# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=144

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 145

---

## [Kibana does not log all lines as json](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:36pm UTC](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627 "2023-02-15T14:36:24Z")

</div>

I have Kibana deployed as an ECK resource. Despite the following config: config: logging: appenders: json-layout: type: console layout: type: json root: appenders: \[json-…

---

## [Designing a visualisation for success/failure of processes](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634)

<div class="topic-metadata">

**Author:** [@PetervH](https://discuss.elastic.co/u/PetervH)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 1:38pm UTC](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634 "2023-02-15T13:38:39Z")

</div>

Hi Can someone suggest a way to achieve the following: I'm getting a constant stream of events from a source. These events include data that specifies whether a particular process has completed successfully, as indicat…

---

## [Column count doesn't match after doing alias](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454)

<div class="topic-metadata">

**Author:** [@Rushikesh\_Dikey](https://discuss.elastic.co/u/Rushikesh_Dikey)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454 "2023-02-15T10:37:23Z")

</div>

Hi Team, I am trying to merge two different index, so i used // POST /\_aliases { "actions": \[ { "add": { "index": "abc", "alias": "poc" } }, { "add": { "index": "xyz", …

---

## [Vega-lite, create a forecast similar as lens visualization](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 7\
**Last updated:** [February 15, 2023, 10:05am UTC](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572 "2023-02-15T10:05:12Z")

</div>

Hello everyone I have a question with vega-lite and I don't know how to follow up. I checked on lens I can see data from last 2 hours and next 4 hours on the same graphic (a forecast job has been launched previously to …

---

## [How to develop Kibana custom plugin to add a custom agg type in Kibana Platform?](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556 "2023-02-15T08:06:28Z")

</div>

I want to update Kibana from v6.8.23 to v7.17.8, but the plugin kibana-datasweet-formula that I want to migrate to Kibana Platform do not work (Installation failed). I found this place to register each agg type: but…

---

## [How to search file path field value in Kibana?](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538)

<div class="topic-metadata">

**Author:** [@First\_Last](https://discuss.elastic.co/u/First_Last)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538 "2023-02-15T04:51:59Z")

</div>

New to Kibana and need some help understanding escaping special characters. Basically what I'm trying to do is take what I know in splunk and wildcard searching substrings of eventlog fields. Below is what I tried but re…

---

## [How to dynamically specify a url formatter](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520)

<div class="topic-metadata">

**Author:** [@kohkaw](https://discuss.elastic.co/u/kohkaw)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:58am UTC](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520 "2023-02-15T01:58:25Z")

</div>

I want to dynamically specify a url formatter for a document that contains an ever-increasing number of URL strings. Is there any other way than manually setting Set format=url from Index pattern?

---

## [Reindexing in Production Environment](https://discuss.elastic.co/t/reindexing-in-production-environment/323543)

<div class="topic-metadata">

**Author:** [@vishnu\_teja](https://discuss.elastic.co/u/vishnu_teja)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 12:18am UTC](https://discuss.elastic.co/t/reindexing-in-production-environment/323543 "2023-02-15T00:18:19Z")

</div>

Hi Everyone, Currently in our Elasticsearch cluster we have a lot of documents which need to deleted, so we are looking to re-index the used documents to a new index and delete the old index. We will be doing this in pro…

---

## [Optimizer fails when running yarn start in Kibana version 8](https://discuss.elastic.co/t/optimizer-fails-when-running-yarn-start-in-kibana-version-8/324142)

<div class="topic-metadata">

**Author:** [@ssimmons](https://discuss.elastic.co/u/ssimmons)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 4:49pm UTC](https://discuss.elastic.co/t/optimizer-fails-when-running-yarn-start-in-kibana-version-8/324142 "2023-02-14T16:49:19Z")

</div>

I'm in the process of upgrading our custom plugins to Kibana version 8. I'm trying to setup Kibana and Elasticsearch through docker. In the past, I built Kibana using a Dockerfile that would clone Kibana and then run yar…

---

## [Index Patterns](https://discuss.elastic.co/t/index-patterns/325496)

<div class="topic-metadata">

**Author:** [@hnclientes\_HN](https://discuss.elastic.co/u/hnclientes_HN)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 4:48pm UTC](https://discuss.elastic.co/t/index-patterns/325496 "2023-02-14T16:48:48Z")

</div>

Hi, I'm testing this version (cloud), and I can't find the option to create an index pattern for an index that I create using devtools. Could you tell me how I can activate this option please? Thank you

---

## [Add a custom tooltip to charts in Kibana?](https://discuss.elastic.co/t/add-a-custom-tooltip-to-charts-in-kibana/325487)

<div class="topic-metadata">

**Author:** [@Senol\_Kurt](https://discuss.elastic.co/u/Senol_Kurt)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 3:50pm UTC](https://discuss.elastic.co/t/add-a-custom-tooltip-to-charts-in-kibana/325487 "2023-02-14T15:50:03Z")

</div>

I want to add a custom tooltip that explains charts created with Lens. Is it possible with Kibana? Elasticsearch v.8.3.3

---

## [Rule type Log threshold](https://discuss.elastic.co/t/rule-type-log-threshold/325436)

<div class="topic-metadata">

**Author:** [@maxxl](https://discuss.elastic.co/u/maxxl)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 12:44pm UTC](https://discuss.elastic.co/t/rule-type-log-threshold/325436 "2023-02-14T12:44:22Z")

</div>

Kibana 8.4.3 Stack Management \\ Rules and Connectors Connectors type - Server Log Rule type - Log threshold The rule works well. How do I send the hostname and the original log (error.message) to the message?

