# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=152

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 153

---

## [Kibana REST API for integrations setup](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 16\
**Last updated:** [January 16, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151 "2023-01-16T12:49:24Z")

</div>

Hello, I have installed Elastic stack using ECK (Elasticsearch, Kibana, Beats, APM Server + agents), and trying to automate setup moving manual configuration steps to Kubernetes jobs that use Elasticsearch REST API. Bu…

---

## [Need proper example and resource for xml filter plugin](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087)

<div class="topic-metadata">

**Author:** [@Nikhil27](https://discuss.elastic.co/u/Nikhil27)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087 "2023-01-16T12:25:38Z")

</div>

I want to parse unstructured xml log data.I am not getting any proper resource for reference.The xml filter plugin documentation is not that able to sort my problem. I am new to the ELK please help me out of this....

---

## [Watcher - send runtime field in a Slack message](https://discuss.elastic.co/t/watcher-send-runtime-field-in-a-slack-message/323235)

<div class="topic-metadata">

**Author:** [@Darko\_Krstevski](https://discuss.elastic.co/u/Darko_Krstevski)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 10:36am UTC](https://discuss.elastic.co/t/watcher-send-runtime-field-in-a-slack-message/323235 "2023-01-16T10:36:12Z")

</div>

Hi All. I've created runtime mapping (field), transaction.duration.sec, which contains converted (in seconds) value of the "original" transaction duration (expressed in microseconds), with the following watcher configur…

---

## [Please keep the old expand document, the new "pop-out" makes everything slow](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941)

<div class="topic-metadata">

**Author:** [@blommis](https://discuss.elastic.co/u/blommis)\
**Replies:** 6\
**Last updated:** [January 16, 2023, 10:54am UTC](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941 "2023-01-16T10:54:30Z")

</div>

We just upgraded version and expanding a document in the table is now in a popup covering halv the screen. Before this change it was shown as more details below every row, making it possible to view details on multiple …

---

## [How to Get Control Filter in my custom plugin](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221)

<div class="topic-metadata">

**Author:** [@monusharma](https://discuss.elastic.co/u/monusharma)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 6:59am UTC](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221 "2023-01-16T06:59:28Z")

</div>

In this regards, I have searched on internet and found deprecated below mentioned code: import FilterBarQueryFilterProvider from 'ui/filter\_bar/query\_filter'; // Somewhere in your directive, service, or controller con…

---

## [Regarding daily active users count formula](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188)

<div class="topic-metadata">

**Author:** [@bhavin.shah](https://discuss.elastic.co/u/bhavin.shah)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 5:52am UTC](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188 "2023-01-16T05:52:57Z")

</div>

Hello team, I am trying to calculate one number output as , how many customers have placed daily atleast one order in last one day. My index formation is like following Ord\_order\_no - unique record / document ID Clien…

---

## [Unable to reset default password](https://discuss.elastic.co/t/unable-to-reset-default-password/323210)

<div class="topic-metadata">

**Author:** [@yuvrajbset](https://discuss.elastic.co/u/yuvrajbset)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 3:58am UTC](https://discuss.elastic.co/t/unable-to-reset-default-password/323210 "2023-01-16T03:58:15Z")

</div>

Hello ES Team, I am unable to reset my Elasticsearch password. Please find the screenshot below. Please help me out with this.

---

## [I want contribute to kibana](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845)

<div class="topic-metadata">

**Author:** [@dawn023349](https://discuss.elastic.co/u/dawn023349)\
**Replies:** 7\
**Last updated:** [January 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845 "2023-01-15T16:41:02Z")

</div>

I finished installing and testing the Linux version of Kibana. And I forked git repo. But "kibana\\src\\plugins\\data\\target\\public\\data.plugin.js" file did not exist. What should I do?

---

## [Unable to trigger a watcher alert when multiple conditions are met](https://discuss.elastic.co/t/unable-to-trigger-a-watcher-alert-when-multiple-conditions-are-met/319361)

<div class="topic-metadata">

**Author:** [@as-sre](https://discuss.elastic.co/u/as-sre)\
**Replies:** 0\
**Last updated:** [November 20, 2022, 9:40am UTC](https://discuss.elastic.co/t/unable-to-trigger-a-watcher-alert-when-multiple-conditions-are-met/319361 "2022-11-20T09:40:53Z")

</div>

I am trying to implement a logic in watcher to trigger an alert when multiple conditions are met. I have seen a couple of examples where it talks about checking the field ctx.payload.alert.hits.total, but I am sure it is…

---

## [Merging fields of two index pattern](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564)

<div class="topic-metadata">

**Author:** [@random\_dash](https://discuss.elastic.co/u/random_dash)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 2:19pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564 "2022-10-24T14:19:49Z")

</div>

Hi, I have two data streams in Kibana with similar information. I am trying to aggregate them by creating a new index pattern. Each of them has a field "state". For one of them, the state can be \[passed, failed\], and f…

---

## [Kibana Cavas empty datatable](https://discuss.elastic.co/t/kibana-cavas-empty-datatable/317001)

<div class="topic-metadata">

**Author:** [@Zdeno\_Liska](https://discuss.elastic.co/u/Zdeno_Liska)\
**Replies:** 4\
**Last updated:** [October 24, 2022, 1:46pm UTC](https://discuss.elastic.co/t/kibana-cavas-empty-datatable/317001 "2022-10-24T13:46:48Z")

</div>

Hi, I am facing strange issue. I have created canvas report like below. Anyway, I am getting random icons with exclamation marks, but when I reload data with Alt+R, they randomly disapear and reapear on different metric…

---

## [Kibana Iframe Share Issue with Xframe and SameSite Cookie](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824)

<div class="topic-metadata">

**Author:** [@hidanny](https://discuss.elastic.co/u/hidanny)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824 "2022-10-24T12:49:34Z")

</div>

Hello all, This may be a super dumb question. For reference, I am using latest React and Google Chrome. Also, to note, this is working completely fine in Firefox. Just not in Google Chrome. Essentially, I am trying to …

---

## [Plot a table based on aggregate key values](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 9:46am UTC](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635 "2023-01-14T09:46:35Z")

</div>

Hi and HNY! I am looking to put this kind of data every 30 minutes to Kibana under 1 index. data1- {key: 'key1', user: 'A', manager: 'C', cnt1: 2, cnt2:4} data2- {key: 'key2', user: 'B', manager: 'C', cnt1: 4, cnt2:5} …

---

## [Create visualize builder gauge using conditional value from document](https://discuss.elastic.co/t/create-visualize-builder-gauge-using-conditional-value-from-document/316371)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 11:49am UTC](https://discuss.elastic.co/t/create-visualize-builder-gauge-using-conditional-value-from-document/316371 "2022-10-24T11:49:26Z")

</div>

I'd like to dynamically set the value for the gauge according to the source data. How do I access the source data that has a variable named 'func'. Appreciate your advice. if (params.\_source\['func'\] == 'secret1') { para…

---

## [Range Slider](https://discuss.elastic.co/t/range-slider/317068)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 6\
**Last updated:** [October 24, 2022, 11:19am UTC](https://discuss.elastic.co/t/range-slider/317068 "2022-10-24T11:19:34Z")

</div>

Hi. Does the topic cover come with negative value for ranger slider. Anyone could share with me how to input the negative value or any documents? I have input a + value, but when input "-" it have the error status.

---

## [Signal status change time](https://discuss.elastic.co/t/signal-status-change-time/317301)

<div class="topic-metadata">

**Author:** [@Faycal\_B](https://discuss.elastic.co/u/Faycal_B)\
**Replies:** 0\
**Last updated:** [October 24, 2022, 9:12am UTC](https://discuss.elastic.co/t/signal-status-change-time/317301 "2022-10-24T09:12:35Z")

</div>

The signal api only return kibana.alert.workflow\_status field for the signal status change, is there a way to get a timestamp of the status change ?

---

## [Log all queries from Kibana 8.3 with custom data](https://discuss.elastic.co/t/log-all-queries-from-kibana-8-3-with-custom-data/321424)

<div class="topic-metadata">

**Author:** [@Anthony\_Gaskins1](https://discuss.elastic.co/u/Anthony_Gaskins1)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 5:50pm UTC](https://discuss.elastic.co/t/log-all-queries-from-kibana-8-3-with-custom-data/321424 "2022-12-16T17:50:29Z")

</div>

I want to make a plugin that captures all of the queries to elasticsearch and logs them with some custom information. How do I intercept the queries so I can add my info?

---

## [Color change based on field value instead of count](https://discuss.elastic.co/t/color-change-based-on-field-value-instead-of-count/323117)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 3:27pm UTC](https://discuss.elastic.co/t/color-change-based-on-field-value-instead-of-count/323117 "2023-01-13T15:27:57Z")

</div>

I'm trying to create a visualization, which will allow me to show my data from a community created Beats - Processbeat. It's a monitoring of processes with statuses like "RUNNING" or "STOPPED". Now to the point, below i…

---

## [Need to more about store the logs on Hot node instead of warm node](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 2:16pm UTC](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131 "2023-01-13T14:16:42Z")

</div>

Hello Team, We would like to know about to store the data from Hot node instead of warm node. Normally the process was stored the data from hot node and warm node depends on ILM policies by 7days of retention period. H…

---

## [Kibana - Table without time](https://discuss.elastic.co/t/kibana-table-without-time/323112)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 1:09pm UTC](https://discuss.elastic.co/t/kibana-table-without-time/323112 "2023-01-13T13:09:47Z")

