# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=117

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 118

---

## [Problem "filter on maximum of timestamp"](https://discuss.elastic.co/t/problem-filter-on-maximum-of-timestamp/335518)

<div class="topic-metadata">

**Author:** [@elteraxya](https://discuss.elastic.co/u/elteraxya)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 9:37am UTC](https://discuss.elastic.co/t/problem-filter-on-maximum-of-timestamp/335518 "2023-06-08T09:37:45Z")

</div>

Hello everyone, I'd like to tell you about my problem. I have data coming up every day with logstash on my kibana, this data comes up either "ok" or "other" in a "status" field with the @timestamp of the day. I'd like t…

---

## [Kibana User Experience - Not showing on on Observability Overview](https://discuss.elastic.co/t/kibana-user-experience-not-showing-on-on-observability-overview/335462)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 6:23pm UTC](https://discuss.elastic.co/t/kibana-user-experience-not-showing-on-on-observability-overview/335462 "2023-06-07T18:23:28Z")

</div>

Is there a simple reason why the User Experience Metrics does not show on the Observability Overview, but does when clicking on it from the sidebar ?

---

## [Select data based on timestamp](https://discuss.elastic.co/t/select-data-based-on-timestamp/335496)

<div class="topic-metadata">

**Author:** [@laurijssen](https://discuss.elastic.co/u/laurijssen)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 9:22am UTC](https://discuss.elastic.co/t/select-data-based-on-timestamp/335496 "2023-06-08T09:22:34Z")

</div>

Im trying to select data in a timestamp range (plus somie more criteria: @timestamp: \[ "2023-06-07T:07:00:00" TO "2023-06-07T09:00:00" \] but this gives the error: Expected AND, OR, end of input, whitespace but """ fou…

---

## [Set time range filter to drill-down target from Vega panel](https://discuss.elastic.co/t/set-time-range-filter-to-drill-down-target-from-vega-panel/333805)

<div class="topic-metadata">

**Author:** [@rowish](https://discuss.elastic.co/u/rowish)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 7:17am UTC](https://discuss.elastic.co/t/set-time-range-filter-to-drill-down-target-from-vega-panel/333805 "2023-06-08T07:17:14Z")

</div>

Hello community, I am trying to implement a drill-down functionality to my Vega panel able to send, alongside a manually set query filter, the time range inherited from my origin dashboard. The version that I was able …

---

## [Elements Rotation (Arrow) based on Conditions in Canvas (ELK Stack)](https://discuss.elastic.co/t/elements-rotation-arrow-based-on-conditions-in-canvas-elk-stack/335183)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 6\
**Last updated:** [June 8, 2023, 6:33am UTC](https://discuss.elastic.co/t/elements-rotation-arrow-based-on-conditions-in-canvas-elk-stack/335183 "2023-06-08T06:33:33Z")

</div>

How do I rotate an arrow based on certain conditions in Canvas? I just want to integrate the CSS rotate function based on certain conditions. Can anyone suggest what functions we should use to rotate the axis? Below is …

---

## [Enhanced table plugin on elastic cloud](https://discuss.elastic.co/t/enhanced-table-plugin-on-elastic-cloud/335214)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 5:45am UTC](https://discuss.elastic.co/t/enhanced-table-plugin-on-elastic-cloud/335214 "2023-06-08T05:45:48Z")

</div>

Hello Elastic Team, I've a request or guidance required .Its important as its causing major isssue now for our usecases. We show statistical data in tables. The data is of following type: 1)Hyperlinks-\>ONCLICK downloa…

---

## [Unable to enrich document](https://discuss.elastic.co/t/unable-to-enrich-document/335492)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:30am UTC](https://discuss.elastic.co/t/unable-to-enrich-document/335492 "2023-06-08T03:30:32Z")

</div>

Hi All, I have created an kibana alert which is ingesting the document to a index. I have set a default pipeline to that index but when i see the documents ingested from kibana alerts it doesn't have the enrich fields. …

---

## [Error during restore snapshot "but system indices can only be restored as part of a feature state"](https://discuss.elastic.co/t/error-during-restore-snapshot-but-system-indices-can-only-be-restored-as-part-of-a-feature-state/335489)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 2:32am UTC](https://discuss.elastic.co/t/error-during-restore-snapshot-but-system-indices-can-only-be-restored-as-part-of-a-feature-state/335489 "2023-06-08T02:32:33Z")

</div>

Hi guys i encountered some error during my restore snapshot. All begin when i check my cluster health there is unassigned shard after i check it. it was .kibana\_alerting\_cases\_8.8.0\_001 and i tried to get information us…

---

## [Set Kibana Memory](https://discuss.elastic.co/t/set-kibana-memory/335472)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 4\
**Last updated:** [June 7, 2023, 7:54pm UTC](https://discuss.elastic.co/t/set-kibana-memory/335472 "2023-06-07T19:54:57Z")

