Elastic Kibana 8 Security
Introduction
This guide tells you how to authenticate the Elastic Kibana 8 - Security connector in Swimlane using one of the supported authentication methods.
You will configure Elastic API access, collect the required credentials, and configure the connector asset in Swimlane.
Prerequisites
Elastic Access Requirements
You must have administrative access in Elastic to:
- Access the Kibana Security API endpoint
- Generate API keys (Elastic Cloud or self-managed)
- Create or manage users with appropriate roles
- Assign permissions for Cases, Detections, Timelines, and Endpoint actions
Required Credentials
During setup, you will collect one of the following credential sets depending on the authentication method used:
API Key Authentication (Elastic Cloud or Self-Managed)
- Kibana URL
- Elastic API Key
HTTP Basic Authentication (On-Premises / Self-Managed)
- Kibana URL
- Username
- Password
Authentication Methods Overview
The Elastic Kibana 8 β Security connector supports the following authentication methods:
- API Key Authentication (recommended for Elastic Cloud)
- HTTP Basic Authentication (commonly used for on-prem deployments)
Elastic Setup
Elastic authentication steps differ slightly depending on whether you are connecting to Elastic Cloud or an On-Premises Kibana deployment.
Generating an API Key (Elastic Cloud / API Key Authentication)
Take the following steps to generate an API Key in Kibana:
- Log in to Kibana with an administrator account.
- Open the main menu and navigate to: Stack Management β Security β API Keys
- Click Create API key.
- Provide the following:
- Key name (example: Swimlane-Turbine-Connector)
- Expiration (optional)
- Role privileges (must include Security access)
- Click Create API key.
- Copy the generated key immediately.
Elastic Cloud API Key Formatting Requirement
If your API key was generated from within the Elastic Cloud portal, you may need to reformat it before using it in Swimlane.
Run the following command to decode the key:
echo "BASE64_VALUE==" | base64 -d
This produces a value similar to:
id:api_key_secret
Then encode it again:
echo -n "id:api_key_secret" | base64
This final encoded value is the correct API Key format required for Swimlane.
Creating a User for Basic Authentication (On-Premises)
Take the following steps if using HTTP Basic Authentication:
- Log in to Kibana as an administrator.
- Navigate to: Stack Management β Security β Users
- Click Create user.
- Assign roles that allow access to Elastic Security features, such as:
- superuser (full access)
- kibana_admin
- Security-specific roles for Cases and Detections
- Set a strong password and save the user.
Connector Configuration in Swimlane
Take the following steps to configure the Elastic Kibana 8 β Security connector asset in Swimlane:
- Log in to Turbine.
- From the left-hand navigation pane, click ORCHESTRATION β Assets.
- Click the plus icon to open the Configure your Connector Asset window.
- Select Elastic Kibana 8 β Security from the Asset type list.
- Fill in the Asset Settings and Asset Input as shown below.
Configuration - API Key Authentication
Use this method for Elastic Cloud or when API keys are preferred.
Field | Description | Required |
|---|---|---|
url | Kibana host URL (no trailing slash) | Yes |
x-apikey | Elastic API Key | Yes |
port | Host port (if not default) | Optional |
verify_ssl | Enable or disable SSL verification | Optional |
http_proxy | Proxy configuration (if required) | Optional |
6. Click Create.
Configuration β HTTP Basic Authentication
Use this method for self-managed Kibana deployments.
Field | Description | Required |
|---|---|---|
url | Kibana host URL | Yes |
username | Kibana username | Yes |
password | Kibana password | Yes |
verify_ssl | Enable or disable SSL verification | Optional |
http_proxy | Proxy configuration (if required) | Optional |
Connecting to Elastic Cloud vs On-Premises
Elastic Cloud Requirements
When using Elastic Cloud, you must configure:
- url
- x-apikey
API Key Authentication is strongly recommended.
On-Premises Requirements
When connecting to an on-prem deployment:
- The URL must be formatted as:
<kibana-host>:<port>
You must configure:
- url
- username
- Password
Troubleshooting
If authentication fails, verify the following:
Invalid API Key
- Ensure the API key is active and not expired.
- Confirm it has sufficient privileges for Elastic Security APIs.
- If generated from Elastic Cloud, ensure it was encoded correctly.
Host URL Errors
If you receive a host validation error:
- Remove trailing slashes from the URL.
403 Forbidden Errors
A 403 response usually means insufficient permissions.
Confirm the API key or user role includes access to:
- Cases
- Detections
- Timelines
- Endpoint actions
Sources
Elastic Security API Documentation (8.10) https://www.elastic.co/guide/en/security/current/security-api-overview.htmlο»Ώ
Result: You have successfully authenticated the Elastic Kibana 8 - Security connector in Swimlane using API Key Authentication or HTTP Basic Authentication.