---

## [Kibana Visualize - Display count even if field not exists](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246)

<div class="topic-metadata">

**Author:** [@Pedro\_Ventura](https://discuss.elastic.co/u/Pedro_Ventura)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246 "2023-02-14T09:41:02Z")

</div>

Hello! First time posting here, I've been looking around but haven't found anything to point me towards the right direction to solve my issue. I'm creating a data table which contains an aggregation by Terms for a date …

---

## [Canvas failed to load after upgrading kibana v7.17.1 to v8.5.2](https://discuss.elastic.co/t/canvas-failed-to-load-after-upgrading-kibana-v7-17-1-to-v8-5-2/325443)

<div class="topic-metadata">

**Author:** [@Aida](https://discuss.elastic.co/u/Aida)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 7:16am UTC](https://discuss.elastic.co/t/canvas-failed-to-load-after-upgrading-kibana-v7-17-1-to-v8-5-2/325443 "2023-02-14T07:16:28Z")

</div>

Hi, i have issue where canvas failed to load after upgrading from v7.17.1 to v8.5.2. It's taking really long time to load (more than 10mins). There are few times the canvas loaded after reaching timeout, & i see this err…

---

## [Improve filtering with control fields](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397 "2023-02-13T14:40:27Z")

</div>

Hello Community, I'm working of a kind of project to visulaze the mail flow. (see also here: Issue in Controls - #19 by moep ). The main problem is, that my content is not in the same line for example a mail flow looks …

---

## [Kibana 8.6.1 keeps Loading Elastic forever when using a JWT token](https://discuss.elastic.co/t/kibana-8-6-1-keeps-loading-elastic-forever-when-using-a-jwt-token/325274)

<div class="topic-metadata">

**Author:** [@frits](https://discuss.elastic.co/u/frits)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:57am UTC](https://discuss.elastic.co/t/kibana-8-6-1-keeps-loading-elastic-forever-when-using-a-jwt-token/325274 "2023-02-14T03:57:06Z")

</div>

I've been trying to get a JWT token login to work for a few days now. I've made a couple of great steps, I think I've managed to authenticate against the JWT provider (Broadcom IDM). I think I've created a correct role a…

---

## [Spring boot visualize actuator health](https://discuss.elastic.co/t/spring-boot-visualize-actuator-health/325389)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 12:34am UTC](https://discuss.elastic.co/t/spring-boot-visualize-actuator-health/325389 "2023-02-14T00:34:33Z")

</div>

Hello, I have a question. Our Java programmer has created a health API output for his Java program (output in json). Now I can get the API information by using an http pooler. I was wondering if there is a good way to v…

---

## [Is it possible to use TimeFilter on multiple date Fields?](https://discuss.elastic.co/t/is-it-possible-to-use-timefilter-on-multiple-date-fields/324688)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 8:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-timefilter-on-multiple-date-fields/324688 "2023-02-13T20:20:13Z")

</div>

So I have two date fields: createdTime and resolutionTime; The problem in question is that I need one chart A to operate by createdTime and a chart B to operate in resolutionTime. I had a guess that maybe I could achie…

---

## [Kibana - Display additional information with each datapoint](https://discuss.elastic.co/t/kibana-display-additional-information-with-each-datapoint/325305)

<div class="topic-metadata">

**Author:** [@Taylor\_Graham](https://discuss.elastic.co/u/Taylor_Graham)\
**Replies:** 2\
**Last updated:** [February 13, 2023, 5:16pm UTC](https://discuss.elastic.co/t/kibana-display-additional-information-with-each-datapoint/325305 "2023-02-13T17:16:28Z")

</div>

Maybe this is a unique problem, or maybe it's simply not possible. I have a set of devices for which I'm tracking metrics over time. To do this I create a Line Lens and put timestamp on the x-axis, CPU usage on the y-a…

---

## [Filter documents using aggregation in Discover](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401)

<div class="topic-metadata">

**Author:** [@Suresh\_Subramaniyan](https://discuss.elastic.co/u/Suresh_Subramaniyan)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:54pm UTC](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401 "2023-02-13T14:54:59Z")

</div>

Need to filter the documents based on aggregated results in kibana discover . { "aggs": { "match\_id": { "terms": { "field": "MATCH\_ID", "size": 10000 }, "aggs": { "count\_i…

