# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=11

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 12

---

## [A dashboard for the indices has been under construction for a long time](https://discuss.elastic.co/t/a-dashboard-for-the-indices-has-been-under-construction-for-a-long-time/380673)

<div class="topic-metadata">

**Author:** [@RShyp](https://discuss.elastic.co/u/RShyp)\
**Replies:** 0\
**Last updated:** [August 1, 2025, 2:59pm UTC](https://discuss.elastic.co/t/a-dashboard-for-the-indices-has-been-under-construction-for-a-long-time/380673 "2025-08-01T14:59:38Z")

</div>

We have an Oracle Linux Server 9.2 with ELK Stack version 8.18.3 deployed. In Elasticsearch, we store information about web resource activity (each resource is a separate daily index, with approximately 45 indices and a…

---

## [Unable to Load Page After Upgrade](https://discuss.elastic.co/t/unable-to-load-page-after-upgrade/380638)

<div class="topic-metadata">

**Author:** [@Jadorin](https://discuss.elastic.co/u/Jadorin)\
**Replies:** 3\
**Last updated:** [August 1, 2025, 1:44pm UTC](https://discuss.elastic.co/t/unable-to-load-page-after-upgrade/380638 "2025-08-01T13:44:27Z")

</div>

I recently upgraded our ELK stack from v8.4.3 to v8.18.4 (single node for each product). The only issue we seem to have is that we're unable to open the Stack Management -\> API keys page. We get an error stating "Unable …

---

## [Dashboards can't find the data view](https://discuss.elastic.co/t/dashboards-cant-find-the-data-view/380599)

<div class="topic-metadata">

**Author:** [@rara01](https://discuss.elastic.co/u/rara01)\
**Replies:** 5\
**Last updated:** [August 1, 2025, 10:03am UTC](https://discuss.elastic.co/t/dashboards-cant-find-the-data-view/380599 "2025-08-01T10:03:37Z")

</div>

Hi, I would say majority of automatically generated dashboards from elastic agents, it's integrations , and other dashboards like "Metric System Overview", are in part or overall broken. All of them are pointing to metr…

---

## [Unable to sync only documents that match connector include rules](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418)

<div class="topic-metadata">

**Author:** [@anielo](https://discuss.elastic.co/u/anielo)\
**Replies:** 5\
**Last updated:** [August 1, 2025, 9:37am UTC](https://discuss.elastic.co/t/unable-to-sync-only-documents-that-match-connector-include-rules/374418 "2025-08-01T09:37:26Z")

</div>

Hi there, I am setting up a MySQL connector to synchronise a table with Elasticsearch. My use case is to synchronise only rows that have a field matching a given value (and exclude all the others). I created one includ…

---

## [Ingest pipeline creation problem](https://discuss.elastic.co/t/ingest-pipeline-creation-problem/380538)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 5\
**Last updated:** [August 1, 2025, 9:31am UTC](https://discuss.elastic.co/t/ingest-pipeline-creation-problem/380538 "2025-08-01T09:31:48Z")

</div>

I'm trying to create an ingest pipeline using a grok porcessor to strip the syslog header and a json processor to extract the json portion of the message. Here's the structure of the messages I need to ingest: 2025-07-…

---

## [Elastic Certified Analyst Certification](https://discuss.elastic.co/t/elastic-certified-analyst-certification/380647)

<div class="topic-metadata">

**Author:** [@viktor1](https://discuss.elastic.co/u/viktor1)\
**Replies:** 0\
**Last updated:** [August 1, 2025, 3:59am UTC](https://discuss.elastic.co/t/elastic-certified-analyst-certification/380647 "2025-08-01T03:59:55Z")

</div>

Hi Team, Any recent takers of Elastic Certified Analyst Certification exam ? Can you help share your experience for someone planning to book a certification ? Appreciate. Thanks !

