# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=154

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 155

---

## [Kibana Visualization of bucket aggregation data](https://discuss.elastic.co/t/kibana-visualization-of-bucket-aggregation-data/320554)

<div class="topic-metadata">

**Author:** [@jos\_nubel007](https://discuss.elastic.co/u/jos_nubel007)\
**Replies:** 3\
**Last updated:** [December 13, 2022, 9:33am UTC](https://discuss.elastic.co/t/kibana-visualization-of-bucket-aggregation-data/320554 "2022-12-13T09:33:05Z")

</div>

I created an index that collects metrics for different applications and I visualize these metrics in Kibana. However, there is a field that contains bucket aggregation datas (something like that: Variable width histogram…

---

## [Kibana Data view "fieldAttrs"](https://discuss.elastic.co/t/kibana-data-view-fieldattrs/322629)

<div class="topic-metadata">

**Author:** [@cotarbe](https://discuss.elastic.co/u/cotarbe)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 9:28am UTC](https://discuss.elastic.co/t/kibana-data-view-fieldattrs/322629 "2023-01-10T09:28:03Z")

</div>

Hello, I used Kibana API to get info about a data view GET kbn:/api/data\_views/data\_view/\<data\_view\_id\> and I got an object as the following: { "data\_view": { "id": "...", "version": "...", "tit…

---

## [GUID is not a configured index pattern ID Showing the default index pattern:](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/322352)

<div class="topic-metadata">

**Author:** [@hagite](https://discuss.elastic.co/u/hagite)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 7:11am UTC](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/322352 "2023-01-10T07:11:50Z")

</div>

Hello, My Kibana is working well always, yesterday, in Discovery page I got the message 99792e00-1552-11ec-929c-81cfc96dcc03" is not a configured index pattern ID Showing the default index pattern: "file\*" (5c1d0020…

---

## ['Select A field' option is not populating while creating a new alert](https://discuss.elastic.co/t/select-a-field-option-is-not-populating-while-creating-a-new-alert/322794)

<div class="topic-metadata">

**Author:** [@Narinder\_Tiwari](https://discuss.elastic.co/u/Narinder_Tiwari)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 7:11am UTC](https://discuss.elastic.co/t/select-a-field-option-is-not-populating-while-creating-a-new-alert/322794 "2023-01-10T07:11:46Z")

</div>

Hi, i am trying to create a Metric threshold alert for memory usages is \> 90 %. No field is populating in 'Select A field'' option . When I trying to add the field 'system.memory.used.pct'. it's not accepting it. Surpr…

---

## [I want to show that's ip which is triggered](https://discuss.elastic.co/t/i-want-to-show-thats-ip-which-is-triggered/322788)

<div class="topic-metadata">

**Author:** [@Tayyab\_Ilyas](https://discuss.elastic.co/u/Tayyab_Ilyas)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 6:14am UTC](https://discuss.elastic.co/t/i-want-to-show-thats-ip-which-is-triggered/322788 "2023-01-10T06:14:52Z")

</div>

I want the detected anomaly's IP to show in the alert, I am attaching the picture for reference.

---

## [Mismatch between dotted lines and the default dark lines in Time Series of TSVB visualization](https://discuss.elastic.co/t/mismatch-between-dotted-lines-and-the-default-dark-lines-in-time-series-of-tsvb-visualization/319540)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 12\
**Last updated:** [December 13, 2022, 5:20am UTC](https://discuss.elastic.co/t/mismatch-between-dotted-lines-and-the-default-dark-lines-in-time-series-of-tsvb-visualization/319540 "2022-12-13T05:20:34Z")

</div>

Hi Team, In the Timeseries visualization, we can see dotted lines in the middle of the visualization which is matching exactly on top of the default dark lines. However, when we hover the mouse either on the left or …

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322780)

<div class="topic-metadata">

**Author:** [@Rishvana](https://discuss.elastic.co/u/Rishvana)\
**Replies:** 8\
**Last updated:** [January 10, 2023, 4:04am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322780 "2023-01-10T04:04:10Z")

</div>

Hi Team, We are not able to login to kibana application as it throws an error "Kibana server is not ready yet. we recently renewed ssl certificate for kibana and we done sanity check at that time it works fine. can let…

---

## [Force kibana into connecting to preferred ES node](https://discuss.elastic.co/t/force-kibana-into-connecting-to-preferred-es-node/322779)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 2:55am UTC](https://discuss.elastic.co/t/force-kibana-into-connecting-to-preferred-es-node/322779 "2023-01-10T02:55:10Z")

</div>

Hi, I've installed two instances of ES (co-ordinator only) running on a couple of machines, with a kibana instance. For kibana, I've set both of them as elasticsearch.hosts=\[es1, es2\] However, I'd always like it to talk…

---

## [Canvas Filters (filterrows)](https://discuss.elastic.co/t/canvas-filters-filterrows/321075)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 1:21am UTC](https://discuss.elastic.co/t/canvas-filters-filterrows/321075 "2022-12-13T01:21:00Z")

</div>

Hi, I'm starting to learn Canvas but struggling with a few concepts in the expression editor. I hope someone can point me in the correct direction. I'm trying to filter a table, using the current date. My table conta…

---

## [Dutation field type - days to weeks error](https://discuss.elastic.co/t/dutation-field-type-days-to-weeks-error/320996)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 4\
**Last updated:** [December 12, 2022, 9:11pm UTC](https://discuss.elastic.co/t/dutation-field-type-days-to-weeks-error/320996 "2022-12-12T21:11:15Z")

</div>

using a horizontal lens vis and a duration metric to human readable duration metrics, there appears to be a conversion miscalculation between days to weeks. the attached except shows the x axis increasing by 2.3 days un…

---

## [Define Multiple Conditions in an Alert](https://discuss.elastic.co/t/define-multiple-conditions-in-an-alert/322652)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 1:49pm UTC](https://discuss.elastic.co/t/define-multiple-conditions-in-an-alert/322652 "2023-01-09T13:49:41Z")

</div>

Is it possible to define multiple conditions in an alert? Based on this documentation (Alerting | Kibana Guide \[8.5\] | Elastic) it doesn't appear to. I would like to trigger an alert when 2 conditions are met. I want to …

---

## [CORS error while adding ServiceNow ITSM connector](https://discuss.elastic.co/t/cors-error-while-adding-servicenow-itsm-connector/321042)

<div class="topic-metadata">

**Author:** [@rakeshl](https://discuss.elastic.co/u/rakeshl)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 2:40pm UTC](https://discuss.elastic.co/t/cors-error-while-adding-servicenow-itsm-connector/321042 "2022-12-12T14:40:12Z")

</div>

I have installed ECK with kibana 8.5.3. I have used logstash to forward the logs to ELK stack. I am able to see the logs in kibana. Now, I am trying to integrate elastic to ServiceNow ITSM for creating incidents for the …

---

## [Lens Table - "wrong" selection of top N elements](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 8\
**Last updated:** [January 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784 "2023-01-09T11:12:53Z")

</div>

Hi! I want to display a table like this: | File Name | Number of warnings | | path/to/foo.cpp | 123 | | path/to/bar.cpp | 30 …

---

## [Unable to find Upgrade Assistant option in 8.3.3 version](https://discuss.elastic.co/t/unable-to-find-upgrade-assistant-option-in-8-3-3-version/322458)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [January 9, 2023, 11:46am UTC](https://discuss.elastic.co/t/unable-to-find-upgrade-assistant-option-in-8-3-3-version/322458 "2023-01-09T11:46:56Z")

</div>

Hi Team, we are trying to upgrade from version 8.2.3 to 8.5 but, unable to find Upgrade Assistant option. Kindly help us and let us know the process, how to upgrade to the latest version. Thanks.

---

## [Translation does not work in EUI Core components](https://discuss.elastic.co/t/translation-does-not-work-in-eui-core-components/322636)

<div class="topic-metadata">

**Author:** [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 11:10am UTC](https://discuss.elastic.co/t/translation-does-not-work-in-eui-core-components/322636 "2023-01-09T11:10:05Z")

</div>

Hi, We are using Elasticsearch 8.4.1 and some actions does not be translated. How to solve this problem? In the packages/core/i18n/core-i18n-browser-internal/src/i18n\_eui\_mapping.tsx file we find at line 1161 'euiQu…

---

## [Download csv file option directly on visualization/dashboard](https://discuss.elastic.co/t/download-csv-file-option-directly-on-visualization-dashboard/322658)

<div class="topic-metadata">

**Author:** [@amarkoli](https://discuss.elastic.co/u/amarkoli)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/download-csv-file-option-directly-on-visualization-dashboard/322658 "2023-01-09T11:02:27Z")

</div>

the Download CSV option in visible when clicked on the "Inspect" which is open when clicked on the 3 dots icons. But can we have the Download CSV option directly on the visualization/dashboard or somewhere else. if ther…

---

## [KQL Query Date filter on non timeseries data](https://discuss.elastic.co/t/kql-query-date-filter-on-non-timeseries-data/321839)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 4\
**Last updated:** [January 9, 2023, 10:44am UTC](https://discuss.elastic.co/t/kql-query-date-filter-on-non-timeseries-data/321839 "2023-01-09T10:44:56Z")

</div>

Hi, I'm tying to use Lens to plot data changing over a period of time. We generate the data once a week at single point in time, and so it doesn't look good as a time series. We also want to plot the count of a data …

---

## [Yearly reset of cumulative sum with monthly buckets](https://discuss.elastic.co/t/yearly-reset-of-cumulative-sum-with-monthly-buckets/321315)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 9:36am UTC](https://discuss.elastic.co/t/yearly-reset-of-cumulative-sum-with-monthly-buckets/321315 "2023-01-09T09:36:49Z")

</div>

Hello, i have a table lens with a monthly date histogram and a cumulative sum column. Is there a way to "reset" the cumulative sum to 0 at the start of a year? So 1.1.2007 would start with 0 instead of 3867 from the…

---

## [\[8.5.3\] Unable to download CSV from dashboard / visualizations](https://discuss.elastic.co/t/8-5-3-unable-to-download-csv-from-dashboard-visualizations/321835)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 8\
**Last updated:** [January 9, 2023, 9:14am UTC](https://discuss.elastic.co/t/8-5-3-unable-to-download-csv-from-dashboard-visualizations/321835 "2023-01-09T09:14:49Z")

</div>

None of my Kibana dashboard or viz have a "Download to CVS" option showing up in 8.5.3. What am I missing? Below is my setup: I've installed the 8.5.3 stack of elasticsearch and kibana from this official doc. My kibana…

---

## [Error: \[config validation of \[elasticsearch\].serviceAccountToken\]: serviceAccountToken cannot be specified when "username" is also set](https://discuss.elastic.co/t/error-config-validation-of-elasticsearch-serviceaccounttoken-serviceaccounttoken-cannot-be-specified-when-username-is-also-set/321020)

<div class="topic-metadata">

**Author:** [@iLucas.Bechlte.exe](https://discuss.elastic.co/u/iLucas.Bechlte.exe)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 11:04am UTC](https://discuss.elastic.co/t/error-config-validation-of-elasticsearch-serviceaccounttoken-serviceaccounttoken-cannot-be-specified-when-username-is-also-set/321020 "2022-12-12T11:04:39Z")

</div>

Hello, when I try to follow this instruction to secure my Elastic Stack, I will get this error: Error: \[config validation of \[elasticsearch\].serviceAccountToken\]: serviceAccountToken cannot be specified when "username"…

---

## [Elastic won't send data to Kibana](https://discuss.elastic.co/t/elastic-wont-send-data-to-kibana/318833)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 3\
**Last updated:** [November 14, 2022, 7:19am UTC](https://discuss.elastic.co/t/elastic-wont-send-data-to-kibana/318833 "2022-11-14T07:19:38Z")

</div>

Hallo, I have a configuration like the following, but elastic can't retrieve the logs. And the plain-log .log also doesn't show the activation log. How else can I confirm that logstash and filebeat are connected and tran…

---

## [Cluster health status changed from \[YELLOW\] to \[RED\] (reason: \[auto-create\] after changing path.data and path.log](https://discuss.elastic.co/t/cluster-health-status-changed-from-yellow-to-red-reason-auto-create-after-changing-path-data-and-path-log/320864)

<div class="topic-metadata">

**Author:** [@amiraliw](https://discuss.elastic.co/u/amiraliw)\
**Replies:** 1\
**Last updated:** [December 11, 2022, 11:58pm UTC](https://discuss.elastic.co/t/cluster-health-status-changed-from-yellow-to-red-reason-auto-create-after-changing-path-data-and-path-log/320864 "2022-12-11T23:58:12Z")

</div>

I have installed elasticsearch-8.4.3-x86\_64 and changed the path.data and path.log before I started the service. Permissions to the new pathes are more than needed as following: drwxrwsrwx. 2 elasticsearch elasticsearc…

---

## [A kibana startup question](https://discuss.elastic.co/t/a-kibana-startup-question/320611)

<div class="topic-metadata">

**Author:** [@laughting](https://discuss.elastic.co/u/laughting)\
**Replies:** 4\
**Last updated:** [December 11, 2022, 8:52pm UTC](https://discuss.elastic.co/t/a-kibana-startup-question/320611 "2022-12-11T20:52:04Z")

