Port 5601Kibana

TCP 5601 commonly serves Kibana, the Elastic Stack web interface for dashboards, search, and security operations.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
7/10

risk

lookups
0

rank 993 of 5,528 · top 18%

also known as esmagent

Technical Details

what runs on :5601

Kibana commonly listens on TCP 5601 and serves a browser-based web application over HTTP by default; TLS can be enabled in Kibana or provided by a reverse proxy. The interface and its API use HTTP requests and responses, including JSON, to interact with Elasticsearch. UDP 5601 is not a normal Kibana listener. This common use differs from IANA's assignment of the port to Enterprise Security Agent, registered to Kimberly Gibbs.

Security Information

exposure of :5601

risk score

7/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

web services averages 3.1 across 199 ports — this one sits 3.9 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

An internet-accessible Kibana instance can expose dashboards, searches, and potentially sensitive Elasticsearch data; available access depends on the Elastic version and its authentication and authorization configuration. Do not expose it directly to the public internet unless necessary: restrict access with network controls and authentication, and use HTTPS. Older or misconfigured deployments may lack adequate access controls.

the 8 most looked-up other ports in web services — 199 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted