# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=143

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 144

---

## [Mapper\_parsing\_exception](https://discuss.elastic.co/t/mapper-parsing-exception/325962)

<div class="topic-metadata">

**Author:** [@Roshan\_M\_Thomas](https://discuss.elastic.co/u/Roshan_M_Thomas)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:04am UTC](https://discuss.elastic.co/t/mapper-parsing-exception/325962 "2023-02-20T11:04:53Z")

</div>

Hi , getting this error in elastic 7.8.1 and 8.0.0 while inserting mapping using PUT method. Please help us to resolve it. { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping …

---

## [How to store Key value pairs and visualize in Kibana?](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:14am UTC](https://discuss.elastic.co/t/how-to-store-key-value-pairs-and-visualize-in-kibana/325888 "2023-02-20T10:14:12Z")

</div>

Hi, I am trying to store key value pairs into Elasticsearch and visualize in Kibana. I am new to Elastic so sorry if the question is dumb. So here's my data { "mappings": { "properties": { "Topics": {"type…

---

## [How to check the index size on daily basis using python scripts?](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 9:48am UTC](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377 "2023-02-20T09:48:01Z")

</div>

Hi, Does anyone know how to check the index size on daily basis using python scripts?

---

## [Need help to create active directory alerts in Kibana](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102)

<div class="topic-metadata">

**Author:** [@abhi\_tcs](https://discuss.elastic.co/u/abhi_tcs)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:27am UTC](https://discuss.elastic.co/t/need-help-to-create-active-directory-alerts-in-kibana/325102 "2023-02-09T07:27:11Z")

</div>

Hello All, I am new to ELK stack. I need to create Active Directory related alerts in Kibana for below test cases. Can someone help me. Account lockout Account Disable Regards, AB

---

## [When Downloading CSV, one variable value's is getting in two different column because of comma](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 9:25am UTC](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984 "2023-02-20T09:25:07Z")

</div>

When Downloading CSV from Tabular format, each variable is getting separated with Comma (,). Due to this variable which are numerical values (for e.g., 2,946) are also getting in different columns. As shown in below ima…

---

## [Is it possible to configure SAML authentication in kibana 7.17 version without changing the elasticsearch.yml](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727)

<div class="topic-metadata">

**Author:** [@Vlada\_Homyakova](https://discuss.elastic.co/u/Vlada_Homyakova)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:57pm UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727 "2023-02-19T20:57:06Z")

</div>

Hi I'm trying to integrate kibana with okta saml, I try to get constantly FATAL Error: \[config validation of \[xpack.security\].authc.realm\]: Epexted a String but got an object xpack.security.authc.providers: - saml …

---

## [Joining two indexes](https://discuss.elastic.co/t/joining-two-indexes/325876)

<div class="topic-metadata">

**Author:** [@etp](https://discuss.elastic.co/u/etp)\
**Replies:** 2\
**Last updated:** [February 19, 2023, 2:57pm UTC](https://discuss.elastic.co/t/joining-two-indexes/325876 "2023-02-19T14:57:06Z")

</div>

Hi, I have two indices A and B. I wanted to perform inner join on the two indices using a common field such that I can collect the fields(spread across both indices) into another index using transforms. What aggregatio…

---

## [Alerting via email when new value is inserted](https://discuss.elastic.co/t/alerting-via-email-when-new-value-is-inserted/325890)

<div class="topic-metadata">

**Author:** [@camay123](https://discuss.elastic.co/u/camay123)\
**Replies:** 0\
**Last updated:** [February 18, 2023, 3:47pm UTC](https://discuss.elastic.co/t/alerting-via-email-when-new-value-is-inserted/325890 "2023-02-18T15:47:27Z")

</div>

Hello, I have some data that enters my elk stack every four hours. I want to be alerted by email when data is inserted and a specific field contains a never seen before value. I am wondering of this is possible and if…

---

## [Parse Date with RFC\_1123\_DATE\_TIME format](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:03pm UTC](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863 "2023-02-17T19:03:42Z")

</div>

Hi All, I'm ingesting documents to my ES cluster with a field called CREATION\_TIME with format Wed, 13 Oct 2021 13:04:54 GMT. I've tried to parse it using below mappings, but Kibana is still ignoring the value. { "p…

---

## [How do I sum the result of an aggregation and present it in a table?](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 6\
**Last updated:** [February 17, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352 "2023-02-17T18:28:23Z")

</div>

I would like to take the results of this query, namely the values: 3683 3676 3574 3530 3706 3695 3663 3530 3586 3567 Sum them together, which would give: 36210, and display them in a table. I can't seem to …