---

## [Embedding Kibana in Company Portal – CORS and Iframe Customization on Elastic Cloud](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549)

<div class="topic-metadata">

**Author:** [@lithindj](https://discuss.elastic.co/u/lithindj)\
**Replies:** 2\
**Last updated:** [July 31, 2025, 11:16am UTC](https://discuss.elastic.co/t/embedding-kibana-in-company-portal-cors-and-iframe-customization-on-elastic-cloud/380549 "2025-07-31T11:16:50Z")

</div>

We’re currently working on embedding Kibana dashboards (hosted on Elastic Cloud) into our internal company portal via an iframe, and we’re running into a couple of key challenges: CORS issues: Kibana and our portal are…

---

## [Infoblox - index username to create Dashboard](https://discuss.elastic.co/t/infoblox-index-username-to-create-dashboard/380525)

<div class="topic-metadata">

**Author:** [@wabd](https://discuss.elastic.co/u/wabd)\
**Replies:** 5\
**Last updated:** [July 31, 2025, 4:19am UTC](https://discuss.elastic.co/t/infoblox-index-username-to-create-dashboard/380525 "2025-07-31T04:19:57Z")

</div>

Hi, i am new user of the plateform, my teammate have implemented ELK and Kibana to get log from our appliances. I am creating dashboards but i have noticed that username is not indexed yet. as a consequence, i can't s…

---

## [Infinite extent for field “\<field name\>” : \[Infinity, -Infinity\]](https://discuss.elastic.co/t/infinite-extent-for-field-field-name-infinity-infinity/380597)

<div class="topic-metadata">

**Author:** [@Akshat1001](https://discuss.elastic.co/u/Akshat1001)\
**Replies:** 1\
**Last updated:** [July 30, 2025, 1:36pm UTC](https://discuss.elastic.co/t/infinite-extent-for-field-field-name-infinity-infinity/380597 "2025-07-30T13:36:12Z")

</div>

I am using opensearch Dashboard This is how my data look like when I run my script: Inspect \> View Request \> Vega debug \> Spec:

---

## [Maps tooltips when using ES|QL layer](https://discuss.elastic.co/t/maps-tooltips-when-using-es-ql-layer/380584)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 2\
**Last updated:** [July 30, 2025, 1:17pm UTC](https://discuss.elastic.co/t/maps-tooltips-when-using-es-ql-layer/380584 "2025-07-30T13:17:28Z")

</div>

I'm using Kibana 9.0.3 and experimenting with the new ES|QL support in Maps. I'm running an ES|QL query that returns geo\_points (e.g., location) along with aggregated metrics (like total\_sales and pct\_diff), and I'm disp…

---

## [Issue with Rollover Index Using Same Date After ELK Upgrade (8.14 -\> 8.16)](https://discuss.elastic.co/t/issue-with-rollover-index-using-same-date-after-elk-upgrade-8-14-8-16/375688)

<div class="topic-metadata">

**Author:** [@Monika1](https://discuss.elastic.co/u/Monika1)\
**Replies:** 1\
**Last updated:** [July 30, 2025, 3:41am UTC](https://discuss.elastic.co/t/issue-with-rollover-index-using-same-date-after-elk-upgrade-8-14-8-16/375688 "2025-07-30T03:41:33Z")

</div>

After upgrading ELK from 8.14 to 8.16, I noticed an issue with the rollover index. Even after performing a rollover, the new index retains the same date as the previous one—only the number is incrementing.

---

## [Runtime field script error: Cannot cast from \[java.lang.String\] to \[void\] in Kibana 8.17](https://discuss.elastic.co/t/runtime-field-script-error-cannot-cast-from-java-lang-string-to-void-in-kibana-8-17/380517)

<div class="topic-metadata">

**Author:** [@Hendrawns](https://discuss.elastic.co/u/Hendrawns)\
**Replies:** 2\
**Last updated:** [July 30, 2025, 2:10am UTC](https://discuss.elastic.co/t/runtime-field-script-error-cannot-cast-from-java-lang-string-to-void-in-kibana-8-17/380517 "2025-07-30T02:10:15Z")

</div>

Hi everyone, I'm working with Kibana 8.17 and trying to create a runtime field using a Painless script to tag http.request.referrer into sectors based on domains. I followed the docs here: Goal: Create a runtime field…

