# is there any additional function to prevent brute force attack?

**URL:** <https://forum.search-guard.com/t/is-there-any-additional-function-to-prevent-brute-force-attack/1295>\
**Category:** Search Guard\
**Created:** [January 21, 2019, 9:55am UTC](https://forum.search-guard.com/t/is-there-any-additional-function-to-prevent-brute-force-attack/1295 "2019-01-21T09:55:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jin\_Park](https://avatars.discourse-cdn.com/v4/letter/j/5f9b8f/32.png) [@Jin\_Park](https://forum.search-guard.com/u/Jin_Park)\
**Post date:** [January 21, 2019, 9:55am UTC](https://forum.search-guard.com/t/is-there-any-additional-function-to-prevent-brute-force-attack/1295/1 "2019-01-21T09:55:09Z")

</div>

- Elastic search version : 6.5.2 Search guard: equivalent to Elastic search
- Java 10 with MacOS

I just created log-in page (search-guard) for kibana.

after the creation, I have a question

is there any way(function) to prevent brute force attack in search guard?

(for example, if someone typed at least 5times incorrect password on my kibana log-in page, it should be locked for 30 secs

Moreover, infinite number of incorrection were typed then, the account has to be locked)

---

<div class="post-metadata">

**Author:** ![searchguard\_google\_group](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/searchguard_google_group/32/462_2.png) [@searchguard\_google\_group](https://forum.search-guard.com/u/searchguard_google_group)\
**Post date:** [January 21, 2019, 1:38pm UTC](https://forum.search-guard.com/t/is-there-any-additional-function-to-prevent-brute-force-attack/1295/2 "2019-01-21T13:38:06Z")

</div>

Depends on your authentication backend. For example with LDAP/AD this is no problem.  
The internal authentication backend in Search Guard does not have such a functionality.

> **···**
>
> > Am 21.01.2019 um 10:55 schrieb Jin Park \<jpar303@gmail.com\>:
> > 
> > &nbsp;&nbsp;• Elastic search version : 6.5.2 Search guard: equivalent to Elastic search  
> > &nbsp;&nbsp;• Java 10 with MacOS
> > 
> > I just created log-in page (search-guard) for kibana.  
> > after the creation, I have a question
> > 
> > is there any way(function) to prevent brute force attack in search guard?
> > 
> > (for example, if someone typed at least 5times incorrect password on my kibana log-in page, it should be locked for 30 secs  
> > Moreover, infinite number of incorrection were typed then, the account has to be locked)
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "Search Guard Community Forum" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to search-guard+unsubscribe@googlegroups.com.  
> > To post to this group, send email to search-guard@googlegroups.com.  
> > To view this discussion on the web visit [https://groups.google.com/d/msgid/search-guard/13596915-299b-4cd1-bcb1-da7b7749aadb%40googlegroups.com\](https://groups.google.com/d/msgid/search-guard/13596915-299b-4cd1-bcb1-da7b7749aadb%40googlegroups.com%5C).  
> > For more options, visit [https://groups.google.com/d/optout\](https://groups.google.com/d/optout%5C).
