# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=149

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 150

---

## [\_size field (mapper size plugin)](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 6:03pm UTC](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863 "2023-01-24T18:03:15Z")

</div>

Hi all, as i understand when we enable this feature (mapper size plugin) the \_size meta field is not a new field in the index but a field on kibana index patern, correct? Because i can see the \_size field on kibana disc…

---

## [Unable to install Fleet on 8.6.0](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 3:19pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528 "2023-01-24T15:19:49Z")

</div>

Hello I'm unable to install/initiate fleet on our kibana. I get below error message Debug logs for plugin.fleet {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.4.0"},"@timestamp":"2023-01…

---

## [\[illegal\_state\_exception\] alias \[x\] has more than one write index \[y,z\]](https://discuss.elastic.co/t/illegal-state-exception-alias-x-has-more-than-one-write-index-y-z/323843)

<div class="topic-metadata">

**Author:** [@lazaro\_mobicare](https://discuss.elastic.co/u/lazaro_mobicare)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/illegal-state-exception-alias-x-has-more-than-one-write-index-y-z/323843 "2023-01-24T14:34:38Z")

</div>

Hi! I'm having the following problem when trying to restore an index snapshot: \[illegal\_state\_exception\] alias \[x\] has more than one write index \[y,z\]. I followed the following resolution but I came across another proble…

---

## [500 error on running commands on kibana console](https://discuss.elastic.co/t/500-error-on-running-commands-on-kibana-console/323728)

<div class="topic-metadata">

**Author:** [@pranita.ch](https://discuss.elastic.co/u/pranita.ch)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 2:01pm UTC](https://discuss.elastic.co/t/500-error-on-running-commands-on-kibana-console/323728 "2023-01-24T14:01:33Z")

</div>

Version Elasticsearch 7.10 Service software version R20220928-P2 (latest) on Kibana after running GET \_snapshot/my-snapshot-repo/\_all?pretty its gives 500 error { "error" : { "root\_cause" : \[ { "type" : "repositor…

---

## [Missing Legend Entries](https://discuss.elastic.co/t/missing-legend-entries/322625)

<div class="topic-metadata">

**Author:** [@acbiccy](https://discuss.elastic.co/u/acbiccy)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 12:54pm UTC](https://discuss.elastic.co/t/missing-legend-entries/322625 "2023-01-24T12:54:21Z")

</div>

Hi Everyone I have a report that has approximately 200 legend entries, however the screen only displays around 25. I have tried moving the legend position but above and below give even less entries. I have tried diffe…

---

## [Kibana Dashboard is not getting updated with latest data](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303)

<div class="topic-metadata">

**Author:** [@vidvar](https://discuss.elastic.co/u/vidvar)\
**Replies:** 19\
**Last updated:** [January 24, 2023, 12:38pm UTC](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303 "2023-01-24T12:38:09Z")

</div>

In our Kibana, dashboards are not getting displayed the latest data from Nov 04, 2022 and we could see below logs snippets at kibana.log. Could someone please assist what is missing here. {"type":"log","@timestamp":"20…

---

## [CCR replication paused indices](https://discuss.elastic.co/t/ccr-replication-paused-indices/323817)

<div class="topic-metadata">

**Author:** [@Jairam\_Gauns](https://discuss.elastic.co/u/Jairam_Gauns)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 12:12pm UTC](https://discuss.elastic.co/t/ccr-replication-paused-indices/323817 "2023-01-24T12:12:05Z")

</div>

Hi Guys, I am new to this CCR setup. The CCR setup was working fine when we had fewer and smaller indices, but as of today we have many indices. Monitoring of the ccr was not done for quite sometime. We saw there were …

---

## [Custom pattern in grok debugger](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805 "2023-01-24T10:49:08Z")

</div>

Hi I'm trying to set up a grok filter for custom logs, look like this: 2023-01-20 00:00:05.235+0000 \[L: DEBUG\] \[O: S.c.t.d.e.DSLScript\] \[I: \] \[U: Administrator\] \[S: \] \[P: \] \[T: TWEventProcessor-3\] @@@ Property Write Que…

---

## [Cannot access to Security in Kibana due privilege ERROR](https://discuss.elastic.co/t/cannot-access-to-security-in-kibana-due-privilege-error/323804)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 9:40am UTC](https://discuss.elastic.co/t/cannot-access-to-security-in-kibana-due-privilege-error/323804 "2023-01-24T09:40:02Z")