---

## [Rename field after transform with processor / pipeline does not work](https://discuss.elastic.co/t/rename-field-after-transform-with-processor-pipeline-does-not-work/380502)

<div class="topic-metadata">

**Author:** [@StevenGR](https://discuss.elastic.co/u/StevenGR)\
**Replies:** 3\
**Last updated:** [July 29, 2025, 2:06pm UTC](https://discuss.elastic.co/t/rename-field-after-transform-with-processor-pipeline-does-not-work/380502 "2025-07-29T14:06:48Z")

</div>

Hello everybody I have a transform job that writes the following fields from one index into a new index like so: Group By: ap.mac\_address\_normalized Aggregated fields: ap.hostname -\> raw1.ap.hostname ap.mac\_address…

---

## [How to filter dashboard by field maximum value](https://discuss.elastic.co/t/how-to-filter-dashboard-by-field-maximum-value/380129)

<div class="topic-metadata">

**Author:** [@PMF](https://discuss.elastic.co/u/PMF)\
**Replies:** 13\
**Last updated:** [July 29, 2025, 7:00am UTC](https://discuss.elastic.co/t/how-to-filter-dashboard-by-field-maximum-value/380129 "2025-07-29T07:00:41Z")

</div>

Hi all. This seems easy enough, but I'm being unable to achieve it, and don't find an answer on internet. In our use case, we've built a dashboard with several lens graphs. Users reach that dashboard through a shared l…

---

## [Last month time filter](https://discuss.elastic.co/t/last-month-time-filter/380512)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 1\
**Last updated:** [July 29, 2025, 3:36am UTC](https://discuss.elastic.co/t/last-month-time-filter/380512 "2025-07-29T03:36:15Z")

</div>

Hello, I was hoping someone could help me on how to create a time filter that would contain all the data for the preivous month. For example, if it was the 1st of January, I would want this time filter to return all th…

---

## [ES|QL Query Controls](https://discuss.elastic.co/t/es-ql-query-controls/380444)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [July 28, 2025, 4:24pm UTC](https://discuss.elastic.co/t/es-ql-query-controls/380444 "2025-07-28T16:24:49Z")

</div>

Hello, Currently you can build a control through a ES|QL visualization The above is showing when you do the dynamic, building the control based off es|ql query. Is there plans to be able to create a control just ba…

---

## [Calculate sum of piecewise linear aggregations on y axis](https://discuss.elastic.co/t/calculate-sum-of-piecewise-linear-aggregations-on-y-axis/380105)

<div class="topic-metadata">

**Author:** [@MagnesiumReroll](https://discuss.elastic.co/u/MagnesiumReroll)\
**Replies:** 2\
**Last updated:** [July 28, 2025, 2:04pm UTC](https://discuss.elastic.co/t/calculate-sum-of-piecewise-linear-aggregations-on-y-axis/380105 "2025-07-28T14:04:53Z")

</div>

Is there a way to represent/calculate the following for y axis : count\_1 = count(rows where condition=1) count\_2 = count(rows where condition=2) ... sum\_1 = 100 if count\_1\<100 else count\_1 sum\_2 = 100 if count\_2\<100…

---

## [Color coding bar metric](https://discuss.elastic.co/t/color-coding-bar-metric/380489)

<div class="topic-metadata">

**Author:** [@Simon\_Thies](https://discuss.elastic.co/u/Simon_Thies)\
**Replies:** 4\
**Last updated:** [July 28, 2025, 1:52pm UTC](https://discuss.elastic.co/t/color-coding-bar-metric/380489 "2025-07-28T13:52:23Z")

</div>

Hey there. I am currently setting up a dashboard with some bar diagrams. It is possible to set different colors for entries. But is it also possible to have a wildcard in the selection? For example, having anything…

---

## [Pie Chart not showing Bytes](https://discuss.elastic.co/t/pie-chart-not-showing-bytes/380114)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 6\
**Last updated:** [July 28, 2025, 1:41pm UTC](https://discuss.elastic.co/t/pie-chart-not-showing-bytes/380114 "2025-07-28T13:41:22Z")

</div>

Hello, Is this a bug? I have a field with the values as bytes: But I want to display the data on the pie chart as bytes but I only get two options:

---

## [Csv reports timing out despite size of the report being too small](https://discuss.elastic.co/t/csv-reports-timing-out-despite-size-of-the-report-being-too-small/380384)

<div class="topic-metadata">

**Author:** [@Ananth\_Balasubramani](https://discuss.elastic.co/u/Ananth_Balasubramani)\
**Replies:** 2\
**Last updated:** [July 26, 2025, 1:09am UTC](https://discuss.elastic.co/t/csv-reports-timing-out-despite-size-of-the-report-being-too-small/380384 "2025-07-26T01:09:39Z")

</div>

Reporting job status doesn't seem to get updated with status as completed and times out with maximum of 3 attempts despite Kibana generating logs: finished generating, total size in bytes: , CSV: Worker completed: \<job\_i…

---

## [Best Way to Link Error Logs with Recommendations in Kibana?](https://discuss.elastic.co/t/best-way-to-link-error-logs-with-recommendations-in-kibana/380472)

<div class="topic-metadata">

**Author:** [@Amit\_Yaari](https://discuss.elastic.co/u/Amit_Yaari)\
**Replies:** 2\
**Last updated:** [July 25, 2025, 6:40pm UTC](https://discuss.elastic.co/t/best-way-to-link-error-logs-with-recommendations-in-kibana/380472 "2025-07-25T18:40:28Z")

</div>

Hi all, We’re planning a setup in Kibana where we want to link logs with relevant recommendations. Goal: When an error log is generated (e.g., "connection refused", "disk full", etc.), we want to show a matching recomm…

---

## [Why is the "Alert Delay of 5 Consecutive Matches" Not Being Met?](https://discuss.elastic.co/t/why-is-the-alert-delay-of-5-consecutive-matches-not-being-met/380439)

<div class="topic-metadata">

**Author:** [@Diego\_Ramirez](https://discuss.elastic.co/u/Diego_Ramirez)\
**Replies:** 1\
**Last updated:** [July 25, 2025, 12:59pm UTC](https://discuss.elastic.co/t/why-is-the-alert-delay-of-5-consecutive-matches-not-being-met/380439 "2025-07-25T12:59:50Z")

</div>

Here's the English paragraph with "CUSTOM\_ENTIDAD.keyword : "Redipro" and" removed from the query filter: Thread Title: Why is the "Alert Delay of 5 Consecutive Matches" Not Being Met for My Kibana Threshold Rule? Hel…

---

## [Kibana warning enabling TLS and using HTTP/2 while using NGINX](https://discuss.elastic.co/t/kibana-warning-enabling-tls-and-using-http-2-while-using-nginx/379432)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 7\
**Last updated:** [July 25, 2025, 7:44am UTC](https://discuss.elastic.co/t/kibana-warning-enabling-tls-and-using-http-2-while-using-nginx/379432 "2025-07-25T07:44:45Z")

</div>

Hi everyone, I'm using NGINX in my ELK Stack 9.0.1 self-managed instance and the Kibana (version 9.0.1) warns me about considering of enably TLS and using HTTP/2: Following the "Learn more" link, I should insert ins…

---

## [Custom log path for kibana service](https://discuss.elastic.co/t/custom-log-path-for-kibana-service/380397)

<div class="topic-metadata">

**Author:** [@venkat\_tammi](https://discuss.elastic.co/u/venkat_tammi)\
**Replies:** 3\
**Last updated:** [July 25, 2025, 3:45am UTC](https://discuss.elastic.co/t/custom-log-path-for-kibana-service/380397 "2025-07-25T03:45:30Z")

</div>

I do not see log path details in kibana.yml file, however, I added a value (logging.dest: /var/../log/kibana.log) and restarted the kibana service. Unfortunately, this kibana service didn't come up. I had to comment for …