---

## [Index/alias Filter(s)](https://discuss.elastic.co/t/index-alias-filter-s/325851)

<div class="topic-metadata">

**Author:** [@Talvaro](https://discuss.elastic.co/u/Talvaro)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 5:52pm UTC](https://discuss.elastic.co/t/index-alias-filter-s/325851 "2023-02-17T17:52:59Z")

</div>

I'm researching an issue with a existing application I just got as responsible. I am not too familiar with Elastic/Kibana. The issue is the application reading docs from an Alias is not getting all expected results. I no…

---

## [Filter working in "Discover" field, but the same filter in Dashboard/lense does not](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395)

<div class="topic-metadata">

**Author:** [@JCW](https://discuss.elastic.co/u/JCW)\
**Replies:** 7\
**Last updated:** [February 17, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395 "2023-02-17T13:33:46Z")

</div>

I'm using a tags - is - snort filter, on the discover tab it shows 5 hits in the last hour. I have a visualisation, that used the same index pattern etc, with the same filter and timeframe (tags - is - snort) which does…

---

## [Dashboards not showing in custom kibana space](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420 "2023-02-17T07:07:40Z")

</div>

I have created a two space in kibana one for production which is default space and second is for staging. on my production space all indexes are showing into it but on my staging space there is only staging index is show…

---

## [Vega: Set a text for empty data set](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325807)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:58am UTC](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325807 "2023-02-17T03:58:21Z")

</div>

Actually my condition same with this thread but when I try, it doesn't work for me. I did the filter transform and when there's no rows that shown after the transform, I want to make a static text to inform that.

---

## [Lens: changing rows in table](https://discuss.elastic.co/t/lens-changing-rows-in-table/324622)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 9:06pm UTC](https://discuss.elastic.co/t/lens-changing-rows-in-table/324622 "2023-02-16T21:06:49Z")

</div>

Hi there, created the following table in Kibana lens: Is it possible to view all metric1 entries where metric2 and vice versa? I tried to put it in a different metrics field,but the result was the same. I remember…

---

## [Kibana error - can't start due to error (problem with ES)](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409)

<div class="topic-metadata">

**Author:** [@Blazej\_Makula](https://discuss.elastic.co/u/Blazej_Makula)\
**Replies:** 5\
**Last updated:** [February 16, 2023, 8:47pm UTC](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409 "2023-02-16T20:47:58Z")

</div>

Hello, can you please help me with my home lab log collection system. I have two hosts one with logstash + elasticsearch + kibana and the other with logstash + elasticsearch. I want to connect kibana to both ES cluster…

---

## [Automatically closing indices older than x days using ILP](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 8:21pm UTC](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765 "2023-02-16T20:21:17Z")

</div>

I was wondering if it is possible to configure a lifecycle policy so that nodes older than 300 days are automatically closing? I would like to know if I am on the right way or am I really trying something that I will nev…

---

## [Compare 2 days Data and conditional formatting](https://discuss.elastic.co/t/compare-2-days-data-and-conditional-formatting/324860)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 5:25pm UTC](https://discuss.elastic.co/t/compare-2-days-data-and-conditional-formatting/324860 "2023-02-16T17:25:48Z")

</div>

Hi, I am new to Kibana, I have a requirement to compare 2 days of data and create visualization. (Kibana Version 7.10) Day 1 Data Nam Col1 Col2 AAA 500 600 BBB 700 800 Day 2 Data Nam Col1 Col2 AAA…

---

## [Maps visualization can't recognize geospatial field](https://discuss.elastic.co/t/maps-visualization-cant-recognize-geospatial-field/325103)

<div class="topic-metadata">

**Author:** [@Evgenii\_X](https://discuss.elastic.co/u/Evgenii_X)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:27am UTC](https://discuss.elastic.co/t/maps-visualization-cant-recognize-geospatial-field/325103 "2023-02-09T07:27:39Z")

</div>

Maps visualization can't recognize geospatial (geo\_point ) field (source.geo.location). Field source.geo.location having type geo\_point, is searchable and aggregatable. Trying to check everything according to: T…

---

## [How to define multiple keys in index (Y Axis) to sort by clicks against date (X Axis)](https://discuss.elastic.co/t/how-to-define-multiple-keys-in-index-y-axis-to-sort-by-clicks-against-date-x-axis/325323)

<div class="topic-metadata">

**Author:** [@Sahil\_Sharma1](https://discuss.elastic.co/u/Sahil_Sharma1)\
**Replies:** 0\
**Last updated:** [February 11, 2023, 7:04pm UTC](https://discuss.elastic.co/t/how-to-define-multiple-keys-in-index-y-axis-to-sort-by-clicks-against-date-x-axis/325323 "2023-02-11T19:04:44Z")