</div>

when i trying to enter Security (Dashboards, Alert, Manage ...) got the message "Failed to retrieve lists privileges" i created spaces and several dashboards and now i want for Each user (spaces) to restrict viewing of…

---

## [Can not get details of ELK stack monitoring](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 8:54am UTC](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731 "2023-01-24T08:54:37Z")

</div>

Hi, Suddenly I got this error "Monitoring Request Error Connection error: Check the Elasticsearch Monitoring cluster network connection and refer to the Kibana logs for more information. HTTP 503" What would be the…

---

## [Field type changed results in a conflict - kibana reports an error](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 8:51am UTC](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970 "2023-01-24T08:51:09Z")

</div>

Dear All, from a firewall I send log information to filebeat into a self written module. Within a kibana dashboard I have several lenses to get information of different events and aggregations. This is now running sever…

---

## [How do we get scroll up/down option on Controls (Filters)](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 6:52am UTC](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720 "2023-01-24T06:52:35Z")

</div>

Hi Team, We created one control having total 20 options, but its showing only 10 (It's not showing any scroll bar also). But, we are expecting here to view all 20 available options or at least scroll up/down. Please fin…

---

## [Alert for paused indices on CCR](https://discuss.elastic.co/t/alert-for-paused-indices-on-ccr/323777)

<div class="topic-metadata">

**Author:** [@Jairam\_Gauns](https://discuss.elastic.co/u/Jairam_Gauns)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 5:30am UTC](https://discuss.elastic.co/t/alert-for-paused-indices-on-ccr/323777 "2023-01-24T05:30:52Z")

</div>

I would like to know if we can get alerts of paused indices in CCR from the DR site. So that we can then check and resume the indices/pattern. Or any other way one could recommend to know if indices getting paused on DR…

---

## [Import \`integer\_range\` from CSV with kibana \`Visualize data from a file\`?](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 2:00am UTC](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765 "2023-01-24T02:00:55Z")

</div>

Is it possible for the Machine Learning\>Data Visualizer\>Visualize data from file to import a csv file where one of the columns is an integer\_range? If so, what is the syntax that should be used in the integer\_range colu…

---

## [Timelion query filter returning constant 0 results](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625)

<div class="topic-metadata">

**Author:** [@vector\_prime](https://discuss.elastic.co/u/vector_prime)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 9:52pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625 "2023-01-23T21:52:50Z")

</div>

I have an index with the following document structure: "\_source": { "installcreatedbyusername": "xxxx", "@timestamp": "2023-01-20T16:30:03.840332Z", "type": "aegis", "num\_packages": 2, "num\_environme…

---

## [Fleet Server is Not Healthy](https://discuss.elastic.co/t/fleet-server-is-not-healthy/322215)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/fleet-server-is-not-healthy/322215 "2023-01-23T16:41:38Z")

</div>

I am getting the error, and becuase of that I can't add any agent.. what is causing the error. and How do i Resolve it. Is it becuause of the SSL certificate ?

---

## [Elasticsearch exited unexpectedly ES exited with code 1](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly-es-exited-with-code-1/323638)

<div class="topic-metadata">

**Author:** [@jdso1988](https://discuss.elastic.co/u/jdso1988)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 4:22pm UTC](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly-es-exited-with-code-1/323638 "2023-01-23T16:22:00Z")

</div>

After running: yarn es snapshot i get the following error yarn run v1.22.19 warning ../../package.json: No license field $ node scripts/es snapshot info Installing from snapshot │ info version: 8.5.0 │ info inst…

---

## [Reindexing of old v.6 index keeps stopping with reason kibana was restarted](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749)

<div class="topic-metadata">

**Author:** [@teesr5](https://discuss.elastic.co/u/teesr5)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 4:05pm UTC](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749 "2023-01-23T16:05:46Z")

</div>

Hi, we're preparing to upgrade from v.7.10.0, the elk stack is running on an Ubuntu cluster with 3 nodes, although we have an index which we have to prepare for the upgrade, it keeps on looping: Details \[some\]-alias …

---

## [Restore snapshot from another cluster (7.8 to 8.5)](https://discuss.elastic.co/t/restore-snapshot-from-another-cluster-7-8-to-8-5/322747)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 3:24pm UTC](https://discuss.elastic.co/t/restore-snapshot-from-another-cluster-7-8-to-8-5/322747 "2023-01-23T15:24:21Z")

</div>

I have a question/problem. I have a GCP bucket with tons of snapshots taken from a kibana 7.8, A new kibana has been deployed in another cluster v8.5, that kibana has been connected to the GCP bucket where the old kiban…

---

## [How to configure Cluster Filter - Cluster Name](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725 "2023-01-23T12:31:25Z")

</div>

Hello, i am just find out how to configure the Cluster Filter here. Does anyone can help me ?

