This getting started guide walks you through installing Shield, setting up basic authentication, and getting started with role-based access control. You can install Shield on nodes running Elasticsearch 2.4.6.
The Shield plugin must be installed on every node in the cluster. If you are installing to a live cluster, you must stop all of the nodes, install Shield, and restart the nodes. You cannot perform a rolling restart to install Shield.
To install and run Shield:
ES_HOMEto install the license plugin.
bin/plugin install license
bin/plugin installto install the Shield plugin into Elasticsearch.
bin/plugin install shield
If you have disabled automatic index creation in Elasticsearch, configure
elasticsearch.ymlto allow Shield to create the
Marvel and Watcher also store data in automatically created indices. If you are using Marvel, you must allow creation of the
.marvel-*indices. If you are using Watcher, you must allow creation of the
Check the startup log entries to verify that Shield is up and running. When Shield is operating normally, the log indicates that the network transports are using Shield:
[2014-10-09 13:47:38,841][INFO ][transport ] [Ezekiel Stane] Using [org.elasticsearch.shield.transport.ShieldServerTransportService] as transport service, overridden by [shield] [2014-10-09 13:47:38,841][INFO ][transport ] [Ezekiel Stane] Using [org.elasticsearch.shield.transport.netty.ShieldNettyTransport] as transport, overridden by [shield] [2014-10-09 13:47:38,842][INFO ][http ] [Ezekiel Stane] Using [org.elasticsearch.shield.transport.netty.ShieldNettyHttpServerTransport] as http transport, overridden by [shield]
Now you’re ready to secure your cluster! Here are a few things you might want to do to start with: