# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=167

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 168

---

## [Kibana Alerts add fields property](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999)

<div class="topic-metadata">

**Author:** [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Replies:** 4\
**Last updated:** [November 2, 2022, 5:24pm UTC](https://discuss.elastic.co/t/kibana-alerts-add-fields-property/317999 "2022-11-02T17:24:41Z")

</div>

I am trying to add an extra fields using script\_fields or runtime\_mappings to Kibana alerts. But Kibana replaces the property fields with some timestamp. Is there a solution or workaround? Edit #1 to add code Query /my…

---

## [Ignore-above](https://discuss.elastic.co/t/ignore-above/320064)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 4:15pm UTC](https://discuss.elastic.co/t/ignore-above/320064 "2022-11-29T16:15:29Z")

</div>

Hi, i could see ignore-above variable in index settings. What does this mean and does this applicable to both ELASTIC SEARCH Discovery and Kibana Lens view?

---

## [How to create an alert for windows event log?](https://discuss.elastic.co/t/how-to-create-an-alert-for-windows-event-log/319996)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 4:06pm UTC](https://discuss.elastic.co/t/how-to-create-an-alert-for-windows-event-log/319996 "2022-11-29T16:06:02Z")

</div>

Hi , I am completely new to this Alert creation. Need to create alert for winlogbeat with search guard. Does anyone have a template or know where I can find an example watch for an event log?

---

## [I am trying to create a memory usage alert in kibana but its showing 422 statuscode](https://discuss.elastic.co/t/i-am-trying-to-create-a-memory-usage-alert-in-kibana-but-its-showing-422-statuscode/319548)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 4:03pm UTC](https://discuss.elastic.co/t/i-am-trying-to-create-a-memory-usage-alert-in-kibana-but-its-showing-422-statuscode/319548 "2022-11-29T16:03:04Z")

</div>

Hi , i am trying to create a memory usage alert in kibana but its showing 422 statuscode, while i define & return application details. This is the source which i used where error is showing up. if i removed applicati…

---

## [Error when exporting more than 1000 saved objects](https://discuss.elastic.co/t/error-when-exporting-more-than-1000-saved-objects/317497)

<div class="topic-metadata">

**Author:** [@jonas27](https://discuss.elastic.co/u/jonas27)\
**Replies:** 7\
**Last updated:** [November 2, 2022, 12:57pm UTC](https://discuss.elastic.co/t/error-when-exporting-more-than-1000-saved-objects/317497 "2022-11-02T12:57:58Z")

</div>

Hi, I am hitting an error in our infrastructure when exporting more than =\< 1000 saved objects (visualizations in particular) from either the API or inside the dev tools. However, when exporting the same objects via a li…

---

## ["TypeError: You provided 'undefined' where a stream was expected. You can provide an Observable](https://discuss.elastic.co/t/typeerror-you-provided-undefined-where-a-stream-was-expected-you-can-provide-an-observable/320056)

<div class="topic-metadata">

**Author:** [@Rajitha\_Bizz](https://discuss.elastic.co/u/Rajitha_Bizz)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 2:12pm UTC](https://discuss.elastic.co/t/typeerror-you-provided-undefined-where-a-stream-was-expected-you-can-provide-an-observable/320056 "2022-11-29T14:12:38Z")

</div>

I facing this issue when we update kibana from 7.10.2 to 7.17.7. It is kind of strange behavior, there is a nginx proxy in between. {"type":"log","@timestamp":"2022-11-29T13:32:08+00:00","tags":\["error","http"\],"pid":2…

---

## [Mirror Kibanas on separate clusters](https://discuss.elastic.co/t/mirror-kibanas-on-separate-clusters/319814)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 9\
**Last updated:** [November 29, 2022, 9:50am UTC](https://discuss.elastic.co/t/mirror-kibanas-on-separate-clusters/319814 "2022-11-29T09:50:59Z")

</div>

Hey Everyone, Is there any way to sync Kibanas across multiple clusters? Essentially, a way to sync all visualizations, dashboards, queries, etc. from one Kibana to another. I'm aware that you can use remote reindex, an…

---

## [Runtime field issue creating a date/time field](https://discuss.elastic.co/t/runtime-field-issue-creating-a-date-time-field/317551)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 5\
**Last updated:** [November 2, 2022, 11:24am UTC](https://discuss.elastic.co/t/runtime-field-issue-creating-a-date-time-field/317551 "2022-11-02T11:24:12Z")

