# Add Security headers

**URL:** <https://community.graylog.org/t/add-security-headers/6259>\
**Category:** Graylog Central (peer support)\
**Created:** [August 6, 2018, 9:19am UTC](https://community.graylog.org/t/add-security-headers/6259 "2018-08-06T09:19:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anishvr24](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/anishvr24/32/2199_2.png) [@anishvr24](https://community.graylog.org/u/anishvr24)\
**Post date:** [August 6, 2018, 9:19am UTC](https://community.graylog.org/t/add-security-headers/6259/1 "2018-08-06T09:19:06Z")

</div>

How can we add the following security headers in the web server’s responses:  
• X-Frame-Options  
• Content-Security-Policy  
• Strict-Transport-Security  
• X-XSS-Protection  
• X-Content-Type-Options

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [August 7, 2018, 1:05pm UTC](https://community.graylog.org/t/add-security-headers/6259/2 "2018-08-07T13:05:37Z")

</div>

you would need to use a proxy like nginx that will set this headers. Graylog itself can’t be used/configured to send them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 21, 2018, 1:18pm UTC](https://community.graylog.org/t/add-security-headers/6259/3 "2018-08-21T13:18:39Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