---

## [Expecting 'EOF', got 'OPEN\_ENDBLOCK' when attempting to to set up APM in Fleet](https://discuss.elastic.co/t/expecting-eof-got-open-endblock-when-attempting-to-to-set-up-apm-in-fleet/380422)

<div class="topic-metadata">

**Author:** [@garetharmstrong](https://discuss.elastic.co/u/garetharmstrong)\
**Replies:** 1\
**Last updated:** [July 24, 2025, 7:01pm UTC](https://discuss.elastic.co/t/expecting-eof-got-open-endblock-when-attempting-to-to-set-up-apm-in-fleet/380422 "2025-07-24T19:01:42Z")

</div>

I'm trying to set up an APM Integration to work with my Fleet servers, and when I set up the Agent Policy as per the instructions, when I save, I get this error Error while compiling agent template: Parse error on line …

---

## [Getting mapper\_parsing\_exception error and field name cannot be an empty string in logstash](https://discuss.elastic.co/t/getting-mapper-parsing-exception-error-and-field-name-cannot-be-an-empty-string-in-logstash/380380)

<div class="topic-metadata">

**Author:** [@upreddy253](https://discuss.elastic.co/u/upreddy253)\
**Replies:** 3\
**Last updated:** [July 24, 2025, 12:37pm UTC](https://discuss.elastic.co/t/getting-mapper-parsing-exception-error-and-field-name-cannot-be-an-empty-string-in-logstash/380380 "2025-07-24T12:37:29Z")

</div>

Hi, We are trying to onboard new logs into elasticsearch but logs are not indexing into elasticsearch.Logs are apperar in Logstash deadletter queue with "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reas…

---

## [Issue with connecting to local llm from 8.18.0 ESv](https://discuss.elastic.co/t/issue-with-connecting-to-local-llm-from-8-18-0-esv/380086)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 11\
**Last updated:** [July 24, 2025, 4:19am UTC](https://discuss.elastic.co/t/issue-with-connecting-to-local-llm-from-8-18-0-esv/380086 "2025-07-24T04:19:14Z")

</div>

Hello Team, We are facing issues with connecting to our local LLM from Elasticsearch cluster of 8.18.0 version. While we are able to connect the same model Llama 3.2 3B Instruct to the 8.15.1 Elasticsearch. Getting the…

---

## [Problem rendering large log field due to performance reasons](https://discuss.elastic.co/t/problem-rendering-large-log-field-due-to-performance-reasons/380386)

<div class="topic-metadata">

**Author:** [@LukasGomez](https://discuss.elastic.co/u/LukasGomez)\
**Replies:** 0\
**Last updated:** [July 23, 2025, 1:41pm UTC](https://discuss.elastic.co/t/problem-rendering-large-log-field-due-to-performance-reasons/380386 "2025-07-23T13:41:19Z")

</div>

Hi! We're watching in Kibana some logs related with an exception of our service that show this "warning" when we try to check the message field of the log: "Rendering paused for long line for performance reasons. This ca…

---

## [Kibana,back button implementation process](https://discuss.elastic.co/t/kibana-back-button-implementation-process/380370)

<div class="topic-metadata">

**Author:** [@Mayuri\_Jaiswal](https://discuss.elastic.co/u/Mayuri_Jaiswal)\
**Replies:** 2\
**Last updated:** [July 23, 2025, 9:53am UTC](https://discuss.elastic.co/t/kibana-back-button-implementation-process/380370 "2025-07-23T09:53:46Z")

</div>

Hello,I am very new to kibana I want to make a back button in kibana dashboard. As i make many tables fields are filterable so if multiple filters are open so instead of crossing the filter that button when we click it,…

---

## [Duplicate Data Views, Recreate Discover Session](https://discuss.elastic.co/t/duplicate-data-views-recreate-discover-session/380313)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [July 22, 2025, 3:28pm UTC](https://discuss.elastic.co/t/duplicate-data-views-recreate-discover-session/380313 "2025-07-22T15:28:11Z")

</div>

Hello, I am working on shrinking spaces into one space in Elastic. I been able to move dashboards from different spaces into one space, the issue is that I have now duplicate data views. For example: So the simple …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=10)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=12)
