# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=15

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 16

---

## [Does X-Pack perform authorization checks per index or shard on every request?](https://discuss.elastic.co/t/does-x-pack-perform-authorization-checks-per-index-or-shard-on-every-request/378556)

<div class="topic-metadata">

**Author:** [@catalyst1](https://discuss.elastic.co/u/catalyst1)\
**Replies:** 5\
**Last updated:** [May 27, 2025, 9:29am UTC](https://discuss.elastic.co/t/does-x-pack-perform-authorization-checks-per-index-or-shard-on-every-request/378556 "2025-05-27T09:29:46Z")

</div>

Hi, I'm currently managing an Elasticsearch cluster with X-Pack security enabled. Our setup includes approximately 6,400 indices and 23,200 shards. Right after I activated xpack, Elasticsearch's performance became extr…

---

## [How to know what Elasticsearch endpoint is used by Kibana to make graphs?](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529)

<div class="topic-metadata">

**Author:** [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Replies:** 5\
**Last updated:** [May 27, 2025, 9:02am UTC](https://discuss.elastic.co/t/how-to-know-what-elasticsearch-endpoint-is-used-by-kibana-to-make-graphs/378529 "2025-05-27T09:02:11Z")

</div>

I have URI like ../discover#/?\_g=(filters:!(),refreshInterval:(pause:!t,value:0),time:(from:now%2Fd,to:now%2Fd))&\_a=(columns:!(\_source),filters:!(),index:{index},interval:auto,query:(language:kuery,query:%27%27),sort:!(…

---

## [Error on field and document level security](https://discuss.elastic.co/t/error-on-field-and-document-level-security/378462)

<div class="topic-metadata">

**Author:** [@teeraw](https://discuss.elastic.co/u/teeraw)\
**Replies:** 3\
**Last updated:** [May 27, 2025, 4:10am UTC](https://discuss.elastic.co/t/error-on-field-and-document-level-security/378462 "2025-05-27T04:10:35Z")

</div>

I want to filter the server list for each user role based on the servers they are responsible for. During my research, I found that this can be done using "document level security" I prepared the following JSON request …

---

## [Configure common user to export csv](https://discuss.elastic.co/t/configure-common-user-to-export-csv/378537)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 3\
**Last updated:** [May 26, 2025, 1:35pm UTC](https://discuss.elastic.co/t/configure-common-user-to-export-csv/378537 "2025-05-26T13:35:59Z")

</div>

I'm not able to give permission for a user to export one of the dashboard viewers. Can you help me? I'm on version 9.0.1 Here's an image of what I need to appear for him.

---

## [Input log file is not discovered in Kibana in window 11](https://discuss.elastic.co/t/input-log-file-is-not-discovered-in-kibana-in-window-11/378523)

<div class="topic-metadata">

**Author:** [@Jitendra2](https://discuss.elastic.co/u/Jitendra2)\
**Replies:** 1\
**Last updated:** [May 26, 2025, 8:56am UTC](https://discuss.elastic.co/t/input-log-file-is-not-discovered-in-kibana-in-window-11/378523 "2025-05-26T08:56:34Z")

</div>

I have configured and started elastic-search, kibana and logstash. Everything is working without error but I am not able to see my log file in kibana. below is logstash configuration. Can someone please suggest me what I…

---

## [ML Anomaly Detection - Alert Thresholds](https://discuss.elastic.co/t/ml-anomaly-detection-alert-thresholds/378094)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [May 23, 2025, 11:38pm UTC](https://discuss.elastic.co/t/ml-anomaly-detection-alert-thresholds/378094 "2025-05-23T23:38:37Z")

</div>

Hello, I recently been building Anomaly Detection jobs and alerts. I was wondering if there's a way to specify a threshold. Here's my current issue: Anomaly Detection works by using the historical data as a baseline. …

---

## [Sum aggregation Giving incorrect resumt](https://discuss.elastic.co/t/sum-aggregation-giving-incorrect-resumt/378329)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 14\
**Last updated:** [May 23, 2025, 4:46pm UTC](https://discuss.elastic.co/t/sum-aggregation-giving-incorrect-resumt/378329 "2025-05-23T16:46:03Z")

</div>

I'm encountering an issue in Kibana. When I check a particular variable in Discover, I can see that it has a value of 0 on four different dates. For the remaining dates, there is no data shown for this variable in Discov…

---

## [Limit Kibana watcher emails](https://discuss.elastic.co/t/limit-kibana-watcher-emails/378466)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 1\
**Last updated:** [May 23, 2025, 9:59am UTC](https://discuss.elastic.co/t/limit-kibana-watcher-emails/378466 "2025-05-23T09:59:32Z")