</div>

Why need to configure elasticsearch.password and elasticsaerch.username to start Kibana? What is initialized? Why not login directly through the account and password from the browser？

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/320962)

<div class="topic-metadata">

**Author:** [@Jinhyuck\_Cha](https://discuss.elastic.co/u/Jinhyuck_Cha)\
**Replies:** 1\
**Last updated:** [December 11, 2022, 4:38pm UTC](https://discuss.elastic.co/t/illegal-argument-exception/320962 "2022-12-11T16:38:55Z")

</div>

Hi i'm try to query to Elasticsearch in kibana But I got some error in there How can I solve it? this is my query POST dingo-dev-images-enriched-index-v1/\_search { "query": { "bool": { "filter": \[ …

---

## [Kibana painless scripted fields](https://discuss.elastic.co/t/kibana-painless-scripted-fields/316762)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 3\
**Last updated:** [October 18, 2022, 7:58am UTC](https://discuss.elastic.co/t/kibana-painless-scripted-fields/316762 "2022-10-18T07:58:21Z")

</div>

Hi elastic Team, I want to calculate the number of adults and children in every room. Below is an example of my document: "rooms": \[ { "pensionId": 16, "LibelleChambre": "Twin GardenView ", "MontantRemise": 0, "N…

---

## [Visualize data by two fields](https://discuss.elastic.co/t/visualize-data-by-two-fields/316819)

<div class="topic-metadata">

**Author:** [@Kohlman](https://discuss.elastic.co/u/Kohlman)\
**Replies:** 1\
**Last updated:** [October 18, 2022, 6:54am UTC](https://discuss.elastic.co/t/visualize-data-by-two-fields/316819 "2022-10-18T06:54:56Z")

</div>

We have multiple clients. Each client has there own instance of our database. While there may be subtle differences in schema as we continue to make enhancements. For purposes of this question we can assume they are the …

---

## [Status of hosts with ELK](https://discuss.elastic.co/t/status-of-hosts-with-elk/318738)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 3\
**Last updated:** [November 13, 2022, 11:08am UTC](https://discuss.elastic.co/t/status-of-hosts-with-elk/318738 "2022-11-13T11:08:03Z")

</div>

hello friends! I have the following task: it is necessary to monitor hundreds of hosts (virtual machines). now they are monitored using Nagios, but I want to get a clear visualization of the availability of hosts. ther…

---

## [Kibana time filter change dynamically API](https://discuss.elastic.co/t/kibana-time-filter-change-dynamically-api/316732)

<div class="topic-metadata">

**Author:** [@PabloCuestaGarcia](https://discuss.elastic.co/u/PabloCuestaGarcia)\
**Replies:** 1\
**Last updated:** [October 17, 2022, 11:48pm UTC](https://discuss.elastic.co/t/kibana-time-filter-change-dynamically-api/316732 "2022-10-17T23:48:21Z")

</div>

Hi all. I would like to know if it is possible to dynamically change the time range in Kibana according to the last load data. I mean, I have an ETL loading data every day, but some days the data comes empty, the proce…

---

## [Kibana error when enabling xpack security](https://discuss.elastic.co/t/kibana-error-when-enabling-xpack-security/322666)

<div class="topic-metadata">

**Author:** [@francis009](https://discuss.elastic.co/u/francis009)\
**Replies:** 7\
**Last updated:** [January 7, 2023, 4:23pm UTC](https://discuss.elastic.co/t/kibana-error-when-enabling-xpack-security/322666 "2023-01-07T16:23:49Z")

</div>

Hi, i've look through the forums and found many people having errors when enabling xpack, but not exactly my error, if i enable xpack on elasticsearch it pops up the log in when i access the website, but when i enable it…

---

## [Kibana Index not working after update](https://discuss.elastic.co/t/kibana-index-not-working-after-update/316796)

<div class="topic-metadata">

**Author:** [@Rommy](https://discuss.elastic.co/u/Rommy)\
**Replies:** 1\
**Last updated:** [October 17, 2022, 2:08pm UTC](https://discuss.elastic.co/t/kibana-index-not-working-after-update/316796 "2022-10-17T14:08:28Z")

</div>

Hello, A version update was made for the stack. After the update, there is a problem with the Kibana index. Before the update there was a Kibana version 7.10.2 (OpenDistro 1.13). Has been updated to version 7.13.4. {"t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=153)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=155)