</div>

I am creating a new date field through Lens. The original field is coming through as text in the format '2022-10-25T16:04:35.320' In the Set Value field i have... if (doc.containsKey('sql.metrics.string.starttime')) { …

---

## [Multiple URL links in one field](https://discuss.elastic.co/t/multiple-url-links-in-one-field/319965)

<div class="topic-metadata">

**Author:** [@Harold\_Van\_der\_Veken](https://discuss.elastic.co/u/Harold_Van_der_Veken)\
**Replies:** 3\
**Last updated:** [November 29, 2022, 9:15am UTC](https://discuss.elastic.co/t/multiple-url-links-in-one-field/319965 "2022-11-29T09:15:00Z")

</div>

Is there a way to create a field that has more than 1 link to another resource. Can I create (and format) a string that holds 2 urls. E.g. "Goto \<this url\> or \<another url\>" \<this url\> can be selected to open the url. \<…

---

## [How to setup the text of an alert in Kibana?](https://discuss.elastic.co/t/how-to-setup-the-text-of-an-alert-in-kibana/320016)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 9:05am UTC](https://discuss.elastic.co/t/how-to-setup-the-text-of-an-alert-in-kibana/320016 "2022-11-29T09:05:01Z")

</div>

I have a question which I cannot find the answer for in docs: How t setup the text of an alert in Kibana? In above image, you can see some alerts from my rules. I'd like to change the text of the reason field to som…

---

## [Kibana console not working](https://discuss.elastic.co/t/kibana-console-not-working/320006)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 7:56am UTC](https://discuss.elastic.co/t/kibana-console-not-working/320006 "2022-11-29T07:56:41Z")

</div>

Hi all, While working on some queries today, all of a sudden my Kibana console stopped working. On inspecting the network console, I found that a request at /api/exception\_lists is failing with the status code 409 Confl…

---

## [Restrict permissions in roles to not download data table visualization CSV](https://discuss.elastic.co/t/restrict-permissions-in-roles-to-not-download-data-table-visualization-csv/319711)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [November 29, 2022, 5:03am UTC](https://discuss.elastic.co/t/restrict-permissions-in-roles-to-not-download-data-table-visualization-csv/319711 "2022-11-29T05:03:47Z")

</div>

Hi, I'm Using Kibana 7.10.0 Is there a way(role) to show Dashboard/Visualization & user should not download CSV of the data table visualization ? I'm having dashboard with data table visualizations. I have tried diff…

---

## [Missing .keyword fields](https://discuss.elastic.co/t/missing-keyword-fields/317610)

<div class="topic-metadata">

**Author:** [@khaoz](https://discuss.elastic.co/u/khaoz)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 10:08am UTC](https://discuss.elastic.co/t/missing-keyword-fields/317610 "2022-11-02T10:08:18Z")

</div>

Hello, I am quite new to ELK and I am facing the following issue. For some reason, the .keyword fields (e.g. hostname.keyword) are not being populated in Kibana and I cannot use them in setting up alerts etc. Let's t…

---

## [Creating an index pattern](https://discuss.elastic.co/t/creating-an-index-pattern/319799)

<div class="topic-metadata">

**Author:** [@Swathi\_S](https://discuss.elastic.co/u/Swathi_S)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 2:26am UTC](https://discuss.elastic.co/t/creating-an-index-pattern/319799 "2022-11-29T02:26:14Z")

</div>

Need help for creation on index pattern in kibana

---

## [Kibana server is not ready yet 8.5](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-8-5/319786)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 7\
**Last updated:** [November 29, 2022, 1:05am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-8-5/319786 "2022-11-29T01:05:57Z")

</div>

I was using ELK 8.4 and everything was working fine until I saw pending updates on the server which included Elastic and Kibana 8.5 updates. AND after upgrading both services are in active running status but kibana givi…

---

## [Aliases not created in Index management](https://discuss.elastic.co/t/aliases-not-created-in-index-management/319052)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 12:55am UTC](https://discuss.elastic.co/t/aliases-not-created-in-index-management/319052 "2022-11-29T00:55:11Z")

</div>

Hi Team, We are facing index lifecycle error in index management and it couldn't be rollover also, it shows Aliases as none status. Could you please help us to fix the issue. Please find the attached snapshot. Regar…

---

## [Kibana dashboards - global filter vs individual filters performance](https://discuss.elastic.co/t/kibana-dashboards-global-filter-vs-individual-filters-performance/319961)

