# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=162

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 163

---

## [Hierarchical topology in Kibana Graph - Is it possible to construct a hierarchical topology?](https://discuss.elastic.co/t/hierarchical-topology-in-kibana-graph-is-it-possible-to-construct-a-hierarchical-topology/321522)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 2\
**Last updated:** [December 19, 2022, 8:46am UTC](https://discuss.elastic.co/t/hierarchical-topology-in-kibana-graph-is-it-possible-to-construct-a-hierarchical-topology/321522 "2022-12-19T08:46:35Z")

</div>

Is it possible to construct a hierarchical topology, and if so, how do users pass data for that?

---

## [0 hits in preview result with custom query](https://discuss.elastic.co/t/0-hits-in-preview-result-with-custom-query/315484)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 2\
**Last updated:** [October 25, 2022, 2:15pm UTC](https://discuss.elastic.co/t/0-hits-in-preview-result-with-custom-query/315484 "2022-10-25T14:15:09Z")

</div>

Hi, I am trying to create a custom query detection rule in kibana 7.16, the query is as simple as this: dstcountry.keyword : "Spain" when i click on preview results it returns 0 hits, but in the discover i get almos…

---

## [Setting Time Filter to a default date](https://discuss.elastic.co/t/setting-time-filter-to-a-default-date/321494)

<div class="topic-metadata">

**Author:** [@Hasan](https://discuss.elastic.co/u/Hasan)\
**Replies:** 2\
**Last updated:** [December 19, 2022, 8:27am UTC](https://discuss.elastic.co/t/setting-time-filter-to-a-default-date/321494 "2022-12-19T08:27:47Z")

</div>

Hello, I have a dashboard which is querying data on the basis of Time Filter values. As my data consists of values more than a year so I want to set the Time Filter to past 12 months as a default value from 15 mins. Plea…

---

## [Need help in kibana customization](https://discuss.elastic.co/t/need-help-in-kibana-customization/321524)

<div class="topic-metadata">

**Author:** [@Maneesha](https://discuss.elastic.co/u/Maneesha)\
**Replies:** 7\
**Last updated:** [December 19, 2022, 7:35am UTC](https://discuss.elastic.co/t/need-help-in-kibana-customization/321524 "2022-12-19T07:35:35Z")

</div>

Is it possible to add dashboard name (custom dashboard name) on top of search query and time filter instead of top bar Because we are hiding the top bar as per requirement. if we hide top bar then dashboard name also hi…

---

## [EFK missing geo\_point](https://discuss.elastic.co/t/efk-missing-geo-point/321445)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 2\
**Last updated:** [December 19, 2022, 12:48am UTC](https://discuss.elastic.co/t/efk-missing-geo-point/321445 "2022-12-19T00:48:37Z")

</div>

I am running EFK using ECK 8.5.3. fluentd ConfigMap: @type geoip # Specify one or more geoip lookup field which has ip address (default: host) geoip\_lookup\_keys IP # Specify optional geoip datab…

---

## [Logs isn't showing in kibana](https://discuss.elastic.co/t/logs-isnt-showing-in-kibana/319250)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 2\
**Last updated:** [November 21, 2022, 5:20am UTC](https://discuss.elastic.co/t/logs-isnt-showing-in-kibana/319250 "2022-11-21T05:20:03Z")

</div>

Dear Team, Due to certain server dependency problems, my Elk server recently crashed. To recover Elk, I used an old Elk snapshot of the server and updated all configuration settings for the new IP. unable to access the…

---

## [How to make kibana alerting send email content to add report？](https://discuss.elastic.co/t/how-to-make-kibana-alerting-send-email-content-to-add-report/321080)

<div class="topic-metadata">

**Author:** [@qiang\_tang](https://discuss.elastic.co/u/qiang_tang)\
**Replies:** 2\
**Last updated:** [December 18, 2022, 10:40pm UTC](https://discuss.elastic.co/t/how-to-make-kibana-alerting-send-email-content-to-add-report/321080 "2022-12-18T22:40:52Z")

</div>

How does kibana send the automatically generated report to my mailbox by email, my Elastic It is "Amazon OpenSearch Service". Only the alarm set in the "Alerting" function has the function of sending emails. Can I add a…

---

## [Does kibana watcher action supports painless script?](https://discuss.elastic.co/t/does-kibana-watcher-action-supports-painless-script/317408)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [October 25, 2022, 11:41am UTC](https://discuss.elastic.co/t/does-kibana-watcher-action-supports-painless-script/317408 "2022-10-25T11:41:37Z")

