# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=100

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 101

---

## [After Update from Kibana 7.x to Kibana 8.9 =\>security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_cluster/settings?include\_defaults=true&f](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984)

<div class="topic-metadata">

**Author:** [@Wolfgang\_Winter](https://discuss.elastic.co/u/Wolfgang_Winter)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 10:24am UTC](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984 "2023-08-21T10:24:36Z")

</div>

Hello, we updated yesterday our elasticsearch-stack to 8.9.0. Now, kibana don't start and i found this error in /var/log/messages FATAL ResponseError: security\_exception Aug 17 10:42:58 elasticserver kibana\[342912\]: …

---

## [Securing Elasticsearch/Kibana / "Bad Decrypt" Error](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 15\
**Last updated:** [August 21, 2023, 10:08am UTC](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944 "2023-08-21T10:08:59Z")

</div>

Hi! I think I totally lost the thread, I don't know where my error is right now. I wanted to change my Elasticsearch-Kibana-WinlogBeat installation, which was working flawlessly so far, to an encrypted connection. The …

---

## [SESSION\_EXPIRED after logging in another Kibana](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003)

<div class="topic-metadata">

**Author:** [@theo2](https://discuss.elastic.co/u/theo2)\
**Replies:** 8\
**Last updated:** [August 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003 "2023-08-21T09:59:25Z")

</div>

Hello, I have a cluster with 3 Elasticsearch on it, individually it works fine. But if I have an instance A connected, and I connect to instance B or C, I receive a SESSION\_EXPIRED timeout. I run kibana locally with d…

---

## [How to get values of filters to a variable in Canvas](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216)

<div class="topic-metadata">

**Author:** [@KLM](https://discuss.elastic.co/u/KLM)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216 "2023-08-21T09:24:41Z")

</div>

I have set of filters on the canvas and values of these will be used in an essql query to pick data to a line chart. filters | essql query="SELECT .." .. .. | render But based on some of the selected values in filter…

---

## [How to query list of offline agents using the Fleet API?](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 11\
**Last updated:** [August 21, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783 "2023-08-21T08:36:03Z")

</div>

I looked at these two docs: and came up with this query: curl --request GET --url 'https://mykibana/api/fleet/agents?kuery=status:offline' \\ --header 'Accept: \*/\*' \\ --header 'Authorization: ApiKey myk…

---

## [Continuously get data from Elasticsearch, when new poll data comes in](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254 "2023-08-21T08:22:56Z")

</div>

Hi, I am creating an external plugin in Kibana 8.1.1 using React. I am retrieving the data I have in ES using the data plugin. Is it possible to fetch and update the plugin state as and when data is inserted into the i…

---

## [Single click option in drilldown](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200 "2023-08-21T07:36:08Z")

</div>

I am used self deploy kibana application with basic licence and I want Single click option in drilldown for dashboard visualizations . Can anyone suggest me to approach for this?

---

## [How to show difference percentage between 2 lines](https://discuss.elastic.co/t/how-to-show-difference-percentage-between-2-lines/341062)

<div class="topic-metadata">

**Author:** [@grace\_Li](https://discuss.elastic.co/u/grace_Li)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 6:09pm UTC](https://discuss.elastic.co/t/how-to-show-difference-percentage-between-2-lines/341062 "2023-08-20T18:09:12Z")

</div>

Hi, Now I have this graph. Is there a way to display how many percentage difference between the 2 lines at each data point?

---

## [KIBANA 8.7.1 kibana\_system password update](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137)

<div class="topic-metadata">

**Author:** [@sealove23](https://discuss.elastic.co/u/sealove23)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137 "2023-08-20T18:08:00Z")

</div>

Happy Friday, need help with KIBANA start using xxxxxxx:5601

---

## [Search related documents in kibana in single query](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115)

<div class="topic-metadata">

**Author:** [@vignesh\_nayak](https://discuss.elastic.co/u/vignesh_nayak)\
**Replies:** 4\
**Last updated:** [August 20, 2023, 4:32pm UTC](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115 "2023-08-20T16:32:38Z")

</div>

Hi, I have one scenario. I am pushing certain ID in thread context from application for each transaction along with individual log messages, which means all docs in kibana for that transaction will have same ID, Ex: Tra…

---

## [As part of elastic upgrade prerequisite deleted .reindexed-v6-watches-6 all watchers are gone](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 4:01pm UTC](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139 "2023-08-20T16:01:06Z")

</div>

Hi All, We're currently on Elastic 7.17 and are preparing to upgrade to version 8.6. As part of the upgrade process, we were reviewing the breaking changes, specifically in relation to the indices created in version 6. …

