# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [The select time range does not include the entire bucket it may contain partial data](https://discuss.elastic.co/t/the-select-time-range-does-not-include-the-entire-bucket-it-may-contain-partial-data/388927)

<div class="topic-metadata">

**Author:** [@Ricardo\_Alves](https://discuss.elastic.co/u/Ricardo_Alves)\
**Replies:** 0\
**Last updated:** [July 31, 2026, 2:28pm UTC](https://discuss.elastic.co/t/the-select-time-range-does-not-include-the-entire-bucket-it-may-contain-partial-data/388927 "2026-07-31T14:28:56Z")

</div>

I want the graph to show just one day, and it shows me 2 days, with this message "The select time range does not include the entire bucket it may contain partial data". In attached I will send you the graph and the adva…

---

## [AWS integration 7.1 fleet agent bug or UI glitch](https://discuss.elastic.co/t/aws-integration-7-1-fleet-agent-bug-or-ui-glitch/388899)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 10\
**Last updated:** [July 30, 2026, 3:01pm UTC](https://discuss.elastic.co/t/aws-integration-7-1-fleet-agent-bug-or-ui-glitch/388899 "2026-07-30T15:01:48Z")

</div>

Recently upgraded ELK cluster from 9.3.2 to 9.4.4. On older version had AWS integration of version 6.20, on new cluster upgraded it to 7.1 latest. Prior to upgrade, we had 1 Elastic agent with this integration 6.2 (agent…

---

## [Cant close alerts using the api](https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605)

<div class="topic-metadata">

**Author:** [@Shahar\_Argov](https://discuss.elastic.co/u/Shahar_Argov)\
**Replies:** 1\
**Last updated:** [July 26, 2026, 4:22am UTC](https://discuss.elastic.co/t/cant-close-alerts-using-the-api/388605 "2026-07-26T04:22:09Z")

</div>

hi there, we are using kibana security alerts and came by an error. we were trying to use the kibana api to close security alerts using workflow automation. about 10 seconds after the run is started, we get the follow…

---

## [Elastic for MSSP: What is the impact of a new space on kibana?](https://discuss.elastic.co/t/elastic-for-mssp-what-is-the-impact-of-a-new-space-on-kibana/388732)

<div class="topic-metadata">

**Author:** [@ArgoAdvisory](https://discuss.elastic.co/u/ArgoAdvisory)\
**Replies:** 4\
**Last updated:** [July 24, 2026, 4:39pm UTC](https://discuss.elastic.co/t/elastic-for-mssp-what-is-the-impact-of-a-new-space-on-kibana/388732 "2026-07-24T16:39:53Z")

</div>

Hello! Our main goal: As an MSSP, we want to create a multi-tenant subdivision for our customers. Each customer has an internal IT team who wants access to their Elastic Security Space. Useful information: Elastic …

---

## [Relationship missing between dashboard and visualization](https://discuss.elastic.co/t/relationship-missing-between-dashboard-and-visualization/388389)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 1\
**Last updated:** [July 20, 2026, 5:39am UTC](https://discuss.elastic.co/t/relationship-missing-between-dashboard-and-visualization/388389 "2026-07-20T05:39:44Z")

</div>

Hello, I discovered something what seems to be a bug when creating a new dashboard from a visualization. Steps to reproduce: Start from a Saved Discovery Session and click on the "Edit Visualization" on the chart abo…

---

## [Changing global setting "Autocomplete value suggestion method" not working](https://discuss.elastic.co/t/changing-global-setting-autocomplete-value-suggestion-method-not-working/388394)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 0\
**Last updated:** [July 17, 2026, 12:23pm UTC](https://discuss.elastic.co/t/changing-global-setting-autocomplete-value-suggestion-method-not-working/388394 "2026-07-17T12:23:13Z")

</div>

Hello, There is a global Kibana setting called "Autocomplete value suggestion method" (autocomplete:valueSuggestionMethod) which defaults to "terms\_enum and with the following remark: The method used for querying sugge…

---

## [Dropdown suggestions not showing up for Filters in Kibana Dashboard](https://discuss.elastic.co/t/dropdown-suggestions-not-showing-up-for-filters-in-kibana-dashboard/383811)

