# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Kibana category](https://discuss.elastic.co/t/about-the-kibana-category/22)

<div class="topic-metadata">

**Author:** [@Leslie\_Hawthorn](https://discuss.elastic.co/u/Leslie_Hawthorn)\
**Replies:** 0\
**Last updated:** [April 22, 2015, 3:36pm UTC](https://discuss.elastic.co/t/about-the-kibana-category/22 "2015-04-22T15:36:09Z")

</div>

Your window into the Elastic Stack Kibana is a free and open user interface that lets you visualize your Elasticsearch data and navigate the Elastic Stack. Do anything from tracking query load to understanding the way re…

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [October 1, 2026, 12:02am UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775 "2026-10-01T00:02:38Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [September 30, 2026, 2:25pm UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774 "2026-09-30T14:25:19Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [Elasticsearch Netflow Top-N dashboard showing data in bytes instead of MB.GB etc](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 0\
**Last updated:** [September 30, 2026, 7:28am UTC](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772 "2026-09-30T07:28:33Z")

</div>

Hi i have upgraded "or so to speak" from filebeat netflow module to elastic netflow fleet based. And while i see its dashboards are somewhat good compared to the filebeat ones. but one dashboard that i used a lot in fil…

---

## [Time picker in ES|QL query - esql](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [September 25, 2026, 1:55pm UTC](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631 "2026-09-25T13:55:30Z")

</div>

Hi community, I was wondering about a weird behaviour that might catch some people off-guard. How does the time picker affect ES|QL searches? For example the following query implies a 24-hour search, but yet the data d…

---

## [Field formatters in ES|QL table panels](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 1\
**Last updated:** [September 23, 2026, 8:07am UTC](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418 "2026-09-23T08:07:19Z")

</div>

Hi! We have started to use ES|QL a lot in our Kibana dashboards, and I love the flexibility it brings! One of the few missing features compared to Lens table panels is to set formatting on a text/keyword field. F ex a l…

---

## [Kibana 9 - Detail pane is a bad replacement for Expandable row for my use cases](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:00pm UTC](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555 "2026-09-21T12:00:16Z")

</div>

In Kibana 8 we continued to use the "old" UI that offered to expand each row individually to show it's detail values. This works good as the full width of the windows is also available to the detailed attributes and so …

---

## [Kibana 9 - Detail dialog also shows "Truncated string" as configured for the overview](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 11:49am UTC](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551 "2026-09-21T11:49:22Z")

</div>

In the new Kibana 9 UI it's possible to customize the column visualization with "Edit data view field". This allows to e.g. enable to truncate a field to the first x characters so it only needs a reasonable size i…

---

## [Kibana Dark Theme Now Blue?](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 4\
**Last updated:** [September 21, 2026, 9:26am UTC](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919 "2026-09-21T09:26:32Z")

</div>

In Kibana versions up to 8.18.1, the dark theme was black, just as with almost all other software I have used that offers a dark theme. I just upgraded my company's DEV cluster, as well as my home cluster, to 9.0.1, and …

---

## [Kibana error](https://discuss.elastic.co/t/kibana-error/390521)

<div class="topic-metadata">

**Author:** [@vanhung0709](https://discuss.elastic.co/u/vanhung0709)\
**Replies:** 1\
**Last updated:** [September 18, 2026, 4:17am UTC](https://discuss.elastic.co/t/kibana-error/390521 "2026-09-18T04:17:51Z")

</div>

I have set up elasticsearch and kibana. All steps have been done. Although i can curl es from kibana pod, kibana doesn’t put request to create index .kibana. When searching logs in pod kibana, it loop curl get nodes, but…

---

## [Kibana 8.17.3 – Malware Detection of security\_labs Knowledge Base File (TROJ\_FRS.VSNTIA26)](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482)

<div class="topic-metadata">

**Author:** [@shiva3](https://discuss.elastic.co/u/shiva3)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 10:21pm UTC](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482 "2026-09-16T22:21:06Z")

</div>

Hello Elastic Team, We are investigating a security alert involving the Kibana 8.17.3 Docker image deployed in our OpenShift environment. Our endpoint security product detected the following file as: Detection: TROJ\_F…

