Add Kibana user settings
editAdd Kibana user settings
editElastic Cloud Enterprise supports most of the standard Kibana and X-Pack settings. Through a YAML editor in the console, you can append Kibana properties to the kibana.yml
file. Your changes to the configuration file are read on startup.
Be aware that some settings that could break your cluster if set incorrectly and that the syntax might change between major versions. Before upgrading, be sure to review the full list of the latest Kibana settings and syntax.
To change Kibana settings:
- Log into the Cloud UI.
-
On the Deployments page, select your deployment.
Narrow the list by name, ID, or choose from several other filters. To further define the list, use a combination of filters.
- From your deployment menu, go to the Edit page.
- In the Kibana section, select Edit user settings. For deployments with existing user settings, you may have to expand the Edit kibana.yml caret instead.
- Update the user settings.
- Select Save changes.
Saving your changes initiates a configuration plan change that restarts Kibana automatically for you.
If a setting is not supported by Elastic Cloud Enterprise, you will get an error message when you try to save. We suggest changing one setting with each save, so you know which one is not supported.
If you have a license from 2018 or earlier, you might receive a warning that your cluster license is about to expire. Don’t panic, it isn’t really. Elastic Cloud Enterprise manages the cluster licenses so that you don’t have to. In rare cases, such as when a cluster is overloaded, it can take longer for Elastic Cloud Enterprise to reapply the cluster license. If you have a license from 2019 and later, you’ll receive a warning only when your full platform license is about to expire, which you’ll need to renew.
Example: Increase the timeout for creating reports
editWhen creating reports, you can adjust the number of milliseconds before a worker times out. This is particularly helpful for instances with a slow or heavy load.
xpack.reporting.queue.timeout: "150000"
Example: Change the truncation point for CSV exports
editIf large exports are causing performance or storage issues, you can increase the number of bytes before the report truncates from the default 250 MB. For stack versions before 8.10, the default is 10 MB. For stack versions between 6.0.0 and 7.15.0 the maximum allowed value is limited to 50 MB (52428800 Bytes).
xpack.reporting.csv.maxSizeBytes: "20971520"
Logging and audit settings
editExamples of Kibana logging and audit settings:
For 7.6 and later 7.x versions:
-
logging.verbose
- If set to true, all events are logged, including system usage information and all requests. Defaults to false.
-
logging.quiet
- If set to true, all logging output other than error messages is suppressed. Defaults to false.
-
elasticsearch.logQueries
-
When set to true, queries sent to Elasticsearch are logged (requires
logging.verbose
set to true). Defaults to false. -
xpack.security.audit.enabled
- When set to true, audit logging is enabled for security events. Defaults to false.
For 7.12 and later 7.x versions:
-
xpack.security.audit.appender.type
-
When set to "rolling-file" and
xpack.security.audit.enabled
is set to true, Kibana ECS audit logs are enabled. Beginning with version 8.0, this setting is no longer necessary for ECS audit log output; it’s only necessary to setxpack.security.audit.enabled
totrue
For version 7.11 and later:
-
xpack.security.audit.ignore_filters
- List of filters that determine which audit events should be excluded from the ECS audit log.
For 7.11.x versions:
-
xpack.security.audit.appender.kind
-
When set to "rolling-file" and
xpack.security.audit.enabled
is set to true, Kibana ECS audit logs are enabled.