<div class="topic-metadata">

**Author:** [@Lakshay\_Choube](https://discuss.elastic.co/u/Lakshay_Choube)\
**Replies:** 6\
**Last updated:** [July 17, 2026, 9:41am UTC](https://discuss.elastic.co/t/dropdown-suggestions-not-showing-up-for-filters-in-kibana-dashboard/383811 "2026-07-17T09:41:49Z")

</div>

How can we have auto-suggestions and options to show in filters for say Program Names - with account\_id restriction on the documents the user can see. Basically my account has all granted fields access but when an accou…

---

## [Kibana 9.4.3 high RAM consumption](https://discuss.elastic.co/t/kibana-9-4-3-high-ram-consumption/388326)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 2\
**Last updated:** [July 15, 2026, 5:31pm UTC](https://discuss.elastic.co/t/kibana-9-4-3-high-ram-consumption/388326 "2026-07-15T17:31:44Z")

</div>

Hello, I have a problem that Kibana is taking too much RAM after upgrading to version 9.4.3 consumption in previous versions (from stack monitoring) 8.17.0 & 8.19.0 : consumption doubled after upgrade (9.4.3): A…

---

## [Security update ESA-2026-08](https://discuss.elastic.co/t/security-update-esa-2026-08/388361)

<div class="topic-metadata">

**Author:** [@Peter\_Misovic](https://discuss.elastic.co/u/Peter_Misovic)\
**Replies:** 1\
**Last updated:** [July 15, 2026, 12:36pm UTC](https://discuss.elastic.co/t/security-update-esa-2026-08/388361 "2026-07-15T12:36:46Z")

</div>

Hello, please, I currently have ELK v 9.2.2, Kibana 8.19.10, 9.1.10, 9.2.4 Security Update (ESA-2026-08) says "The issue is resolved in version 8.19.10, 9.1.10, 9.2.4.", please, what about 9.4.2 or 9.4.3? Shall I upgra…

---

## [How to break down (terms aggregation) in Kibana Lens by a sub-key of a flattened field (other than a runtime field)](https://discuss.elastic.co/t/how-to-break-down-terms-aggregation-in-kibana-lens-by-a-sub-key-of-a-flattened-field-other-than-a-runtime-field/388352)

<div class="topic-metadata">

**Author:** [@shojiiii](https://discuss.elastic.co/u/shojiiii)\
**Replies:** 0\
**Last updated:** [July 15, 2026, 4:43am UTC](https://discuss.elastic.co/t/how-to-break-down-terms-aggregation-in-kibana-lens-by-a-sub-key-of-a-flattened-field-other-than-a-runtime-field/388352 "2026-07-15T04:43:38Z")

</div>

Environment Elasticsearch / Kibana: 8.14.0 ~several million to ~10 million documents per index (daily indices) What I want to do In Kibana Lens, I want to break down (Top values / terms aggregation) by the value of a…

---

## [Basic license site is broken - register.elastic.co/registration](https://discuss.elastic.co/t/basic-license-site-is-broken-register-elastic-co-registration/387710)

<div class="topic-metadata">

**Author:** [@Adrian\_Beloqui](https://discuss.elastic.co/u/Adrian_Beloqui)\
**Replies:** 2\
**Last updated:** [July 11, 2026, 5:11am UTC](https://discuss.elastic.co/t/basic-license-site-is-broken-register-elastic-co-registration/387710 "2026-07-11T05:11:59Z")

</div>

I am trying to get a new Basic license for our hosted ELK stack with elastic version 6.2.4 but the website Register | Elastic seems to have an issue with the reCAPTHA and doesn't allow me to submit the form. Can you ple…

---

## [Updating Node.js (Ubuntu) within the Kibana application](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720)

<div class="topic-metadata">

**Author:** [@MandoStorm](https://discuss.elastic.co/u/MandoStorm)\
**Replies:** 4\
**Last updated:** [July 9, 2026, 5:12pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720 "2026-07-09T17:12:56Z")

</div>

Good morning/afternoon, I am currently running Ubuntu 24.04 and I want to upgrade the version of node.js to v26.3.1 within kibana application. Any guidance would be greatly appreciated.