---

## [Display live image data (base64 jpeg) in Kibana](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 21\
**Last updated:** [February 13, 2023, 8:42am UTC](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871 "2023-02-13T08:42:59Z")

</div>

I have Base64 encoded jpeg image data stored in ES which I want to display in a dashboard. I'm able to to that with a static image from a specific path using the markdown visualization. But how can I do that with data …

---

## [Help! workpad on website not showing fullwidth](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590)

<div class="topic-metadata">

**Author:** [@rens](https://discuss.elastic.co/u/rens)\
**Replies:** 2\
**Last updated:** [February 13, 2023, 7:44am UTC](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590 "2023-02-13T07:44:18Z")

</div>

Hi, I am new to this forum and to elastic. And I have a question. If I share a canvas workpad in static website I cannot get it to show fullwidth. On different monitors the result is either overflowing or to small. I …

---

## [Receiving an empty attachment with watcher email notification](https://discuss.elastic.co/t/receiving-an-empty-attachment-with-watcher-email-notification/325354)

<div class="topic-metadata">

**Author:** [@VenkatAnudeep](https://discuss.elastic.co/u/VenkatAnudeep)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 6:23am UTC](https://discuss.elastic.co/t/receiving-an-empty-attachment-with-watcher-email-notification/325354 "2023-02-13T06:23:18Z")

</div>

Hello, We have an email action configure in watcher which will send a result of Reporting URL. "email": { "profile": "standard", "attachments": { "KafkaReport.csv": { "reporting": …

---

## [How to redirect Dashboard's legacy URL alias using resolve API?](https://discuss.elastic.co/t/how-to-redirect-dashboards-legacy-url-alias-using-resolve-api/325349)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/how-to-redirect-dashboards-legacy-url-alias-using-resolve-api/325349 "2023-02-13T05:17:41Z")

</div>

I'm planning to upgrade Elastic Cloud v.7.17.0 to v.8.6.1. I know that there is a change to the saved object IDs from v.8 and my existing object IDs will be changed to a new UUID. To avoid changing the old dashboard UR…

---

## [How to filter by the nested values in the "message" field?](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 6\
**Last updated:** [February 12, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277 "2023-02-12T19:57:11Z")

</div>

Hi, I have a "message" field in my "filebeat\*" index. This "message" field, particularly has nested fields like "httpRequest" and a "country" field in it. The value of this "country" field is 'US' I want to use a quer…

---

## [Import objects from v8.x to v7.x](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:35am UTC](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801 "2023-02-12T01:35:53Z")

</div>

Hi, is it possible to import to kibana v7.16.2 dashboards which were created in kibana version 8.2.3? when i try to import objects i have an error: Best

---

## [Configurate ElasticSearch and Kibana with a differente certificate CA](https://discuss.elastic.co/t/configurate-elasticsearch-and-kibana-with-a-differente-certificate-ca/325295)

<div class="topic-metadata">

**Author:** [@Urbina](https://discuss.elastic.co/u/Urbina)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 10:33pm UTC](https://discuss.elastic.co/t/configurate-elasticsearch-and-kibana-with-a-differente-certificate-ca/325295 "2023-02-10T22:33:19Z")

</div>

Hello everyone, I installed elasticksearch and kibana version 8.61 in docker, but I need to cahnge the certificate ca by a differente certificate, can you help me with the steps to take?

---

## [How can I get elasticsearch indices, dataviews, documents inside my Kibana plugin?](https://discuss.elastic.co/t/how-can-i-get-elasticsearch-indices-dataviews-documents-inside-my-kibana-plugin/324901)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:45pm UTC](https://discuss.elastic.co/t/how-can-i-get-elasticsearch-indices-dataviews-documents-inside-my-kibana-plugin/324901 "2023-02-10T19:45:10Z")

</div>

Hi, I an creating an external plugin in Kibana 8.5.3. How can I get data/docs/indices/dataviews/... from my elasticsearch instance within my plugin? Thanks

---

## [Curl'ing Kibana Dashboards exported into NDJSON](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012)

<div class="topic-metadata">

**Author:** [@plissken](https://discuss.elastic.co/u/plissken)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 4:55pm UTC](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012 "2023-02-10T16:55:49Z")

</div>

I'm having considerable difficulty in understanding the documentation on the Kibana API's. There's so much out of date information on the web that I could literally spend months doing syntax jenga. I have a set of dash…

---

## [Check Forecast accuracy with scripted field](https://discuss.elastic.co/t/check-forecast-accuracy-with-scripted-field/324650)

<div class="topic-metadata">

**Author:** [@CHP93](https://discuss.elastic.co/u/CHP93)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 4:23pm UTC](https://discuss.elastic.co/t/check-forecast-accuracy-with-scripted-field/324650 "2023-02-10T16:23:20Z")

</div>

Hello community, I have a quite challenging task and have not found a solution for my problem, yet. I created a multi-metric anomalies detection machine learning job which is running a forecast as well. My aim is now t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=143)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=145)