</div>

Hello, I would like to ask about the Kibana watcher. When the watcher conditions are met, an email is sent. Is there any way to limit the maximum number of emails? I would like to run the watcher every 30 minutes, but…

---

## [Data Table Grouping](https://discuss.elastic.co/t/data-table-grouping/378443)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [May 23, 2025, 9:23am UTC](https://discuss.elastic.co/t/data-table-grouping/378443 "2025-05-23T09:23:22Z")

</div>

Hello All, I can't describe this type of logic but is it possible to do this with lens data table: The logic is first row contains a group, the second row contains the associated services but don't repeat the same v…

---

## [Setup a Machine Learning rule is not active](https://discuss.elastic.co/t/setup-a-machine-learning-rule-is-not-active/378170)

<div class="topic-metadata">

**Author:** [@nzeland149](https://discuss.elastic.co/u/nzeland149)\
**Replies:** 25\
**Last updated:** [May 22, 2025, 2:03pm UTC](https://discuss.elastic.co/t/setup-a-machine-learning-rule-is-not-active/378170 "2025-05-22T14:03:26Z")

</div>

i have configured this rule but status always ok not active what can i do to fix this

---

## [Kibana alerts not sorting properly](https://discuss.elastic.co/t/kibana-alerts-not-sorting-properly/376407)

<div class="topic-metadata">

**Author:** [@rara01](https://discuss.elastic.co/u/rara01)\
**Replies:** 6\
**Last updated:** [May 21, 2025, 3:22pm UTC](https://discuss.elastic.co/t/kibana-alerts-not-sorting-properly/376407 "2025-05-21T15:22:08Z")

</div>

Hi, When trying to sort Alerts in Stack management - Alerts by date started, the sorting is not working as expected. When trying to sort alerts on "Started" from "New to Old", i get what seems randomly sorted values, sa…

---

## [Dark Blue Mode Bug](https://discuss.elastic.co/t/dark-blue-mode-bug/378353)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [May 21, 2025, 2:41pm UTC](https://discuss.elastic.co/t/dark-blue-mode-bug/378353 "2025-05-21T14:41:06Z")

</div>

Hello, I am guessing this is not supposed to happen:

---

## [Microsoft SQL Connector not able to connect](https://discuss.elastic.co/t/microsoft-sql-connector-not-able-to-connect/362961)

<div class="topic-metadata">

**Author:** [@sebaV\_20](https://discuss.elastic.co/u/sebaV_20)\
**Replies:** 12\
**Last updated:** [May 21, 2025, 1:28pm UTC](https://discuss.elastic.co/t/microsoft-sql-connector-not-able-to-connect/362961 "2025-05-21T13:28:33Z")

</div>

Hello, So Basically what the title says. I´m trying to create a native connector for an Azure deployed Microsoft SQL Database and i´m not being able to connect to the db. All this in the Connectors tab. I have this con…

---

## [Results from aliases in Index Management](https://discuss.elastic.co/t/results-from-aliases-in-index-management/378380)

<div class="topic-metadata">

**Author:** [@henrikuib](https://discuss.elastic.co/u/henrikuib)\
**Replies:** 0\
**Last updated:** [May 21, 2025, 11:18am UTC](https://discuss.elastic.co/t/results-from-aliases-in-index-management/378380 "2025-05-21T11:18:29Z")

</div>

It's currently not possible to search for an alias in Index Management. It's also impractical that you have to open each index to see if they have aliases.

---

## [I can't configure a connector to send mail with alert](https://discuss.elastic.co/t/i-cant-configure-a-connector-to-send-mail-with-alert/378373)

<div class="topic-metadata">

**Author:** [@elastic\_interogation](https://discuss.elastic.co/u/elastic_interogation)\
**Replies:** 0\
**Last updated:** [May 21, 2025, 7:57am UTC](https://discuss.elastic.co/t/i-cant-configure-a-connector-to-send-mail-with-alert/378373 "2025-05-21T07:57:29Z")

</div>

Hi, I am trying to configure a connector to automatically send emails when an alert is triggered. For that, I went to the connector section and created my first connector. I configured the connector name, and in the se…

---

## [Cannot access the Kibana Security Analyst for Elastic training lab](https://discuss.elastic.co/t/cannot-access-the-kibana-security-analyst-for-elastic-training-lab/378362)

<div class="topic-metadata">

**Author:** [@Ernest](https://discuss.elastic.co/u/Ernest)\
**Replies:** 0\
**Last updated:** [May 20, 2025, 11:50pm UTC](https://discuss.elastic.co/t/cannot-access-the-kibana-security-analyst-for-elastic-training-lab/378362 "2025-05-20T23:50:54Z")

</div>

I cannot access the Kibana Security Analyst for the Elastic training lab. The issue I encountered is attached. Please assist.

---

## [Use of unmapped\_type in sorting](https://discuss.elastic.co/t/use-of-unmapped-type-in-sorting/378127)

<div class="topic-metadata">

**Author:** [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Replies:** 3\
**Last updated:** [May 20, 2025, 8:33am UTC](https://discuss.elastic.co/t/use-of-unmapped-type-in-sorting/378127 "2025-05-20T08:33:22Z")

</div>

Hi everyone, In my application, I want to sort fields similar to the Kibana Discover page. While exploring Kibana APIs for sorting, I noticed that Kibana addsunmapped\_type: "boolean" in sort query to all the fields. I j…

---

## [Dataview id from API request does not correlate with actual dataview id](https://discuss.elastic.co/t/dataview-id-from-api-request-does-not-correlate-with-actual-dataview-id/374181)

<div class="topic-metadata">

**Author:** [@elasticexpert2](https://discuss.elastic.co/u/elasticexpert2)\
**Replies:** 3\
**Last updated:** [May 20, 2025, 8:31am UTC](https://discuss.elastic.co/t/dataview-id-from-api-request-does-not-correlate-with-actual-dataview-id/374181 "2025-05-20T08:31:17Z")

</div>

I have been trying to use the Kibana API in order to get a list of all the dataviews and use their ID for link generation purposes. Following this doc \[get all dataviews\]: https://www.elastic.co/guide/en/kibana/current/…

---

## [Critical http://10.54.120.149:9200 seems to be unreachable](https://discuss.elastic.co/t/critical-http-10-54-120-149-9200-seems-to-be-unreachable/377728)

<div class="topic-metadata">

**Author:** [@Madhu\_Challapalli](https://discuss.elastic.co/u/Madhu_Challapalli)\
**Replies:** 34\
**Last updated:** [May 20, 2025, 5:40am UTC](https://discuss.elastic.co/t/critical-http-10-54-120-149-9200-seems-to-be-unreachable/377728 "2025-05-20T05:40:51Z")

</div>

I have used below steps to install and run docker images for Elasticsearch and Kibana.

---

## [Getting error 'Payload Too Large' in Kibana UI](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246)

<div class="topic-metadata">

**Author:** [@Natalia\_Mellino](https://discuss.elastic.co/u/Natalia_Mellino)\
**Replies:** 4\
**Last updated:** [May 19, 2025, 1:20pm UTC](https://discuss.elastic.co/t/getting-error-payload-too-large-in-kibana-ui/378246 "2025-05-19T13:20:35Z")

</div>

Hello! We are currently running the ELK on 7.17.26 version along with ReadonlyREST plugin in both Kibana an Elasticsearch in order to use Keycloak authentication in Kibana. This past weeks some users were experiencing th…

---

## [Creating a Kinana table using a multi-field with es|ql](https://discuss.elastic.co/t/creating-a-kinana-table-using-a-multi-field-with-es-ql/377972)

<div class="topic-metadata">

**Author:** [@Robin\_Gorry](https://discuss.elastic.co/u/Robin_Gorry)\
**Replies:** 2\
**Last updated:** [May 19, 2025, 11:24am UTC](https://discuss.elastic.co/t/creating-a-kinana-table-using-a-multi-field-with-es-ql/377972 "2025-05-19T11:24:29Z")

</div>

v 8.17.4 I am trying to create a visualisation table in Kibana using an es|ql query. The main field in question is a Keyword multi-field call ItemsFound. I want the first column to be a list of unique items found. Co…

---

## [Capturing Service Layer](https://discuss.elastic.co/t/capturing-service-layer/378292)

<div class="topic-metadata">

**Author:** [@Pooya\_Mirzapour](https://discuss.elastic.co/u/Pooya_Mirzapour)\
**Replies:** 0\
**Last updated:** [May 19, 2025, 11:11am UTC](https://discuss.elastic.co/t/capturing-service-layer/378292 "2025-05-19T11:11:51Z")

</div>

I am using co.elastic.otel in my Spring boot project. Everything is working well, except I just see tracing in controller and repository level. I need to trace in service layer as well. How it is possible? My Maven depe…

---

## [ES | QL / Combining Charts?](https://discuss.elastic.co/t/es-ql-combining-charts/378050)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 9:43am UTC](https://discuss.elastic.co/t/es-ql-combining-charts/378050 "2025-05-19T09:43:18Z")

</div>

Hello, I have this two pie charts: They are use different fields, but I would like to combine them into one: Is this possible with ES|QL

---

## [Alerting function from "Rules and Connector" can be able on Kibana version 7.17.28 with Basic License?](https://discuss.elastic.co/t/alerting-function-from-rules-and-connector-can-be-able-on-kibana-version-7-17-28-with-basic-license/378152)

<div class="topic-metadata">

**Author:** [@carbon](https://discuss.elastic.co/u/carbon)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 6:31am UTC](https://discuss.elastic.co/t/alerting-function-from-rules-and-connector-can-be-able-on-kibana-version-7-17-28-with-basic-license/378152 "2025-05-19T06:31:55Z")

</div>

Alerting function from "Rules and Connector" can be able on Kibana version 7.17.28 with Basic License?

