LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What happens when Elasticsearch starts for the first time, and why do you have to act quickly when connecting Kibana?

On its first start, Elasticsearch configures security automatically: it generates TLS certificates, a password for the elastic superuser and an enrollment token for Kibana. The token expires after a short time (30 minutes), so Kibana must be unpacked and ready before Elasticsearch is started.

Six-step first start of Elasticsearch and Kibana; the enrollment token printed in step 3 must be used in Kibana before it expires

* Credentials and the token are printed once; Kibana has to be ready in time. *

The sequence:

  1. Unpack both Elasticsearch and Kibana first.
  2. Start bin\elasticsearch.bat (no admin rights needed). Allow the firewall rule it requests.
  3. Copy the generated elastic password and the enrollment token somewhere safe; they are printed only once.
  4. Check https://127.0.0.1:9200/: after accepting the self-signed certificate warning and logging in as elastic, a JSON response means Elasticsearch is running.
  5. Start bin\kibana.bat in a second console, open the URL it prints (port 5601), and paste the enrollment token.
  6. Log in to Kibana as elastic with the same password.

Security is on by default because Elasticsearch clusters left open on the internet were a common cause of large data leaks. The certificate warning appears because the certificate is signed by a CA Elasticsearch created itself; importing that CA into the trusted root store removes it. Ctrl+C in the console stops each program.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026