---

## [Found not migrated detection alerts](https://discuss.elastic.co/t/found-not-migrated-detection-alerts/385044)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 2\
**Last updated:** [September 10, 2026, 6:57pm UTC](https://discuss.elastic.co/t/found-not-migrated-detection-alerts/385044 "2026-09-10T18:57:35Z")

</div>

Hello we are planning our upgrade from 8.19.x to 9.2.x The upgrade assistant contains a warning for Kibana: "Found not migrated detection alerts" I have tried to migrate but this does not work (example with .reindexed…

---

## [Upgrading 8.13.0 - 8.19.20 giving migrations error for kibana\_analytics index](https://discuss.elastic.co/t/upgrading-8-13-0-8-19-20-giving-migrations-error-for-kibana-analytics-index/389786)

<div class="topic-metadata">

**Author:** [@drewb](https://discuss.elastic.co/u/drewb)\
**Replies:** 1\
**Last updated:** [September 8, 2026, 5:14pm UTC](https://discuss.elastic.co/t/upgrading-8-13-0-8-19-20-giving-migrations-error-for-kibana-analytics-index/389786 "2026-09-08T17:14:29Z")

</div>

Unable to complete saved object migrations for the .kibana\_analytics index. Unexpected Elasticsearch ResponseError: statuscode: 404, method: DELETE, url: /pit error: \[undefiend\]: ("succeeded":false,"num\_freed":0} My err…

---

## [Kibana Dev Tools Console does not execute full \_bulk request](https://discuss.elastic.co/t/kibana-dev-tools-console-does-not-execute-full-bulk-request/390219)

<div class="topic-metadata">

**Author:** [@Abdullah\_Hamza](https://discuss.elastic.co/u/Abdullah_Hamza)\
**Replies:** 1\
**Last updated:** [September 7, 2026, 4:30am UTC](https://discuss.elastic.co/t/kibana-dev-tools-console-does-not-execute-full-bulk-request/390219 "2026-09-07T04:30:33Z")

</div>

Description: When running a valid Elasticsearch Bulk API request in Kibana Dev Tools Console, the console does not appear to process all NDJSON operations as a single request. Example: POST /logs/\_bulk {"create":{}} {"@t…

---

## [Security labs documentation via API call - ignoreSecurityLabs](https://discuss.elastic.co/t/security-labs-documentation-via-api-call-ignoresecuritylabs/389948)

<div class="topic-metadata">

**Author:** [@novst](https://discuss.elastic.co/u/novst)\
**Replies:** 2\
**Last updated:** [September 3, 2026, 2:25pm UTC](https://discuss.elastic.co/t/security-labs-documentation-via-api-call-ignoresecuritylabs/389948 "2026-09-03T14:25:11Z")

</div>

Hello, I am trying to automate installation for the customer and I want to install "Elastic documentation" and "Security labs" under http://localhost:5601/app/management/ai/genAiSettings According to documentation Crea…

---

## [A2A server authentication](https://discuss.elastic.co/t/a2a-server-authentication/390030)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [September 2, 2026, 5:03pm UTC](https://discuss.elastic.co/t/a2a-server-authentication/390030 "2026-09-02T17:03:35Z")

</div>

Hi Team, We have created a Custom AI Agent in Elasticsearch and are planning to access it from an external application through the A2A (Agent-to-Agent) Server. Currently, we understand that authentication to the A2A Se…

---

## [Kibana Lens/Time Series Chart Incorrectly Splits Documents That Fall Exactly on a Minute Boundary](https://discuss.elastic.co/t/kibana-lens-time-series-chart-incorrectly-splits-documents-that-fall-exactly-on-a-minute-boundary/390125)

<div class="topic-metadata">

**Author:** [@sebastian31231](https://discuss.elastic.co/u/sebastian31231)\
**Replies:** 0\
**Last updated:** [September 2, 2026, 9:03am UTC](https://discuss.elastic.co/t/kibana-lens-time-series-chart-incorrectly-splits-documents-that-fall-exactly-on-a-minute-boundary/390125 "2026-09-02T09:03:59Z")

</div>

Hi, I’m having an issue with data visualization in Kibana on a time series chart. It appears that documents whose timestamps fall very close to the start of a full minute - e.g., \`12:15:00.03\` - aren’t always assigned t…