</div>

Hi, I have an issue with kibana dashboards. I want multiple fields in index (Entity1.keyword, Entity2.keyword and Entity3.keyword) to be sorted by max clicks against date. Entities will be in Y axis and Date will in …

---

## [Change how Kibana interprets dates as datetimes](https://discuss.elastic.co/t/change-how-kibana-interprets-dates-as-datetimes/325616)

<div class="topic-metadata">

**Author:** [@catrexis](https://discuss.elastic.co/u/catrexis)\
**Replies:** 6\
**Last updated:** [February 16, 2023, 2:17pm UTC](https://discuss.elastic.co/t/change-how-kibana-interprets-dates-as-datetimes/325616 "2023-02-16T14:17:44Z")

</div>

One of my indices uses a date (yyyy-MM-dd) instead of a datetime as timstamp-field. Kibana interprets that as a datetime, by setting the time to 01:00. As the document contains data of the whole day, I would like to set …

---

## [Elasticsearch cluster automatically adds transient settings...How do I remove this?](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353)

<div class="topic-metadata">

**Author:** [@prabhash\_mohanty](https://discuss.elastic.co/u/prabhash_mohanty)\
**Replies:** 4\
**Last updated:** [February 16, 2023, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353 "2023-02-16T06:27:29Z")

</div>

I have 2 nodes in the cluster log-es-default-0 and log-es-default-1. log-es-default-0 - master node log-es-default-1 - data node I tried running the below command but it still adds it. PUT /\_cluster/settings?pretty {…

---

## [Missing setting option "response.include\_body\_max\_bytes" in "Add Elastic Synthetics integration" UI](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444)

<div class="topic-metadata">

**Author:** [@billhong-just](https://discuss.elastic.co/u/billhong-just)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 1:24am UTC](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444 "2023-02-16T01:24:03Z")

</div>

Description In Kibana v8.5.3's dashboard, I can't find the setting option response.include\_body\_max\_bytes to control the maximum size of the stored body contents. Is this a bug or is it by design? :thinking: Refer…

---

## [Kibana alerts](https://discuss.elastic.co/t/kibana-alerts/325570)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:41pm UTC](https://discuss.elastic.co/t/kibana-alerts/325570 "2023-02-15T21:41:00Z")

</div>

Hi team, I have installed elastisearch and kibana 8.5.1 throgh helm on cluster, now i tried to configure the alerts on kibana. So inside kibana pod kibana.yaml, In the kibana.yml configuration file, add the xpack.encryp…

---

## [Getting 403 code while connecting to elastic](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615)

<div class="topic-metadata">

**Author:** [@fvtarnovskiy](https://discuss.elastic.co/u/fvtarnovskiy)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:32pm UTC](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615 "2023-02-15T21:32:05Z")

</div>

Hello! We are a cloud provider from Uzbekistan pro-data.tech (https://pro-data.tech/). Please help in solving the problem - when trying to access Elastic, we get an error code 403 from all our addresses (95.47.127.0/24…

---

## [Kibana does not recognize the @timestamp field as a time filter](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404)

<div class="topic-metadata">

**Author:** [@Alvik173](https://discuss.elastic.co/u/Alvik173)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 9:27pm UTC](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404 "2023-02-15T21:27:07Z")

</div>

Kibana (7.17.8) does not seem to recognize the @timestamp field in my index as a time field. The symptoms are as follows. In Discover, the "Show dates" box on the top right is missing The time series chart above the D…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665 "2023-02-15T21:07:06Z")

</div>

Hi All, Please am new to Dsiem. I have just clone it from github and running it on ubuntu, below is the error am getting. "Kibana server is not ready yet" see the logs below, can I get help with this please {"type":"…

---

## [Connect kibana to Elasticsearch after changes made](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 16\
**Last updated:** [February 15, 2023, 4:00pm UTC](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518 "2023-02-15T16:00:15Z")

</div>

Hello! My kibana doesnt talk to Elasticsearch after changes are made in elasticsearch config Some history: installed ELK on one host and filebeat on another one. Started elasticsearch, started kibana, started logsta…

---

## [Elasticsearch sort returns incorrect results?](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512)

<div class="topic-metadata">

**Author:** [@Fatih\_Erol1](https://discuss.elastic.co/u/Fatih_Erol1)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512 "2023-02-15T15:40:18Z")

</div>

Why elasticsearch sort returns incorrect results? Mappings { "mappings": { "\_doc": { "properties": { "name": { "type": "keyword", "fields": { "sort": { …

---

## [Bar horizontal percentage chart from boolean](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 2:52pm UTC](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619 "2023-02-15T14:52:48Z")

</div>

I am retrieving a boolean field from my logs. Now i want to show this field as horizontal bar in percent with two colors green for true and red for false. It would be great if there was one bar showing the percentage of …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=142)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=144)