---

## [Kibana 8.19.17 fails to start after upgrade with FATAL Error \[ERR\_REQUIRE\_ESM\] in @elastic/charts](https://discuss.elastic.co/t/kibana-8-19-17-fails-to-start-after-upgrade-with-fatal-error-err-require-esm-in-elastic-charts/387406)

<div class="topic-metadata">

**Author:** [@JPPereira](https://discuss.elastic.co/u/JPPereira)\
**Replies:** 4\
**Last updated:** [July 7, 2026, 4:07pm UTC](https://discuss.elastic.co/t/kibana-8-19-17-fails-to-start-after-upgrade-with-fatal-error-err-require-esm-in-elastic-charts/387406 "2026-07-07T16:07:51Z")

</div>

Hi everyone, I am experiencing a crash loop with Kibana version 8.19.17 after upgrade on Rocky Linux 9.8 (Kernel 5.14). The service starts but crashes and restarts every ~20 seconds. Error Logs Here is the fatal error …

---

## [How can I generate the full list of dependencies required to build a Kibana plugin in airgapped env?](https://discuss.elastic.co/t/how-can-i-generate-the-full-list-of-dependencies-required-to-build-a-kibana-plugin-in-airgapped-env/386297)

<div class="topic-metadata">

**Author:** [@Rishav](https://discuss.elastic.co/u/Rishav)\
**Replies:** 1\
**Last updated:** [July 6, 2026, 9:34am UTC](https://discuss.elastic.co/t/how-can-i-generate-the-full-list-of-dependencies-required-to-build-a-kibana-plugin-in-airgapped-env/386297 "2026-07-06T09:34:18Z")

</div>

We currently build our Kibana plugins in a CI/CD pipeline on a VM with full internet access. As part of a security hardening effort, we are moving this build to an airgapped environment where all dependencies must be res…

---

## [One Kibana for three clusters](https://discuss.elastic.co/t/one-kibana-for-three-clusters/387479)

<div class="topic-metadata">

**Author:** [@kkumar123](https://discuss.elastic.co/u/kkumar123)\
**Replies:** 1\
**Last updated:** [July 2, 2026, 4:23pm UTC](https://discuss.elastic.co/t/one-kibana-for-three-clusters/387479 "2026-07-02T16:23:31Z")

</div>

Based on the discussion threads I've reviewed and my understanding, Kibana can connect to only one Elasticsearch cluster. Even if Cross-Cluster Search (CCS) and Cross-Cluster Replication (CCR) are configured, Kibana stil…

---

## [RBAC - Manage spaces - how to disable it?](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881)

<div class="topic-metadata">

**Author:** [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Replies:** 6\
**Last updated:** [July 2, 2026, 7:26am UTC](https://discuss.elastic.co/t/rbac-manage-spaces-how-to-disable-it/386881 "2026-07-02T07:26:56Z")

</div>

In elastic stack 9.4 we want to disable /enable "Manage spaces" functionality. I found only this in the documentation: "An example of a built-in role is kibana\_admin. Assigning this role to your users will grant access…

---

## [\[ERROR\]\[plugins.monitoring.monitoring\] Could not find license information for cluster = 'mylogging'. Please check the cluster's master node server logs for errors or warnings](https://discuss.elastic.co/t/error-plugins-monitoring-monitoring-could-not-find-license-information-for-cluster-mylogging-please-check-the-clusters-master-node-server-logs-for-errors-or-warnings/387415)

<div class="topic-metadata">

**Author:** [@zteddie](https://discuss.elastic.co/u/zteddie)\
**Replies:** 1\
**Last updated:** [June 30, 2026, 7:44pm UTC](https://discuss.elastic.co/t/error-plugins-monitoring-monitoring-could-not-find-license-information-for-cluster-mylogging-please-check-the-clusters-master-node-server-logs-for-errors-or-warnings/387415 "2026-06-30T19:44:16Z")

</div>

I am upgrading my elasticsearch stack hosted on an AKS cluster. The cluster is running with basic license. Everything seemed fine with 8.19.17. But after I upgraded to 9.4.2, kibana is throwing out following error (when …

---

## [I want to do the max of the sum doc\_count per second in line grpah visualization](https://discuss.elastic.co/t/i-want-to-do-the-max-of-the-sum-doc-count-per-second-in-line-grpah-visualization/387260)

<div class="topic-metadata">

**Author:** [@Goncalo\_Santos](https://discuss.elastic.co/u/Goncalo_Santos)\
**Replies:** 1\
**Last updated:** [June 29, 2026, 1:22am UTC](https://discuss.elastic.co/t/i-want-to-do-the-max-of-the-sum-doc-count-per-second-in-line-grpah-visualization/387260 "2026-06-29T01:22:58Z")