---

## [Trigger alert for individual cpu core crossing 95% utilization](https://discuss.elastic.co/t/trigger-alert-for-individual-cpu-core-crossing-95-utilization/389959)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 28, 2026, 12:19pm UTC](https://discuss.elastic.co/t/trigger-alert-for-individual-cpu-core-crossing-95-utilization/389959 "2026-08-28T12:19:32Z")

</div>

I have a simple requirement to trigger alert if any of the CPU core breach 95% threshold:(using alert/rule in kibana) Challenge facing: system.core.total.pct this field gives abnormal values to be used like 1000, 4700, …

---

## [How to change data view for an already created map?](https://discuss.elastic.co/t/how-to-change-data-view-for-an-already-created-map/389961)

<div class="topic-metadata">

**Author:** [@HaydenB0101](https://discuss.elastic.co/u/HaydenB0101)\
**Replies:** 1\
**Last updated:** [August 27, 2026, 7:18pm UTC](https://discuss.elastic.co/t/how-to-change-data-view-for-an-already-created-map/389961 "2026-08-27T19:18:16Z")

</div>

Hello, I imported a map from a separate server and want to change the data view that the map is using. I can't find any option to change the data view, only to see the details of the source. I tried looking through the …

---

## [Moment.js Vulnerability](https://discuss.elastic.co/t/moment-js-vulnerability/389932)

<div class="topic-metadata">

**Author:** [@ashish.jagtap](https://discuss.elastic.co/u/ashish.jagtap)\
**Replies:** 0\
**Last updated:** [August 26, 2026, 2:01pm UTC](https://discuss.elastic.co/t/moment-js-vulnerability/389932 "2026-08-26T14:01:42Z")

</div>

Hello, I am using Elasticsearch-Kibana version 7.17.2. In the security tests, it was observed that there was a vulnerability in moment.js software. moment.js 2.28.0 --\> CVE-2022-24785 Do we have remediation plan for …

---

## [Kibana Dashboard search blocks bracket characters in \[\] prefix](https://discuss.elastic.co/t/kibana-dashboard-search-blocks-bracket-characters-in-prefix/389725)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 4\
**Last updated:** [August 19, 2026, 6:20pm UTC](https://discuss.elastic.co/t/kibana-dashboard-search-blocks-bracket-characters-in-prefix/389725 "2026-08-19T18:20:53Z")

</div>

We are using ELK 9.4.3 We are seeing this error when searching our dashboard. I though using brackets was a naming convention from Kibana itself so why is it giving an error?

---

## [Using time shift in ES|QL dashboard panels](https://discuss.elastic.co/t/using-time-shift-in-es-ql-dashboard-panels/389751)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 2\
**Last updated:** [August 19, 2026, 7:17am UTC](https://discuss.elastic.co/t/using-time-shift-in-es-ql-dashboard-panels/389751 "2026-08-19T07:17:12Z")

</div>

Is time shift planned for ES|QL dashboard panels? I'm building Kibana dashboards using ES|QL and would like to compare the time range selected in the dashboard with the same period 52 weeks earlier. Ideally, I'd like t…

---

## [Latency graph not showing](https://discuss.elastic.co/t/latency-graph-not-showing/389668)

<div class="topic-metadata">

**Author:** [@ajoshi](https://discuss.elastic.co/u/ajoshi)\
**Replies:** 3\
**Last updated:** [August 15, 2026, 4:24pm UTC](https://discuss.elastic.co/t/latency-graph-not-showing/389668 "2026-08-15T16:24:03Z")

</div>

latency graph not coming in APM dashboard other things are coming i don't know why ?

---

## [Advanced Tab is missing in Streams Page in 9.5.0](https://discuss.elastic.co/t/advanced-tab-is-missing-in-streams-page-in-9-5-0/389476)

<div class="topic-metadata">

**Author:** [@Suren\_R](https://discuss.elastic.co/u/Suren_R)\
**Replies:** 2\
**Last updated:** [August 13, 2026, 3:10pm UTC](https://discuss.elastic.co/t/advanced-tab-is-missing-in-streams-page-in-9-5-0/389476 "2026-08-13T15:10:16Z")

</div>

After upgrading to 9.5.1, I can no longer see Advanced Tab in Streams page. This section allowed to easily configure the number of shards and refresh interval of backing indices without having to edit JSON settings in in…

