# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=126

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 127

---

## [Vega-Lite in Kibana visualization problem](https://discuss.elastic.co/t/vega-lite-in-kibana-visualization-problem/330711)

<div class="topic-metadata">

**Author:** [@martinez06](https://discuss.elastic.co/u/martinez06)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 6:12pm UTC](https://discuss.elastic.co/t/vega-lite-in-kibana-visualization-problem/330711 "2023-04-26T18:12:29Z")

</div>

Hi, Im trying to create a custom vizualization using Vega-Lite in Kibana. I have the source data: syslog\_ip\_address, syslog\_url,syslog\_status. For each ip address i check status of three url and i want to visualise it …

---

## [Descargar CSV con la búsqueda desde un dashboard](https://discuss.elastic.co/t/descargar-csv-con-la-busqueda-desde-un-dashboard/330706)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 5:40pm UTC](https://discuss.elastic.co/t/descargar-csv-con-la-busqueda-desde-un-dashboard/330706 "2023-04-26T17:40:08Z")

</div>

Buenos días, He creado un dashboard añadiendo una visualización con la búsqueda de un discover. He configurado un rol con permisos de lectura al dashboard y aplicado a un usuario. El problema es que cuando hago una bús…

---

## [Markdown only clickable in a small region at the bottom of the image](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684 "2023-04-26T14:54:00Z")

</div>

I have upgraded to version 8.7, but still experience an issue that should have been fix as follows: \[Dashboard\] Add styling to allow clickable TSVB markdown images by Heenawter · Pull Request #147802 · elastic/kibana · G…

---

## [Fuzzy Search Query using KQL or Lucene](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:14pm UTC](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575 "2023-04-26T14:14:22Z")

</div>

I'm trying to find documents where the host.os.platform field has some words similar to host.os.name for example I want to use Kibana discover either Lucene or KQL for that. This is what I came up with : host.os.plat…

---

## [Elastic agent Does not receive traffic, but it reaches the Linux server](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100)

<div class="topic-metadata">

**Author:** [@Razovnyik](https://discuss.elastic.co/u/Razovnyik)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 2:09pm UTC](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100 "2023-04-26T14:09:40Z")

</div>

Elasticsearch is configured with a Palo Alto Integration a corresponding Agent Policy and Agent. The Agent itself is installed on an Ubuntu Linux machine: The Ubuntu machine itself receives the traffic: But the …

---

## [Monitoring data streams](https://discuss.elastic.co/t/monitoring-data-streams/330759)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [April 26, 2023, 12:57pm UTC](https://discuss.elastic.co/t/monitoring-data-streams/330759 "2023-04-26T12:57:18Z")

</div>

Hi, I started to use data streams in my ELK stack. However, I can't see proper data regarding to the indexing rate. "Elasticsearch overview" shows a 20/s indexing rate, and I can't see the backing indices in the "Indice…

---

## [Number format for mustache](https://discuss.elastic.co/t/number-format-for-mustache/330783)

<div class="topic-metadata">

**Author:** [@phong\_elastic](https://discuss.elastic.co/u/phong_elastic)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/number-format-for-mustache/330783 "2023-04-26T12:54:00Z")

</div>

Hello everyone. I'm trying to separate the value of a mustache value in the field to index in Elasticsearch Query Alert by thousands. For example the {{ timeresponse}} has a value of 2500000 but now I want to change it …

---

## [Kibana dashboard filter doesn't work](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675)

<div class="topic-metadata">

**Author:** [@tonyaw](https://discuss.elastic.co/u/tonyaw)\
**Replies:** 10\
**Last updated:** [April 26, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675 "2023-04-26T05:44:25Z")

</div>

I created a Kibana dashboard contains a Lens visualization. I'm trying to use filter to get data for "cluster\_id == 77" OR "cluster\_id==80", But what Lens shows is cluster\_id == from 77 to 80. Could you please help to …

---

## [Want to use shorten URL functionality of Kibana to generate id of dashboard](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648)

<div class="topic-metadata">

**Author:** [@aman\_giri](https://discuss.elastic.co/u/aman_giri)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:02pm UTC](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648 "2023-04-25T23:02:33Z")

</div>

Hello, everyone I have this public URL that I want to show publicly but it has multiple parameters that can be seen in the URL so I wanted to be short . I was going through Shorten URL | Kibana User Guide \[6.7\] | Elast…

---

## [Kibana connection without enrollment token](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 2:58pm UTC](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728 "2023-04-25T14:58:07Z")