</div>

Hello. I'm trying to get the maximum value of the sum doc\_count but using a max\_bucket aggregation it either reaches the maximum number of buckets (error: "too\_many\_buckets\_exception"), or it ajusts the timerange to be …

---

## [Kibana still shows the hidden indices even with Include hidden indices set to off](https://discuss.elastic.co/t/kibana-still-shows-the-hidden-indices-even-with-include-hidden-indices-set-to-off/387310)

<div class="topic-metadata">

**Author:** [@alifiroozi80](https://discuss.elastic.co/u/alifiroozi80)\
**Replies:** 4\
**Last updated:** [June 27, 2026, 7:29am UTC](https://discuss.elastic.co/t/kibana-still-shows-the-hidden-indices-even-with-include-hidden-indices-set-to-off/387310 "2026-06-27T07:29:18Z")

</div>

Hello everyone Even with Include hidden indices set to off, I can still see the . indices (belongs to xpack) in Kibana. How can I disable them so they don't show in Kibana? version: 9.4.2

---

## [Kibana 9.3.1 dashboard loads slow](https://discuss.elastic.co/t/kibana-9-3-1-dashboard-loads-slow/387206)

<div class="topic-metadata">

**Author:** [@mittal\_rawal](https://discuss.elastic.co/u/mittal_rawal)\
**Replies:** 9\
**Last updated:** [June 25, 2026, 2:18pm UTC](https://discuss.elastic.co/t/kibana-9-3-1-dashboard-loads-slow/387206 "2026-06-25T14:18:38Z")

</div>

Hi Team, i have recently migrated elk from 8.16 to 9.3.1 i notice slowness in dashboard load. time take to loads 1-2 minutes for all panels in dashboard i want to load that within 10sec below i am sharing my cluster d…

---

## [Kibana Index Pattern Configuration Problem](https://discuss.elastic.co/t/kibana-index-pattern-configuration-problem/386854)

<div class="topic-metadata">

**Author:** [@Pacous](https://discuss.elastic.co/u/Pacous)\
**Replies:** 12\
**Last updated:** [June 19, 2026, 6:00pm UTC](https://discuss.elastic.co/t/kibana-index-pattern-configuration-problem/386854 "2026-06-19T18:00:59Z")

</div>

I configured Logstash as follows: input { file { path =\> "/var/log/apache2/access.log" } } filter { grok { match =\> { "message" =\> "%{COMBINEDAPACHELOG}" } } date { match =\> \[ "timestamp", "dd/MMM/yyyy:HH:mm:ss Z"…

---

## [Elastic Defend api/endpoint/metadata: Pagination stuck when more than pageSize endpoints share the same last\_checkin timestamp](https://discuss.elastic.co/t/elastic-defend-api-endpoint-metadata-pagination-stuck-when-more-than-pagesize-endpoints-share-the-same-last-checkin-timestamp/386844)

<div class="topic-metadata">

**Author:** [@d7d929022f550dc3d90e](https://discuss.elastic.co/u/d7d929022f550dc3d90e)\
**Replies:** 1\
**Last updated:** [June 13, 2026, 1:36am UTC](https://discuss.elastic.co/t/elastic-defend-api-endpoint-metadata-pagination-stuck-when-more-than-pagesize-endpoints-share-the-same-last-checkin-timestamp/386844 "2026-06-13T01:36:58Z")

</div>

We are paginating through all endpoints using the Kibana api/endpoint/metadata API. The API does not support PIT or search\_after, so we are using cursor-based pagination with sortField=last\_checkin, sortDirection=asc, a…

---

## [Kibana Alerts - Is there a way to schedule rule execution at a specific time daily?](https://discuss.elastic.co/t/kibana-alerts-is-there-a-way-to-schedule-rule-execution-at-a-specific-time-daily/386822)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 2\
**Last updated:** [June 12, 2026, 1:27pm UTC](https://discuss.elastic.co/t/kibana-alerts-is-there-a-way-to-schedule-rule-execution-at-a-specific-time-daily/386822 "2026-06-12T13:27:51Z")

</div>

Hello Community, I am working with Kibana Alerting rules and have a use case where I need an alert to execute at a fixed time every day (e.g., every day at 03:00 UTC), rather than on a recurring interval like "every 1 h…