<div class="topic-metadata">

**Author:** [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Replies:** 2\
**Last updated:** [November 29, 2022, 12:51am UTC](https://discuss.elastic.co/t/kibana-dashboards-global-filter-vs-individual-filters-performance/319961 "2022-11-29T00:51:34Z")

</div>

Right now I have three objects on a dashboard (one saved search, two data table lens) that are using the logs-system\* namespace. Each LENs is using this filter: event.dataset:"system.system" Is there any performance …

---

## [Text Markdown visualization fails when copying to other spaces](https://discuss.elastic.co/t/text-markdown-visualization-fails-when-copying-to-other-spaces/317900)

<div class="topic-metadata">

**Author:** [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 10:03am UTC](https://discuss.elastic.co/t/text-markdown-visualization-fails-when-copying-to-other-spaces/317900 "2022-11-02T10:03:00Z")

</div>

Hello, I have a Dashboard with a text visualization that I use to jump from that Dashboard to another. This is the markdown of the visualization: \[Nginx logs overview\](#/dashboard/39ad9660-3e40-11ed-ab98-8766b05540f5)…

---

## [How to find the button for creating a dashboard?](https://discuss.elastic.co/t/how-to-find-the-button-for-creating-a-dashboard/319976)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 1\
**Last updated:** [November 28, 2022, 11:24pm UTC](https://discuss.elastic.co/t/how-to-find-the-button-for-creating-a-dashboard/319976 "2022-11-28T23:24:20Z")

</div>

Hi, i am stuck in a fresh installed Cloud-Trial version having no option to create a dashboard. What i see if i click on the 3 stripes and then on "dashboard" is: But what i want to see is something l…

---

## [Visualize changes of an aggregation result over time](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897)

<div class="topic-metadata">

**Author:** [@daverin](https://discuss.elastic.co/u/daverin)\
**Replies:** 2\
**Last updated:** [November 28, 2022, 7:53pm UTC](https://discuss.elastic.co/t/visualize-changes-of-an-aggregation-result-over-time/319897 "2022-11-28T19:53:48Z")

</div>

Hi there. I have been using Elastic for the past year but I am relatively new to Kibana. Basic info on my setup and usecase: I have my database records streaming into Elastic via Kafka Connect. When a record changes i…

---

## [Problem in elasticsearch-create-enrollment-token for Kibana](https://discuss.elastic.co/t/problem-in-elasticsearch-create-enrollment-token-for-kibana/319645)

<div class="topic-metadata">

**Author:** [@Clonky](https://discuss.elastic.co/u/Clonky)\
**Replies:** 6\
**Last updated:** [November 28, 2022, 3:18pm UTC](https://discuss.elastic.co/t/problem-in-elasticsearch-create-enrollment-token-for-kibana/319645 "2022-11-28T15:18:49Z")

</div>

Hello all, I have a new installation of Elasticsearch 8.2 and KIbana 8.2 on my Windows Server. I have installed it on a Windows Server. Elasticsearch is up and running and configured to be an Windows Service. I can ac…

---

## [The length of the variable to display on visualization](https://discuss.elastic.co/t/the-length-of-the-variable-to-display-on-visualization/319510)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 5\
**Last updated:** [November 28, 2022, 1:37pm UTC](https://discuss.elastic.co/t/the-length-of-the-variable-to-display-on-visualization/319510 "2022-11-28T13:37:30Z")

</div>

Hi, i am sending a variable tag to the logs. I can see the variable value in elastic discovery but I am unable to see the value of that particular variable for a particular value on the lens table. if the length of the …

---

## [Max limit context value in Kibana Alerts](https://discuss.elastic.co/t/max-limit-context-value-in-kibana-alerts/319929)

<div class="topic-metadata">

**Author:** [@Danny\_Dijkzeul](https://discuss.elastic.co/u/Danny_Dijkzeul)\
**Replies:** 0\
**Last updated:** [November 28, 2022, 9:45am UTC](https://discuss.elastic.co/t/max-limit-context-value-in-kibana-alerts/319929 "2022-11-28T09:45:10Z")

</div>

Hi, I have a short question. In the standard Kibana Alert, there is a way to represent the value as {{context.value}}. However in the message it is always limited to 10.000, is there a way to show the real value?