---

## [Example Angular plugin](https://discuss.elastic.co/t/example-angular-plugin/323706)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 10:37am UTC](https://discuss.elastic.co/t/example-angular-plugin/323706 "2023-01-23T10:37:52Z")

</div>

Hi, I am creating an external plugin using Angular Is there and example plugin I can use for reference? Thanks

---

## [How to use elastic ui within angular plugin](https://discuss.elastic.co/t/how-to-use-elastic-ui-within-angular-plugin/321973)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-use-elastic-ui-within-angular-plugin/321973 "2023-01-23T10:36:02Z")

</div>

Hi, I am building a custom external plugin using Angular. I want to use Elastic UI for styling. How can I use it within angular? Thanks

---

## [Jupyter -\> Vega -\> Kibana Visualization Error](https://discuss.elastic.co/t/jupyter-vega-kibana-visualization-error/321264)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 9:09am UTC](https://discuss.elastic.co/t/jupyter-vega-kibana-visualization-error/321264 "2023-01-23T09:09:09Z")

</div>

Hi, I want to visualize data from jupyter to Vega to Kibana. I got a reference How to bring Jupyter Notebook visualizations to Kibana dashboards for data science | Elastic Blog and GitHub - walterra/jupyter2kibana: A…

---

## [Divide two counts of the same index with different filters](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631)

<div class="topic-metadata">

**Author:** [@TheFish](https://discuss.elastic.co/u/TheFish)\
**Replies:** 3\
**Last updated:** [January 21, 2023, 12:00pm UTC](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631 "2023-01-21T12:00:32Z")

</div>

Hi, I'm trying to divide two counts in TSVB, and I've read the related answer at Divides two sum fields in kibana? but I have a twist, and I can't get it to work: I have one index with "death" events in a game. Each eve…

---

## [Clean old indexes automatically in elasticsearch](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 4:38pm UTC](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551 "2023-01-20T16:38:05Z")

</div>

Hello friends, I'm having problems with the storage where elasticsearch is installed... I'm constantly having a full disk. What can I do to delete or clean up old indexes?

---

## [Kibana - Metric Threshold Alert - {{context.group}}](https://discuss.elastic.co/t/kibana-metric-threshold-alert-context-group/323544)

<div class="topic-metadata">

**Author:** [@TXBigDawg1836](https://discuss.elastic.co/u/TXBigDawg1836)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 3:50pm UTC](https://discuss.elastic.co/t/kibana-metric-threshold-alert-context-group/323544 "2023-01-20T15:50:54Z")

</div>

Have configured a Metric Threshold Alert using a field within the results called "Provider-City" in the Group Alerts By. In the message body we have a key/value pair "Provider-City": "{{context.group}}" which is worki…

---

## [Unable to authenticate user \[elastic\] for REST request](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/323593)

<div class="topic-metadata">

**Author:** [@vidvar](https://discuss.elastic.co/u/vidvar)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 1:03pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/323593 "2023-01-20T13:03:56Z")

</div>

Hello @warkolm Since few weeks, all of sudden, getting below while I am trying to curl to one of my elastic nodes. And latest data is not getting updated in Kibana dashboards. Elastic search version is 7.8.0. curl --u…

---

## [Can not create index pattern Uncaught TypeError: Cannot read properties of null](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:54pm UTC](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592 "2023-01-20T12:54:41Z")

</div>

Hi everyone, i use Version: 6.3.2, when i try to create a new index pattern i see this error: Any ideas?

---

## [Read-Only User With Save Query Priviieges](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591 "2023-01-20T12:53:39Z")

</div>

I would like a read-only Dashboard user to be able to save a query, how can enable that? I cant seem to make it work but it's essential to our processes internally.

---

## [Could or Should?](https://discuss.elastic.co/t/could-or-should/322473)

<div class="topic-metadata">

**Author:** [@ChrizK](https://discuss.elastic.co/u/ChrizK)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 12:19pm UTC](https://discuss.elastic.co/t/could-or-should/322473 "2023-01-20T12:19:14Z")

</div>

Sorry, the title is a bit tongue-in-cheek :unamused: I have a dashboard which shows test results. The tests are IP related and I use the IP address to identify if the destination address is a Proxy Server or NOT. (I h…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=148)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=150)