</div>

in kibana 7.17.7, How I can set the Memory for kibana, I edited node.options and set to --max-old-space-size=8192 but when i go "stack monitoring", i found that kibana still showing under "Memory Usage :1.9 GB / 4.0 GB"

---

## [Drop old values from group by in metric threshold rule](https://discuss.elastic.co/t/drop-old-values-from-group-by-in-metric-threshold-rule/335456)

<div class="topic-metadata">

**Author:** [@mgordon](https://discuss.elastic.co/u/mgordon)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 5:58pm UTC](https://discuss.elastic.co/t/drop-old-values-from-group-by-in-metric-threshold-rule/335456 "2023-06-07T17:58:08Z")

</div>

I have a metric threshold rule that's grouped by two values (server and app pool name). When I permanently remove an app pool from a server, how do I 'refresh' the values so that one stops alerting that it's missing?

---

## [How can I delete documents 3 months older?](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [June 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351 "2023-06-07T13:41:09Z")

</div>

I have Elasticsearch and Kibana 8.6 and I have an index with a size of 115GB. I would like to query by @timestamp and delete documents older than April 1, 2023. How can I do that? I am new to the query part and not sure …

---

## [How can I increase the JVM via API or CLI](https://discuss.elastic.co/t/how-can-i-increase-the-jvm-via-api-or-cli/335443)

<div class="topic-metadata">

**Author:** [@c.j.t](https://discuss.elastic.co/u/c.j.t)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 1:27pm UTC](https://discuss.elastic.co/t/how-can-i-increase-the-jvm-via-api-or-cli/335443 "2023-06-07T13:27:12Z")

</div>

I've an instance on AWS Opensearch Service that is has a circuit breaking exception, from reading I think increasing the jvm should work but all the examples seem to tell me to edit the yml - which I can't do - I can use…

---

## [Timeout on Kibana](https://discuss.elastic.co/t/timeout-on-kibana/334444)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 8\
**Last updated:** [June 7, 2023, 12:01pm UTC](https://discuss.elastic.co/t/timeout-on-kibana/334444 "2023-06-07T12:01:00Z")

</div>

Hello, Getting this error on Kibana graph is I select the period higher than 5 days (probably too many datapoints): Tried increasing elasticsearch.requestTimeout: 900000 (and restarted kibana service) but this messa…

---

## [Rerunning markdown in intervals](https://discuss.elastic.co/t/rerunning-markdown-in-intervals/335345)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 11:33am UTC](https://discuss.elastic.co/t/rerunning-markdown-in-intervals/335345 "2023-06-07T11:33:08Z")

</div>

Hi everyone, So I've been trying to get Kibana to load up images on dashboard right now. What I did is basically create a python api for Markdown in Kibana to get url to image to put on dashboard. Anyways, what happen…

---

## [Vega visualization](https://discuss.elastic.co/t/vega-visualization/335334)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 10:46am UTC](https://discuss.elastic.co/t/vega-visualization/335334 "2023-06-07T10:46:01Z")

</div>

Hello, I am trying to display records from a document in a table, horizontally, by using vega. I have this: retrieves data from index pattern users-\*, and displays the userName and the manager { "$schema": "https://…

---

## [Adding Lookup field to Kibana dataview](https://discuss.elastic.co/t/adding-lookup-field-to-kibana-dataview/335389)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 9:44am UTC](https://discuss.elastic.co/t/adding-lookup-field-to-kibana-dataview/335389 "2023-06-07T09:44:22Z")

</div>

I have a data-view build using a transaction details index , I am showing transaction details which also has customer id , Can I also add lookup field to get customer name from customer index on the basis of customer id …

---

## [Unable to see the "Available fields column" in the logs forwarding for Devbyok cluster](https://discuss.elastic.co/t/unable-to-see-the-available-fields-column-in-the-logs-forwarding-for-devbyok-cluster/334807)

<div class="topic-metadata">

**Author:** [@subagh](https://discuss.elastic.co/u/subagh)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:15pm UTC](https://discuss.elastic.co/t/unable-to-see-the-available-fields-column-in-the-logs-forwarding-for-devbyok-cluster/334807 "2023-06-06T22:15:09Z")

</div>

Pic 1 - Does not shows any available fields in Dashboard Can anyone please tell me why I cannot see the relevant "string fields" tab to select options from DevByok cluster but with similar configuration, I am able to se…

---

## [Displaying Latest Image with filter from Log Message](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 11:19am UTC](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160 "2023-06-06T11:19:25Z")

</div>

Hi everyone. So currently, I'm getting logs from various services. I manage to tag these services as a field when it's ingested into elasticsearch via logstash. I'm currently stump with one part where i'm trying to disp…