---

## [Create Field in windows for workstation name](https://discuss.elastic.co/t/create-field-in-windows-for-workstation-name/378247)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 1\
**Last updated:** [May 16, 2025, 8:47pm UTC](https://discuss.elastic.co/t/create-field-in-windows-for-workstation-name/378247 "2025-05-16T20:47:14Z")

</div>

Hello, I am currently performing a task to extract the fields related to the NTLM protocol to determine if this protocol is being used in my network. With the security, system and application logs that are collected fr…

---

## [Timezone in watchers](https://discuss.elastic.co/t/timezone-in-watchers/378186)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 2\
**Last updated:** [May 16, 2025, 5:29am UTC](https://discuss.elastic.co/t/timezone-in-watchers/378186 "2025-05-16T05:29:46Z")

</div>

I attempted to configure a Watcher schedule using the timezone property as shown below: "schedule": { "timezone": "Pacific/Auckland", "daily": { "at": "12:00" } } However, when saving the Watcher, I encountered th…

---

## [ISSUES WITH STARTING KABANA SERVICE](https://discuss.elastic.co/t/issues-with-starting-kabana-service/378187)

<div class="topic-metadata">

**Author:** [@eliaotito](https://discuss.elastic.co/u/eliaotito)\
**Replies:** 1\
**Last updated:** [May 15, 2025, 10:56pm UTC](https://discuss.elastic.co/t/issues-with-starting-kabana-service/378187 "2025-05-15T22:56:34Z")

</div>

Good Morning,all I have installed Kabana, Elastic Search, Filebeat on the ubuntu 24.04, but am getting an issue with accessing the URL for Kabana. Also, it shows on status it has failed like below, please let me know wh…

---

## [Kibana metric, can I get: sum of \`NumberOfPeople\` who attended clinics with a unique\`ClinicName\`?](https://discuss.elastic.co/t/kibana-metric-can-i-get-sum-of-numberofpeople-who-attended-clinics-with-a-unique-clinicname/377789)

<div class="topic-metadata">

**Author:** [@Robin\_Gorry](https://discuss.elastic.co/u/Robin_Gorry)\
**Replies:** 9\
**Last updated:** [May 15, 2025, 7:52pm UTC](https://discuss.elastic.co/t/kibana-metric-can-i-get-sum-of-numberofpeople-who-attended-clinics-with-a-unique-clinicname/377789 "2025-05-15T19:52:27Z")

</div>

v 8.17.4 In my metric visualisation I would like to show the sum of NumberOfPeople who attended clinics with a uniqueClinicName . Is this possible? I can see how I can get sum(NumberOfPeople) and unique\_count(ClinicNam…

---

## [Why Are Typical Values Negative or Missing in high\_sum Anomaly Detection in Elasticsearch?](https://discuss.elastic.co/t/why-are-typical-values-negative-or-missing-in-high-sum-anomaly-detection-in-elasticsearch/378196)

<div class="topic-metadata">

**Author:** [@Jordan\_Queiroz](https://discuss.elastic.co/u/Jordan_Queiroz)\
**Replies:** 0\
**Last updated:** [May 15, 2025, 6:30pm UTC](https://discuss.elastic.co/t/why-are-typical-values-negative-or-missing-in-high-sum-anomaly-detection-in-elasticsearch/378196 "2025-05-15T18:30:09Z")

</div>

Hello, everyone. I have a machine learning job that analyzes a numeric field where values are always greater than or equal to 0. The analysis function I'm using is high\_sum, and the field type is float. The machine lea…

---

## [How to know field is sortable or not](https://discuss.elastic.co/t/how-to-know-field-is-sortable-or-not/378124)

<div class="topic-metadata">

**Author:** [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Replies:** 3\
**Last updated:** [May 15, 2025, 10:05am UTC](https://discuss.elastic.co/t/how-to-know-field-is-sortable-or-not/378124 "2025-05-15T10:05:09Z")

</div>

Hi Everyone, In my application, I want to sort fields similar to the Kibana Discover page. After exploring the Kibana Discover page, I found that some fields are not sortable, meaning the sort functionality is disabled …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=14)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=16)