---

## [/app/fleet/agents shows no agents in Kibana, but API does](https://discuss.elastic.co/t/app-fleet-agents-shows-no-agents-in-kibana-but-api-does/388372)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 7\
**Last updated:** [August 13, 2026, 11:48am UTC](https://discuss.elastic.co/t/app-fleet-agents-shows-no-agents-in-kibana-but-api-does/388372 "2026-08-13T11:48:22Z")

</div>

Hi, I use elastic stack in version 9.4.3. I have one fleet instance running, but it's not visible in the Kibana UI: An API call via curl shows otherwise: { "items": \[ { "id": "3b28b7af-6b94-4a08-8105-5ba0b25afd…

---

## [Truncate a Mustache variable in an Alerting rule action (e.g. limit a long text field to N words)?](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 2\
**Last updated:** [August 13, 2026, 5:23am UTC](https://discuss.elastic.co/t/truncate-a-mustache-variable-in-an-alerting-rule-action-e-g-limit-a-long-text-field-to-n-words/389290 "2026-08-13T05:23:43Z")

</div>

Hello Team, Kibana version: 9.x We have a rule (Elasticsearch query rule type) that runs every few minutes against an index of banking transaction logs. When it matches, the action is an Index connector that writes a s…

---

## [Self-managed and air-gapped cluster: How to bypass self-signed certificate validation or configure custom endpoints in kibana.yml?](https://discuss.elastic.co/t/self-managed-and-air-gapped-cluster-how-to-bypass-self-signed-certificate-validation-or-configure-custom-endpoints-in-kibana-yml/389266)

<div class="topic-metadata">

**Author:** [@Osmel\_Pillot\_Leyva](https://discuss.elastic.co/u/Osmel_Pillot_Leyva)\
**Replies:** 2\
**Last updated:** [August 12, 2026, 7:55pm UTC](https://discuss.elastic.co/t/self-managed-and-air-gapped-cluster-how-to-bypass-self-signed-certificate-validation-or-configure-custom-endpoints-in-kibana-yml/389266 "2026-08-12T19:55:01Z")

</div>

Hi everyone, I manage a self-managed, completely air-gapped Elastic cluster in an isolated network environment with no internet access. In our corporate infrastructure, we have an internal ERP and EMS running with self…

---

## [Kibana dashboard elements initially not rendering the contents](https://discuss.elastic.co/t/kibana-dashboard-elements-initially-not-rendering-the-contents/389415)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 3\
**Last updated:** [August 12, 2026, 1:40pm UTC](https://discuss.elastic.co/t/kibana-dashboard-elements-initially-not-rendering-the-contents/389415 "2026-08-12T13:40:29Z")

</div>

I have cloud hosted Elasticsearch solution. After updating from 9.2.8 to 9.4.3 I have issues when loading the data into Kibana dashboard. Before updating all dashboards loaded the data and rendered the visualisation with…

---

## [Assigning an Index Template to an ILM Policy Gets Periodically Removed](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 8\
**Last updated:** [August 6, 2026, 2:30pm UTC](https://discuss.elastic.co/t/assigning-an-index-template-to-an-ilm-policy-gets-periodically-removed/389274 "2026-08-06T14:30:17Z")

</div>

As the title suggests, I keep assigning the index template that I want to be linked with a certain ILM, then after some time I go check it and find that they went back to the previous one. This happened to me numerou…

---

## [HELP: Disable "Help Us Improve Elastic" Pop-Up on Kibana Visualizations](https://discuss.elastic.co/t/help-disable-help-us-improve-elastic-pop-up-on-kibana-visualizations/388990)

<div class="topic-metadata">

**Author:** [@dan\_walker](https://discuss.elastic.co/u/dan_walker)\
**Replies:** 1\
**Last updated:** [August 4, 2026, 5:58pm UTC](https://discuss.elastic.co/t/help-disable-help-us-improve-elastic-pop-up-on-kibana-visualizations/388990 "2026-08-04T17:58:41Z")

</div>

Is there a way to disable these "Help Us Improve Elastic" pop-ups in Kibana? We embed these views in reports which makes the pop-up un-clickable by end-users. They block vital information in the chart.

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=1)