---

## [How to search a value by special character](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 17\
**Last updated:** [June 6, 2023, 11:17am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611 "2023-06-06T11:17:22Z")

</div>

Hi there, so i have a field named uri\_api and some of them have a value like this: /scrt/kpi/v3/code/shean%20jeremy%20patok i want to search other value like that in uri\_api field. how can i achieve it? i already try …

---

## [Hide the time filter in dashboards](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 11:08am UTC](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321 "2023-06-06T11:08:51Z")

</div>

Hello, I have an index pattern for which I did not set a time field. I created a visualization based on this pattern index, and added it to a dashboard. In the dashboard I still have the time picker. How can I make it…

---

## [Kibana Version in Hindi Language](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 10:59am UTC](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277 "2023-06-06T10:59:51Z")

</div>

Hi all, I want a Kibana version in Hindi language that can display everything in Hindi including Dashboard name, visualization Name, options etc. Any setting for language or Kibana version for Hindi language that I can…

---

## [Kibana TSVB - Percentage of Samples crossing Threshold Filter Ratio Always Returning 0 for one Index](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988)

<div class="topic-metadata">

**Author:** [@shgpde](https://discuss.elastic.co/u/shgpde)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988 "2023-06-06T10:55:38Z")

</div>

Hi, First time poster, I'm having difficulty getting the data I want from a Kibana visualisation and I'm hoping for some insight. I'm using Kibana v7.6.1 and have been running into an issue trying to use a Filter Ratio…

---

## [Show HTML Character Entities as symbols in Kibana](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:43am UTC](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191 "2023-06-06T10:43:38Z")

</div>

Hi, I have records in ES where symbols are presented as Character Entities. For example | as &#124; and a record could looks like bla&#124;bla&#124;bla. Is it posible in Kibana to show these entities as symbols, i.e. b…

---

## [Role based Access in Kibana](https://discuss.elastic.co/t/role-based-access-in-kibana/335218)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:23am UTC](https://discuss.elastic.co/t/role-based-access-in-kibana/335218 "2023-06-06T10:23:31Z")

</div>

Hi I have a use case where based on Role user should be able to see only selected Indices for example compliance auditors should be able to see only compliance indices , they should not be able to see any other indices…

---

## [Kibana cluster acces via F5 load balancer](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285)

<div class="topic-metadata">

**Author:** [@kannan2096](https://discuss.elastic.co/u/kannan2096)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285 "2023-06-06T09:31:18Z")

</div>

Hi I'm new to ELK and I'm doing POC to implement ELK with cluster setup. With the basic cluster configuration of Elasticsearch(2nodes), the Kibana GUI working fine. But via F5 load balance URL it is not working. The log…

---

## [Kibana support for System for Cross-Domain Identity Management (SCIM)](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930)

<div class="topic-metadata">

**Author:** [@sivanov](https://discuss.elastic.co/u/sivanov)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930 "2023-06-06T08:44:22Z")

</div>

Hi, Does Kibana / Elastic Stack support SCIM for identity providers like Microsoft (Azure/AD)? There is no documentation available on the topic. A short info on SCIM systems: SCIM synchronization with Azure Active Dir…

---

## [TSVB - Top N - Item URL: keep time interval when link to other dashboard](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 7:04am UTC](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151 "2023-06-06T07:04:29Z")

</div>

Hi, This is a duplicate of this thread which was not answered. I have TSVB top n visualization of host names and i'm using item URL feature to drilldown to more specific dashboard with the {{key}} place holder. However…

---

## [Failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\]](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099)

<div class="topic-metadata">

**Author:** [@gustavo6](https://discuss.elastic.co/u/gustavo6)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:26pm UTC](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099 "2023-06-02T15:26:43Z")

</div>

Hi! I'm getting this error: \[essql\] \> Unexpected error from Elasticsearch: illegal\_argument\_exception - failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\] on this quer…

---

## [How to use mapper size pluging?](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131 "2023-06-06T05:12:24Z")

</div>

Hi folks I want to find the largest documents in my indices and I have installed the mapper size plugin and added the field to index as it explained I have two questions now how to add it to index pattern in kibana? …

---

## [Enable CORS on Kibana](https://discuss.elastic.co/t/enable-cors-on-kibana/334084)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Jain](https://discuss.elastic.co/u/Shreyansh_Jain)\
**Replies:** 12\
**Last updated:** [June 6, 2023, 4:33am UTC](https://discuss.elastic.co/t/enable-cors-on-kibana/334084 "2023-06-06T04:33:58Z")

</div>

Hi all, I am using kibana version v 7.17.9 I am trying to use this api endpoint to generate cookies in my front end angular application : "/internal/security/login". But while making a post call from my web application…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=116)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=118)