</div>

Can we connect to elasticsearch using Kibana without the enrollment token and username-password? I tried sometime back, then it was not mandatory to provide enrollment token. Even tried setting xpack.security.enrollmen…

---

## [Kibana Table - Cell Text gets truncated](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 8\
**Last updated:** [April 25, 2023, 2:12pm UTC](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407 "2023-04-25T14:12:09Z")

</div>

Hi Elastic Gurus, I have created a table in Kibana Dashboard and some cells have large amount of text. Is there a text wrap functionality or ability to resize the cell so that we can view the full data without get trim…

---

## [Inspect raw JSON source data from Vega/Elasticsearch](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629)

<div class="topic-metadata">

**Author:** [@peppar](https://discuss.elastic.co/u/peppar)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629 "2023-04-25T07:58:59Z")

</div>

I'm trying to create advanced visualizations with Vega, but I'm having the hardest time guessing the dataset names. I'm fetching my data as such: { "$schema": "https://vega.github.io/schema/vega/v4.json", "descripti…

---

## [Average of sum(value)](https://discuss.elastic.co/t/average-of-sum-value/330685)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 9:09pm UTC](https://discuss.elastic.co/t/average-of-sum-value/330685 "2023-04-24T21:09:50Z")

</div>

I am running a ingestion and records comes every 15 min one of the field is integer #user value might be 1, 2,3 or what ever. what I am trying to do is average of sum ( users) per hour for example rec1 - 10:00am { …

---

## [Kibana Authentification](https://discuss.elastic.co/t/kibana-authentification/330243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-authentification/330243 "2023-04-24T18:27:00Z")

</div>

Hi, I'have a problem to authentificating Kibana on Elastic . After generating a token on Elastic, Kibana is block on "Server is not ready yet" I have two different IP on each server and they ping each other Changes i…

---

## [Different filters for different visualizations inside the same dashboard](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208 "2023-04-24T11:21:13Z")

</div>

Hi! I'm building a dashboard that has two visualizations, each of them taking data from different indexes. I want to apply a filter (that can be edited on the dashboard to show different data), but as the data comes fro…

---

## [ECK Anonymous user concatenation of privileges](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617)

<div class="topic-metadata">

**Author:** [@Patrick\_Bardo](https://discuss.elastic.co/u/Patrick_Bardo)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 9:07am UTC](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617 "2023-04-24T09:07:09Z")

</div>

We are using ECK operator v2.6.1 and Elastic and Kibana v8.6.2. We would like to enable anonymous access of kibana to our users, and have this user be authenticated with elasticsearch to have certain limited permissions.…

---

## [Reporting Diagnostics tool fails on capture screenshot](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 10:59pm UTC](https://discuss.elastic.co/t/reporting-diagnostics-tool-fails-on-capture-screenshot/330080 "2023-04-23T22:59:32Z")

</div>

I ran the Reporting Diagnostics tool and after sometime, the following error is displayed: Something isn't working properly. There was a problem running the diagnostic: Error For additional debugging information, I …

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/330580 "2023-04-23T13:21:01Z")

</div>

There are a few posts noting this error message, without a solution. In case somebody stumbles upon it : This message may be very misleading, in case you did not activate xpack security First, check your service logs…

---

## [Failed to start kibana.service - Kibana](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630)

<div class="topic-metadata">

**Author:** [@Afif\_Haziq](https://discuss.elastic.co/u/Afif_Haziq)\
**Replies:** 4\
**Last updated:** [April 23, 2023, 5:14pm UTC](https://discuss.elastic.co/t/failed-to-start-kibana-service-kibana/329630 "2023-04-23T17:14:41Z")

</div>

Hi, im newbie so im not quite sure what im currently doing. few hours ago ive configured the kibana server. after i reopened the kali purple in my virtualbox the kibana server failed to start and i dont know what and how…

---

## [Random fields in "Available fields" in Kibana discover](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498)

<div class="topic-metadata">

**Author:** [@rkelastic](https://discuss.elastic.co/u/rkelastic)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 12:16pm UTC](https://discuss.elastic.co/t/random-fields-in-available-fields-in-kibana-discover/330498 "2023-04-23T12:16:40Z")

</div>

I am using a filebeat instance to read data from azure blob storage and see the visualisation in kibana. In Discover tab in kibana, under the "Available fields" section, it is showing list of fields which are not there …