</div>

Hello, I have Kibana 8.3.3. I have firewall data so data with IP address. In the same indices, I have list of IP address. I would like to create a table with IP address from firewall (src IP) and compare it with the …

---

## [Wrong timestamp in Alerting new elastic](https://discuss.elastic.co/t/wrong-timestamp-in-alerting-new-elastic/321286)

<div class="topic-metadata">

**Author:** [@diegomarting](https://discuss.elastic.co/u/diegomarting)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 1:35pm UTC](https://discuss.elastic.co/t/wrong-timestamp-in-alerting-new-elastic/321286 "2022-12-16T13:35:07Z")

</div>

Hello, I am migrating some alerts to te new version of Elastic Stack. I created the rules and the actions to send a message to a Google Webhook when an error log is ingested, but when I formatted the message with the mu…

---

## [KQL Syntax](https://discuss.elastic.co/t/kql-syntax/323031)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/kql-syntax/323031 "2023-01-13T12:03:47Z")

</div>

Does anybody know how to use dev tools? Because I'm thinking about updating the filter of a dashboard directly through python and I don't know how to do it. So, I am thinking of using KQL syntax. 2 questions I have is: d…

---

## [Kibana index data binding in the Vega Tree graph is difficult](https://discuss.elastic.co/t/kibana-index-data-binding-in-the-vega-tree-graph-is-difficult/323103)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 11:23am UTC](https://discuss.elastic.co/t/kibana-index-data-binding-in-the-vega-tree-graph-is-difficult/323103 "2023-01-13T11:23:33Z")

</div>

Static data was successfully connected to the Vega-V5 tree graph, however when I attempted to attach Kibana index data, it failed. Is it feasible to link the index data from Kibana to the Vega Tree graph? Eg: my\_index \[…

---

## [How to Hide the Zero records using JSON Input in Metric Dashboard](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 10:21am UTC](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013 "2023-01-13T10:21:12Z")

</div>

My document gets the data on irregular interval.The field name is Ex.,SensexValue. There can be multiple values on the field (SensexValue) in every interval, with different timestamp(milliseconds) and some interval the f…

---

## [Filtering by date field (other than the timestamp) in Kibana dashboard](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989)

<div class="topic-metadata">

**Author:** [@SaraAlshamsi](https://discuss.elastic.co/u/SaraAlshamsi)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 8:56am UTC](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989 "2023-01-13T08:56:35Z")

</div>

Hello everyone, I have an index with several fields and more than 1 time field. For examle: Field names: "end\_date", "name", "sequence" & "start\_date". The mapping: { "check\_date\_filter": { "mappings": { …

---

## [Kibana visualization error after restoring the snapshot](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [October 23, 2022, 7:34pm UTC](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265 "2022-10-23T19:34:12Z")

</div>

Hi, I have restored ElaticSearch snapsot that been managed by another person, I get the followng error when it comes to kibana dashboards Text fields are not optimised for operations that require per-document field da…

---

## [Add "Save Query" as one of Kibana sub-feature privileges](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 8:15am UTC](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017 "2022-11-18T08:15:38Z")

</div>

Hi Team, Is this feature available in recent versions of Kibana? # Add "Save Query" as one of Kibana sub-feature privileges If not is there a way for users with Read Only access to save query?

---

## [ElasticSearch 7.15.1 / Unhappy Cluster](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974)

<div class="topic-metadata">

**Author:** [@Devin\_Acosta](https://discuss.elastic.co/u/Devin_Acosta)\
**Replies:** 5\
**Last updated:** [January 12, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974 "2023-01-12T21:19:20Z")

</div>

I am trying to troubleshoot an Elasticsearch 7.15.1 cluster that has 3 master nodes, and 30+ data nodes. Recently we have seen where data nodes are complaining about "master not discovered yet" after the nodes have been …

---

## [Kibana can't connect to package directory](https://discuss.elastic.co/t/kibana-cant-connect-to-package-directory/316919)

<div class="topic-metadata">

**Author:** [@jpedroza2k20](https://discuss.elastic.co/u/jpedroza2k20)\
**Replies:** 5\
**Last updated:** [October 21, 2022, 1:53pm UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-package-directory/316919 "2022-10-21T13:53:01Z")

</div>

I have seen this same issue on the forums twice (English and French) and there is no resolution listed. I get the following error: I can access the URL from the server in question (self hosted stack) and there is no …

---

## [Rollup index name with date math](https://discuss.elastic.co/t/rollup-index-name-with-date-math/317161)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [October 21, 2022, 3:30am UTC](https://discuss.elastic.co/t/rollup-index-name-with-date-math/317161 "2022-10-21T03:30:19Z")

</div>

Hello, i tried to create rollup index in rollup job with rollup index name using date math, example of index name: my-log-%{+YYYY.MM.dd}, but kibana returned "Request failed with a 500 error. runtime\_exception: Could not…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=151)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=153)