---

## [Disable scroll instructions on map](https://discuss.elastic.co/t/disable-scroll-instructions-on-map/317625)

<div class="topic-metadata">

**Author:** [@Cory34](https://discuss.elastic.co/u/Cory34)\
**Replies:** 5\
**Last updated:** [November 1, 2022, 12:56am UTC](https://discuss.elastic.co/t/disable-scroll-instructions-on-map/317625 "2022-11-01T00:56:00Z")

</div>

How do we disable the "Use control + scroll to zoom the map..." message which appears on the map? Thanks.

---

## [Why does my Elastic 7.10.2 have automatic report generation and no automatic sending function?](https://discuss.elastic.co/t/why-does-my-elastic-7-10-2-have-automatic-report-generation-and-no-automatic-sending-function/318718)

<div class="topic-metadata">

**Author:** [@qiang\_tang](https://discuss.elastic.co/u/qiang_tang)\
**Replies:** 2\
**Last updated:** [November 28, 2022, 2:06am UTC](https://discuss.elastic.co/t/why-does-my-elastic-7-10-2-have-automatic-report-generation-and-no-automatic-sending-function/318718 "2022-11-28T02:06:51Z")

</div>

Without this function "From the Kibana toolbar, click Share, then select PDF Reports." The URL cannot be generated, but the report can be automatically generated. Is there any other way to automatically send the report …

---

## [Better way of displaying KNN results in Kibana?](https://discuss.elastic.co/t/better-way-of-displaying-knn-results-in-kibana/317104)

<div class="topic-metadata">

**Author:** [@freddyh](https://discuss.elastic.co/u/freddyh)\
**Replies:** 1\
**Last updated:** [October 31, 2022, 9:58am UTC](https://discuss.elastic.co/t/better-way-of-displaying-knn-results-in-kibana/317104 "2022-10-31T09:58:06Z")

</div>

I'm using the approximate kNN feature to index a vector for searching. With the previous exact kNN method I was able to craft a URL string for the script\_score query, but I haven't been able to replicate that with the ap…

---

## [Power of Kibana with complex aggregations that I usually run in Excel](https://discuss.elastic.co/t/power-of-kibana-with-complex-aggregations-that-i-usually-run-in-excel/319864)

<div class="topic-metadata">

**Author:** [@auato](https://discuss.elastic.co/u/auato)\
**Replies:** 0\
**Last updated:** [November 26, 2022, 4:37pm UTC](https://discuss.elastic.co/t/power-of-kibana-with-complex-aggregations-that-i-usually-run-in-excel/319864 "2022-11-26T16:37:41Z")

</div>

I'm used to processing a huge amount of raw data (typically hundreds of thousands of rows, whole months of data per day, per hour, per detail). In Excel I perform some aggregations and calculations as shown in picture an…

---

## [How can we roll up all the aggregation data indices have?](https://discuss.elastic.co/t/how-can-we-roll-up-all-the-aggregation-data-indices-have/317436)

<div class="topic-metadata">

**Author:** [@Nitin08bisht](https://discuss.elastic.co/u/Nitin08bisht)\
**Replies:** 5\
**Last updated:** [October 31, 2022, 2:13am UTC](https://discuss.elastic.co/t/how-can-we-roll-up-all-the-aggregation-data-indices-have/317436 "2022-10-31T02:13:30Z")

</div>

How can we roll up all the aggregation data indices have? And If we do rollup of all the aggregation which indices have than will there be any difference between the size of actual and rollup indices or not?

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/319776)

<div class="topic-metadata">

**Author:** [@Dmitriy\_Esin](https://discuss.elastic.co/u/Dmitriy_Esin)\
**Replies:** 9\
**Last updated:** [November 25, 2022, 4:21pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/319776 "2022-11-25T16:21:01Z")

</div>

Hi! I trying to install EFK stack into my k8s GCP cluster. I use official helm charts from https://helm.elastic.co: elasticsearch and kibana I use automatically generated certificates and credentials on deployment sta…

---

## [Index-wise conditions in Kibana watchers](https://discuss.elastic.co/t/index-wise-conditions-in-kibana-watchers/319622)

<div class="topic-metadata">

**Author:** [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Replies:** 1\
**Last updated:** [November 25, 2022, 4:10pm UTC](https://discuss.elastic.co/t/index-wise-conditions-in-kibana-watchers/319622 "2022-11-25T16:10:15Z")

</div>

Hi All, We are using Elasticsearch watchers for getting the total data ingested from each index. But since we are having different ILMs for each index, we are not able to get the average data ingested for a particular d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=166)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=168)