---

## [Kibana tries to connect to 169.254.169.254:80](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 19\
**Last updated:** [April 23, 2023, 7:43am UTC](https://discuss.elastic.co/t/kibana-tries-to-connect-to-169-254-169-254-80/327353 "2023-04-23T07:43:51Z")

</div>

Hello elastic community, any idea why Kibana tries to connect to 169.254.169.254:80 for first 5-6 minutes after I start it? I noticed this with version 7.17.9, but I think it was like this at least for all 7.17.X versi…

---

## [Visualize count of messages for a specific key (ID) within a time window](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545)

<div class="topic-metadata">

**Author:** [@Florian\_Braun](https://discuss.elastic.co/u/Florian_Braun)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:08pm UTC](https://discuss.elastic.co/t/visualize-count-of-messages-for-a-specific-key-id-within-a-time-window/330545 "2023-04-21T22:08:37Z")

</div>

In my dataset I get a large amount of messages, each providing an update to an object with a unique ID. What I would like to visualize is how frequent these updates are for each unique ID, more specifically, how often d…

---

## [Sysmon events not getting into the SOC and kibana](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-into-the-soc-and-kibana/330543 "2023-04-21T21:16:30Z")

</div>

Hi, I have been trying to get my sysmon events to show up in kibana. Does anyone know if there is a debugging check list that I could follow? I uninstalled and sysmon and winlogbeat. I went into the sysmon.yml and I se…

---

## [Enhanced data table-Add image and on click it should download the log/excel file](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 8:02pm UTC](https://discuss.elastic.co/t/enhanced-data-table-add-image-and-on-click-it-should-download-the-log-excel-file/330315 "2023-04-21T20:02:18Z")

</div>

Hello @fbaligand , 1)Could you plz let me know if its possible to add image instead of hyperlink to download something? In below image i have achived this through using enhanced table and as per my requirement my inten…

---

## [PDF From Watcher is returning blank visualizations](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539)

<div class="topic-metadata">

**Author:** [@swhittenburg](https://discuss.elastic.co/u/swhittenburg)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:52pm UTC](https://discuss.elastic.co/t/pdf-from-watcher-is-returning-blank-visualizations/330539 "2023-04-21T16:52:25Z")

</div>

I set up a custom watcher to send me an email of a pdf of a dashboard every x minutes. I had it set to 5 minutes and the pdf would send correctly a couple times and then would be blank, then would be fine again. I'm assu…

---

## [How to delete a runtime field?](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-delete-a-runtime-field/330526 "2023-04-21T16:47:04Z")

</div>

I am trying to use runtime fields instead of scripted fields and have created one, which I no longer need. Is there any API or from GUI I can delete the runtime fields ?

---

## [Cross index kibana dashboard](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:46pm UTC](https://discuss.elastic.co/t/cross-index-kibana-dashboard/330538 "2023-04-21T16:46:01Z")

</div>

Hello, I am trying to build a dashboard that pulls information from multiple indices. While both indices have the same data, the formatting is different, for example: On index logstash, i have the property resourceId,…

---

## [Canvas add grid lines to graph](https://discuss.elastic.co/t/canvas-add-grid-lines-to-graph/330537)

<div class="topic-metadata">

**Author:** [@goofinator](https://discuss.elastic.co/u/goofinator)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/canvas-add-grid-lines-to-graph/330537 "2023-04-21T16:21:02Z")

</div>

Hello iam trying to add some simple x and y grid lines to my line graph.. I cant find any examples on how to do that. Could anyone please assist me in how i can add them Thanks David

---

## [Permanent filter](https://discuss.elastic.co/t/permanent-filter/330370)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 3\
**Last updated:** [April 21, 2023, 1:08pm UTC](https://discuss.elastic.co/t/permanent-filter/330370 "2023-04-21T13:08:53Z")

</div>

Is there a way to make a "permanent filter" or make a filter non-removable? The reason for this is, I want the user to only see data relevant to their company. If they simply removed the filter, they would be able to vi…

---

## [How to have an array that pulls up linux commands](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116)

<div class="topic-metadata">

**Author:** [@Wad1636](https://discuss.elastic.co/u/Wad1636)\
**Replies:** 6\
**Last updated:** [April 21, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-to-have-an-array-that-pulls-up-linux-commands/330116 "2023-04-21T13:06:34Z")

</div>

Good morning, I would like to have a reassembly of the commands type on linux live and put them in a table, the problem I can't already find how to reassemble the commands. Thanks for your future help.

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=125)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=127)