</div>

Hi Experts, Is it possible to write painless script mentioned below under kibana watcher action? I checked foreach example mentioned in elastic.co documentation; however, I am not sure if it supports inner loops. scri…

---

## [Grouping nested fileds instead of creating new fields](https://discuss.elastic.co/t/grouping-nested-fileds-instead-of-creating-new-fields/319373)

<div class="topic-metadata">

**Author:** [@mehdi\_hadeli](https://discuss.elastic.co/u/mehdi_hadeli)\
**Replies:** 0\
**Last updated:** [November 20, 2022, 7:42pm UTC](https://discuss.elastic.co/t/grouping-nested-fileds-instead-of-creating-new-fields/319373 "2022-11-20T19:42:42Z")

</div>

Hi, I used kibana and elastic v7.13.3, I want my nested fields put inner outer filed in json format instead of creating seperate field for each of them. { "fields.ExceptionDetail.ValidationResultModel.Errors.Message.k…

---

## [Existing "elastic" user credentials continue to function after upgrading elasticsearch?](https://discuss.elastic.co/t/existing-elastic-user-credentials-continue-to-function-after-upgrading-elasticsearch/317240)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 2\
**Last updated:** [October 25, 2022, 5:05am UTC](https://discuss.elastic.co/t/existing-elastic-user-credentials-continue-to-function-after-upgrading-elasticsearch/317240 "2022-10-25T05:05:34Z")

</div>

Hello, Team. I understand that the elastic and kibana versions should be the same. Please verify. Additionally, confirm Existing "elastic" user credentials continue to work after elasticsearch is upgraded? Alternative…

---

## [Graph in lens shows different value compared to graph in TSVB](https://discuss.elastic.co/t/graph-in-lens-shows-different-value-compared-to-graph-in-tsvb/321379)

<div class="topic-metadata">

**Author:** [@sixsenseninja](https://discuss.elastic.co/u/sixsenseninja)\
**Replies:** 6\
**Last updated:** [December 18, 2022, 3:04am UTC](https://discuss.elastic.co/t/graph-in-lens-shows-different-value-compared-to-graph-in-tsvb/321379 "2022-12-18T03:04:42Z")

</div>

I am creating to 2 graph, from two different graph type, tsvb and graph. Both datasets using same filter and aggregation but i realize that there is a noticeable gap between both graph. See image attached. Top graph show…

---

## [How to edit the query of a lens?](https://discuss.elastic.co/t/how-to-edit-the-query-of-a-lens/321467)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [December 18, 2022, 2:30am UTC](https://discuss.elastic.co/t/how-to-edit-the-query-of-a-lens/321467 "2022-12-18T02:30:54Z")

</div>

Packetbeat made this lens for me: But it's not clear to me what constructed the query under Inspect\>Requests\>Data\>Requests and how I am supposed to edit it, see this image: I looked through all the other panel se…

---

## [Kibana - A secure connection is required for log in](https://discuss.elastic.co/t/kibana-a-secure-connection-is-required-for-log-in/321311)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 2\
**Last updated:** [December 17, 2022, 1:38am UTC](https://discuss.elastic.co/t/kibana-a-secure-connection-is-required-for-log-in/321311 "2022-12-17T01:38:53Z")

</div>

Good morning, I am trying setup NGINX to use proxy reverse to access my kibana. The first idea is redirect traffic on http://172.20.6.213:8080 to https://172.20.6.213:5601. My nginx setup below: I received this mes…

---

## [Kibana discover query where two fields are not the same?](https://discuss.elastic.co/t/kibana-discover-query-where-two-fields-are-not-the-same/321431)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [December 16, 2022, 10:18pm UTC](https://discuss.elastic.co/t/kibana-discover-query-where-two-fields-are-not-the-same/321431 "2022-12-16T22:18:33Z")

</div>

I tried running a query like NOT client.geo.country\_iso\_code: source.geo.country\_iso\_code, but it returned results where client.geo.country\_iso\_code == source.geo.country\_iso\_code Anyone know what's wrong with my que…

---

## [How to get the deleted watcher in kibana](https://discuss.elastic.co/t/how-to-get-the-deleted-watcher-in-kibana/317117)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 11:17pm UTC](https://discuss.elastic.co/t/how-to-get-the-deleted-watcher-in-kibana/317117 "2022-10-23T23:17:17Z")

</div>

Hi team, We unfortunately deleted the watcher in Kibana. Could you please tell us, how can we retrieve the same watcher script. Thanks, Yasar Arafaath A.

