longer-lived access without re-sending credentials), you can use session cookies:

curl -c cookies.txt -X POST https://<kibana-host>:5601/_searchguard/login \
  -H "Content-Type: application/json" \
  -d '{
    "username": "your-user",
    "password": "your-password"
  }'

The -c cookies.txt flag saves the session cookie to a file for reuse across subsequent requests.

curl -b cookies.txt https://<kibana-host>:5601/api/status

Keep in mind that sessions have an expiration time, so you'll need to re-authenticate periodically when the cookie expires.

Critical Considerations

  • Permissions: Ensure your user has the necessary Search Guard roles to access Kibana's API endpoints. At minimum, assign a role that includes kibana_user or custom permissions for paths like /api/*.
  • Auth Configuration: Check your kibana.yml to confirm that searchguard.auth.type includes basic or apiKey (these are enabled by default, but if you've configured SAML/OIDC, make sure you haven't disabled these methods).
  • Security Best Practices: Always use HTTPS in production to avoid transmitting credentials in plaintext. Rotate API keys regularly, and avoid hardcoding credentials in scripts.

内容的提问来源于stack exchange,提问作者Mgasmi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 06:46:50