---

## [How to Check which service/application is generating more logs?](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 3\
**Last updated:** [August 20, 2023, 3:42am UTC](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827 "2023-08-20T03:42:08Z")

</div>

Is there a way to check which service/application is generating more logs? Kubernetes Cluster Centralised Elasticsearch and Kibana Fluentbit - different Kubernetes clusters which will send logs to centralised Elastics…

---

## [Is there a way to monitor changes to roles and username / passwords for builtin or created users](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129)

<div class="topic-metadata">

**Author:** [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Replies:** 6\
**Last updated:** [August 20, 2023, 12:25am UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129 "2023-08-20T00:25:21Z")

</div>

Our Security team is looking for a way for them to use Carbon Black to monitor changes to users (add/ delete) , password changes for these adhoc users or built in users. we were looking for a file on disk. The only inf…

---

## [Revert to Basic (Free) License - JDBC / ODBC Support?](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 7:17pm UTC](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125 "2023-08-18T19:17:39Z")

</div>

Hello, I deployed the ELK stack and used it in TRIAL license mode till now. I plan to revert to the basic (free) license, but I need the functionality to ingest MySQL database data into ELK stack via JDBC ingress pipeli…

---

## [Kibana : no handler found for uri](https://discuss.elastic.co/t/kibana-no-handler-found-for-uri/341123)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-no-handler-found-for-uri/341123 "2023-08-18T18:27:52Z")

</div>

I tried to set xpack security for kibana by doing following bin/kibana-encryption-keys generate Copied the generated encryption keys to kibana.yml. xpack.encryptedSavedObjects.encryptionKey: #### xpack.reporti…

---

## [\[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0\] EndpointError: Error scheduling task](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 6:01pm UTC](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121 "2023-08-18T18:01:28Z")

</div>

Hi, I am trying to log in to my kibana but I get the following message: I have logged in to the server and I get the following error in the log: \[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0…

---

## [We couldn't log you in. Please try again](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/340929)

<div class="topic-metadata">

**Author:** [@daniel\_quiroz](https://discuss.elastic.co/u/daniel_quiroz)\
**Replies:** 6\
**Last updated:** [August 18, 2023, 4:50pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/340929 "2023-08-18T16:50:13Z")

</div>

Hi Everyone, I'm install elastic and kibana on Centos 7. They was working but when I restart the server, the services now print "We couldn't log you in. Please try again." in Kibana's login. I look the service status a…

---

## ["You need permission to create data views" error in new space](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998)

<div class="topic-metadata">

**Author:** [@jonasjancarik](https://discuss.elastic.co/u/jonasjancarik)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 8:17pm UTC](https://discuss.elastic.co/t/you-need-permission-to-create-data-views-error-in-new-space/340998 "2023-08-17T20:17:33Z")

</div>

I've created a new space in Kibana, but I am unable to access the Analytics features, such as opening dashboards. I'm met with the error message "You need permission to create data views." What's even more confusing is t…

---

## [Enhanced table button functionality in row or near serach bar](https://discuss.elastic.co/t/enhanced-table-button-functionality-in-row-or-near-serach-bar/341027)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 7:20pm UTC](https://discuss.elastic.co/t/enhanced-table-button-functionality-in-row-or-near-serach-bar/341027 "2023-08-17T19:20:06Z")

</div>

Hello @fbaligand , I have a requirement and need suggestion if this is possible or not in ENHANCED TABLE. I have dashboard using enhanced table, in one particular usecases I would not like to store user data directly i…

---

## [ELK/Kibana SSO using Keycloak](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 7:18pm UTC](https://discuss.elastic.co/t/elk-kibana-sso-using-keycloak/341035 "2023-08-17T19:18:18Z")

</div>

Is the enterprise version of Elasticsearch required for Keycloak OICD integration for single sign on?

---

## [Time slider playback](https://discuss.elastic.co/t/time-slider-playback/341043)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 6:01pm UTC](https://discuss.elastic.co/t/time-slider-playback/341043 "2023-08-17T18:01:05Z")

</div>

Hello, I've been reading through the documenation to see if this capability exists, but I've been unable to find it. Is it possible to setup a time range "playback" that is not just a slider intervals within a global ti…

---

## [Bulk API without printing result on terminal](https://discuss.elastic.co/t/bulk-api-without-printing-result-on-terminal/341002)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 12:23pm UTC](https://discuss.elastic.co/t/bulk-api-without-printing-result-on-terminal/341002 "2023-08-17T12:23:13Z")