---

## [About elk log issues](https://discuss.elastic.co/t/about-elk-log-issues/386790)

<div class="topic-metadata">

**Author:** [@Vtm](https://discuss.elastic.co/u/Vtm)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 9:09am UTC](https://discuss.elastic.co/t/about-elk-log-issues/386790 "2026-06-10T09:09:52Z")

</div>

Hello everyone, Need help with Elasticsearch cluster metadata recovery. We originally had a 3-node cluster, but after a restart/patching activity the cluster failed master election. We later rebuilt the cluster and all…

---

## [Elasticsearch alerts don't show source.ip](https://discuss.elastic.co/t/elasticsearch-alerts-dont-show-source-ip/386763)

<div class="topic-metadata">

**Author:** [@komposektoras](https://discuss.elastic.co/u/komposektoras)\
**Replies:** 0\
**Last updated:** [June 8, 2026, 4:54pm UTC](https://discuss.elastic.co/t/elasticsearch-alerts-dont-show-source-ip/386763 "2026-06-08T16:54:16Z")

</div>

I have built a project lab with following tools: Component Tool Hypervisor VirtualBox Attacker VM Kali Linux Victim VM Ubuntu Server 22.04 SIEM VM Ubuntu Server 22.04 Log shipper (Linux) Filebeat …

---

## [Canvas - Saved Visualizations Not Loading](https://discuss.elastic.co/t/canvas-saved-visualizations-not-loading/386696)

<div class="topic-metadata">

**Author:** [@ArielC](https://discuss.elastic.co/u/ArielC)\
**Replies:** 1\
**Last updated:** [June 5, 2026, 9:14am UTC](https://discuss.elastic.co/t/canvas-saved-visualizations-not-loading/386696 "2026-06-05T09:14:02Z")

</div>

My saved visualizations are not loading in canvas. The method used involved using the expression editor to allow for saved lens visualizations to be loaded into Canvas, and respond to global filters. The script used…

---

## [How to authenticate to Elastic via API with PowerShell?](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714)

<div class="topic-metadata">

**Author:** [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Replies:** 3\
**Last updated:** [June 1, 2026, 7:13am UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714 "2026-06-01T07:13:16Z")

</div>

I am trying to generate a dashboard PDF via POST URL. The documentation provides the following curl command: curl \\ -XPOST \\ -u elastic \\ -H 'kbn-xsrf: true' \\ 'http://0.0.0.0:5601/api/reporting/generate/csv?jobParam…

---

## [Kibana 9.4.1 xpack disabled not working anymore](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 8\
**Last updated:** [May 28, 2026, 10:50pm UTC](https://discuss.elastic.co/t/kibana-9-4-1-xpack-disabled-not-working-anymore/386347 "2026-05-28T22:50:00Z")

</div>

I can't access Kibana with xpack security disabled since upgrading my test setup to 9.4.1 I'm proxying Kibana with nginx

---

## [Kibana audit events for dashboard (It is possible?)](https://discuss.elastic.co/t/kibana-audit-events-for-dashboard-it-is-possible/385823)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 2\
**Last updated:** [May 28, 2026, 11:52am UTC](https://discuss.elastic.co/t/kibana-audit-events-for-dashboard-it-is-possible/385823 "2026-05-28T11:52:49Z")

</div>

We are able to create query to query kibana audit events for changes regarding alerting rules and ml jobs. However it doesnt seems like there is any option for us to do the same for dashboard. For example. we want to kno…

---

## [How to rename missing values in visualizations in kibana 9.2](https://discuss.elastic.co/t/how-to-rename-missing-values-in-visualizations-in-kibana-9-2/386524)

<div class="topic-metadata">

**Author:** [@Ranakel](https://discuss.elastic.co/u/Ranakel)\
**Replies:** 1\
**Last updated:** [May 28, 2026, 3:03am UTC](https://discuss.elastic.co/t/how-to-rename-missing-values-in-visualizations-in-kibana-9-2/386524 "2026-05-28T03:03:11Z")

</div>

Hi all, In kibana 8.17 , I was used to renamimg missing values I wanted to show on charts like in this screen shot. With kibana lens in 9.2 , I can't find the equivalent . I only found how to show missing valiues…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=2)