---

## [Shard Failed. Null Node](https://discuss.elastic.co/t/shard-failed-null-node/317204)

<div class="topic-metadata">

**Author:** [@Shep](https://discuss.elastic.co/u/Shep)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 11:07pm UTC](https://discuss.elastic.co/t/shard-failed-null-node/317204 "2022-10-23T23:07:29Z")

</div>

Kibana 7.14 I am getting a "no\_shard\_available\_action\_exception". It seems to be suggesting the reason is because the node is "null". Any Advice? { "took": 65, "timed\_out": false, "\_shards": { "total": 13…

---

## [Parse context\_hits](https://discuss.elastic.co/t/parse-context-hits/321299)

<div class="topic-metadata">

**Author:** [@Pablo\_Sagrera\_Garcia](https://discuss.elastic.co/u/Pablo_Sagrera_Garcia)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 12:13pm UTC](https://discuss.elastic.co/t/parse-context-hits/321299 "2022-12-16T12:13:13Z")

</div>

I've create a rule whose connector is write to index. I wonder if possible to parse context\_hits to create an additional field when hit the rule. For example I would like to create an additional field called message o…

---

## [Order of documents when using a transform](https://discuss.elastic.co/t/order-of-documents-when-using-a-transform/321183)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 4\
**Last updated:** [December 16, 2022, 10:51am UTC](https://discuss.elastic.co/t/order-of-documents-when-using-a-transform/321183 "2022-12-16T10:51:00Z")

</div>

I'm using elasticsearch to store the events data for web sessions. Each event is it's own document. Then I'm using transforms to aggregate this data grouping them by a sessionId key and also creating a field eventFlow wh…

---

## [One line per year with monthly buckets in line chart](https://discuss.elastic.co/t/one-line-per-year-with-monthly-buckets-in-line-chart/321294)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 13\
**Last updated:** [December 15, 2022, 5:41pm UTC](https://discuss.elastic.co/t/one-line-per-year-with-monthly-buckets-in-line-chart/321294 "2022-12-15T17:41:47Z")

</div>

Hello, i have a line chart with a date histogram with monthly buckets on the horizontal axis. And a proportion of two cumulative sums on the vertical axis. Is there a way to overlay all years to have only a single y…

---

## [Logs in discover tab are in ascending order](https://discuss.elastic.co/t/logs-in-discover-tab-are-in-ascending-order/321252)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 6:13am UTC](https://discuss.elastic.co/t/logs-in-discover-tab-are-in-ascending-order/321252 "2022-12-16T06:13:28Z")

</div>

Hi, As u can see in the image the logs are showing the timestamp of Dec 12 first. The latest one's are of Dec 15. elasticsearch\_syslog is the data view created for indices elasticsearch\_syslog%timestamp. What can i d…

---

## [Sort bucket and metrics columns in Data table](https://discuss.elastic.co/t/sort-bucket-and-metrics-columns-in-data-table/319130)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 10:22am UTC](https://discuss.elastic.co/t/sort-bucket-and-metrics-columns-in-data-table/319130 "2022-12-15T10:22:23Z")

</div>

Hello, I'm using version 8.4.3 of elastic cloud. I have a data table with 5 butckets (split row) and 4 metrics. From what I understand, the buckets columns are always before and the metrics columns are after. I would l…

---

## [How to enable HTTPS and security for my Dev ELK Stack Cluster?](https://discuss.elastic.co/t/how-to-enable-https-and-security-for-my-dev-elk-stack-cluster/321222)

<div class="topic-metadata">

**Author:** [@swethanannam1325](https://discuss.elastic.co/u/swethanannam1325)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 10:09am UTC](https://discuss.elastic.co/t/how-to-enable-https-and-security-for-my-dev-elk-stack-cluster/321222 "2022-12-15T10:09:35Z")

</div>

Hi, I'm new to Elastic Stack and I've setup Dev environment in my local machine. Can someone guide me on how to enable security for my Elasticsearch and Kibana. Also, do share me any documentation if available.