</div>

Is it possible to execute the Bulk API without printing the result on terminal? I am using the following API: curl -X POST "localhost:9200/log/\_bulk?pretty" -H 'Content-Type: application/json' --data-binary @path/log.l…

---

## [Display the consumed energy for every single device in a Trend](https://discuss.elastic.co/t/display-the-consumed-energy-for-every-single-device-in-a-trend/337186)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 11:59am UTC](https://discuss.elastic.co/t/display-the-consumed-energy-for-every-single-device-in-a-trend/337186 "2023-08-17T11:59:25Z")

</div>

Hi together, i have a site with three electric devices but only one energy meter. The task is to display the consumed energy for every single device in a Trend. So i get the actual consumed accumulated Energy from the…

---

## [Kibana TSVB aggregation group by Terms not working correctly?](https://discuss.elastic.co/t/kibana-tsvb-aggregation-group-by-terms-not-working-correctly/340961)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 4:12am UTC](https://discuss.elastic.co/t/kibana-tsvb-aggregation-group-by-terms-not-working-correctly/340961 "2023-08-17T04:12:29Z")

</div>

It seems when I use TSVB with Aggregation "Average" of Field "cm\_status.upstream\_power", with Group By "Terms" of Field "cm\_status.mac-address.keyword", all mac-addresses show the same value so the multiple lines show id…

---

## [Problems with SCORE on Anomaly Detection JOB](https://discuss.elastic.co/t/problems-with-score-on-anomaly-detection-job/338600)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 10\
**Last updated:** [August 17, 2023, 8:32am UTC](https://discuss.elastic.co/t/problems-with-score-on-anomaly-detection-job/338600 "2023-08-17T08:32:38Z")

</div>

hi! I have this behavior The typical value was 18.3 and the Actual vale was 0. The anomaly score is too low and I should had received an anomaly alert but the score was wrong, so the alert was not fired. I also…

---

## [Storage sinze index of a policy](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881)

<div class="topic-metadata">

**Author:** [@agomezgu](https://discuss.elastic.co/u/agomezgu)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 12:36pm UTC](https://discuss.elastic.co/t/storage-sinze-index-of-a-policy/340881 "2023-08-16T12:36:48Z")

</div>

Hi, I'm new to ELKstack and I'm trying to get from an Index Lifecycle Policies "logstash-pro" all the indexes that are in it, and also about this to return me the space occupied by each index. For example, I use the sta…

---

## [Encountering 'Name must match one or more data streams, indices, or index aliases' error when creating a data view in Kibana 8 Discover section](https://discuss.elastic.co/t/encountering-name-must-match-one-or-more-data-streams-indices-or-index-aliases-error-when-creating-a-data-view-in-kibana-8-discover-section/339589)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 11:51am UTC](https://discuss.elastic.co/t/encountering-name-must-match-one-or-more-data-streams-indices-or-index-aliases-error-when-creating-a-data-view-in-kibana-8-discover-section/339589 "2023-08-16T11:51:52Z")

</div>

Hello, hope you're doing well. When I try to create a data view in the Discover section of Kibana 8, I encounter the following error message for any index pattern I write in the index pattern field: "Name must match on…

---

## [Kibana Error Messages](https://discuss.elastic.co/t/kibana-error-messages/340823)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 7:11am UTC](https://discuss.elastic.co/t/kibana-error-messages/340823 "2023-08-16T07:11:39Z")

</div>

Hello, Elasticsearch-Kibana: 7.10.2 As can be seen from the error messages in Kibana below It is seen that a critical level of information about the system is revealed. Is there any way to close these error messag…

---

## [Kibana watcher alerting for Elastic agents](https://discuss.elastic.co/t/kibana-watcher-alerting-for-elastic-agents/340865)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 4:03am UTC](https://discuss.elastic.co/t/kibana-watcher-alerting-for-elastic-agents/340865 "2023-08-16T04:03:17Z")

</div>

Hello All, I am looking for a possible way to create a custom threshold alert that will monitor if the elastic agent goes down and doesn't come back up in 5-10mins, it should send us an email. Have anyone done it befor…

---

## [How to search and display log events linked through a series of UUIDs](https://discuss.elastic.co/t/how-to-search-and-display-log-events-linked-through-a-series-of-uuids/340854)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:43am UTC](https://discuss.elastic.co/t/how-to-search-and-display-log-events-linked-through-a-series-of-uuids/340854 "2023-08-16T02:43:27Z")

</div>

Hi, We have an application which communicates with various microservices. Some initial request to an endpoint /api on A might generate several requests to systems B and C, and they themselves might generate further req…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=99)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=101)
