From version 5.0 onward, Shield is part of X-Pack. For more information, see
Securing Elasticsearch and Kibana in the X-Pack Reference.
Now that you have Shield up and running, we strongly recommend that you secure communications to and from nodes by configuring your cluster to use SSL/TLS encryption. Nodes that do not have encryption enabled send passwords in plain text!
Depending on your security requirements, you might also want to:
- Define and Use Custom Roles for fine-grained access control.
- Integrate with LDAP or Active Directory, or require certificates for authentication.
- Use IP Filtering to allow or deny requests from particular IP addresses or address ranges.