---

## [Kibana 8.2.3 "Donut chart can't render with negative values"](https://discuss.elastic.co/t/kibana-8-2-3-donut-chart-cant-render-with-negative-values/314508)

<div class="topic-metadata">

**Author:** [@nesretep](https://discuss.elastic.co/u/nesretep)\
**Replies:** 20\
**Last updated:** [October 20, 2022, 4:08pm UTC](https://discuss.elastic.co/t/kibana-8-2-3-donut-chart-cant-render-with-negative-values/314508 "2022-10-20T16:08:21Z")

</div>

Previously donuts and pies just rendered. Now this message is shown when negative values exist on buckets. How can this message be turned off, and thereby achieve the rendering of all buckets which are in fact positive. …

---

## [Unrecognized function: kibanaRemoveFilter](https://discuss.elastic.co/t/unrecognized-function-kibanaremovefilter/321274)

<div class="topic-metadata">

**Author:** [@Jaro](https://discuss.elastic.co/u/Jaro)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 8:56am UTC](https://discuss.elastic.co/t/unrecognized-function-kibanaremovefilter/321274 "2022-12-15T08:56:01Z")

</div>

Hello, I get a visualisation error in Kibana: Unrecognized function: kibanaRemoveFilter The Vega code for the visualisation is below. It worked before we upgraded Kibana to OpenSearch 2.2.1 Would anyone know why is …

---

## [Exporting data from a visualization](https://discuss.elastic.co/t/exporting-data-from-a-visualization/320976)

<div class="topic-metadata">

**Author:** [@zivza](https://discuss.elastic.co/u/zivza)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 12:14am UTC](https://discuss.elastic.co/t/exporting-data-from-a-visualization/320976 "2022-12-15T00:14:52Z")

</div>

Hi, I'm new to Kibana, and I need to export some data from a table visualization (pull it once in a while, with the current time), using python. What I actually want, is basically a csv or a JSONI can turn to a pandas …

---

## [Edit protection for Kibana visuals or dashboards](https://discuss.elastic.co/t/edit-protection-for-kibana-visuals-or-dashboards/321238)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 12:04am UTC](https://discuss.elastic.co/t/edit-protection-for-kibana-visuals-or-dashboards/321238 "2022-12-15T00:04:07Z")

</div>

Hello, I was wondering if there was a way to protect Kibana visuals or dashboards from being edited? Even sending a warning if they open the object to not to edit it would be the bare minimal. Mike

---

## [Scrollbar disappeared in Vega](https://discuss.elastic.co/t/scrollbar-disappeared-in-vega/320428)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 5:05pm UTC](https://discuss.elastic.co/t/scrollbar-disappeared-in-vega/320428 "2022-12-14T17:05:59Z")

</div>

Hello, I'm using a graphic developed in Vega in my Dashboard. The "autosize" property is set to "fit-x". It used to show a vertical scrollbar when I was running Elastic 8.3, but since I upgraded to 8.4 and now to 8.5 (8…

---

## [How to access Kibana in different VM](https://discuss.elastic.co/t/how-to-access-kibana-in-different-vm/321224)

<div class="topic-metadata">

**Author:** [@Vivek\_Arumugam](https://discuss.elastic.co/u/Vivek_Arumugam)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 3:37pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-in-different-vm/321224 "2022-12-14T15:37:19Z")

</div>

Hi Team, I have installed Kibana and Elasticsearch in server. I am able access Kibana in same machine. But in different VM it not working. Please help me out

---

## [Drill down in bar vertical stacked in Lens Visuaization gives incorrect output from the parent dashboard](https://discuss.elastic.co/t/drill-down-in-bar-vertical-stacked-in-lens-visuaization-gives-incorrect-output-from-the-parent-dashboard/320627)

<div class="topic-metadata">

**Author:** [@Diya\_19](https://discuss.elastic.co/u/Diya_19)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 2:08pm UTC](https://discuss.elastic.co/t/drill-down-in-bar-vertical-stacked-in-lens-visuaization-gives-incorrect-output-from-the-parent-dashboard/320627 "2022-12-14T14:08:45Z")

</div>

I have created a bar vertical stacked graph to get the response status codes (HTTP 200s, 300s, 400s and 500s). I have applied a drill down through which we can filter through the http code in the drill down dashboard whi…

---

## [How to aggregate data across multiple fields?](https://discuss.elastic.co/t/how-to-aggregate-data-across-multiple-fields/318943)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 4\
**Last updated:** [November 16, 2022, 3:14pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-across-multiple-fields/318943 "2022-11-16T15:14:59Z")

</div>

Hi! I'm fairly new to Kibana. I'm trying to perform data aggregation across multiple fields, but don't seem to be approaching the problem the right way. Example use case: I have data about house prices. E.g. house "a" …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=161)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=163)
