# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=172

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 173

---

## [Kibana logs when in developer mode](https://discuss.elastic.co/t/kibana-logs-when-in-developer-mode/316329)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [November 8, 2022, 3:20pm UTC](https://discuss.elastic.co/t/kibana-logs-when-in-developer-mode/316329 "2022-11-08T15:20:43Z")

</div>

Hi, How can I see kibana logs when in developer mode? The log is not getting written to the file I mention in the kibana.yml file I am using Kibana 7.17 in developer mode Thanks

---

## [FATAL Error: Port 5601 is already in use. Another instance of Kibana may be running!](https://discuss.elastic.co/t/fatal-error-port-5601-is-already-in-use-another-instance-of-kibana-may-be-running/318383)

<div class="topic-metadata">

**Author:** [@Shadow\_CHN](https://discuss.elastic.co/u/Shadow_CHN)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 3:13pm UTC](https://discuss.elastic.co/t/fatal-error-port-5601-is-already-in-use-another-instance-of-kibana-may-be-running/318383 "2022-11-08T15:13:28Z")

</div>

Hello Team I installed Kibana in docker, while the first set up it showed \[2022-11-07T09:58:18.929+00:00\]\[INFO \]\[node\] Kibana process configured with roles: \[background\_tasks, ui\] \[2022-11-07T09:58:40.484+00:00\]\[INFO \]…

---

## [KQL query for fields with a value which is not \`-\`](https://discuss.elastic.co/t/kql-query-for-fields-with-a-value-which-is-not/318098)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 7\
**Last updated:** [November 8, 2022, 11:12am UTC](https://discuss.elastic.co/t/kql-query-for-fields-with-a-value-which-is-not/318098 "2022-11-08T11:12:08Z")

</div>

Kibana 7.17. I've got some indices where documents contain a field called username . Sometimes the value is a username, like bob or alice and often the value is -. What's a KQL query that will return documents where …

---

## [Hide/Disable runtime fields from Kibana available fields](https://discuss.elastic.co/t/hide-disable-runtime-fields-from-kibana-available-fields/301848)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 11\
**Last updated:** [November 8, 2022, 9:34am UTC](https://discuss.elastic.co/t/hide-disable-runtime-fields-from-kibana-available-fields/301848 "2022-11-08T09:34:09Z")

</div>

Hi, Is there a way to hide/disable/pick certain runtime fields from available fields in Discover? When applying many runtime fields, Discover page takes forever to load due to the number of available fields, While Elast…

---

## [Node Uptime Bar Graph](https://discuss.elastic.co/t/node-uptime-bar-graph/318385)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 6:52am UTC](https://discuss.elastic.co/t/node-uptime-bar-graph/318385 "2022-11-08T06:52:20Z")

</div>

Hi Community, ELK version 7.17.5. We want to monitor Node/System availability using metricbeat. We want to create a bar graph of this. I created a dashboard for this The issue i am facing here is for one node i am…

---

## [Data Indices are recovery](https://discuss.elastic.co/t/data-indices-are-recovery/316887)

<div class="topic-metadata">

**Author:** [@Ravi\_S1](https://discuss.elastic.co/u/Ravi_S1)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 5:19am UTC](https://discuss.elastic.co/t/data-indices-are-recovery/316887 "2022-11-08T05:19:52Z")

</div>

I would like to check with community on recovery state of indices... after upgrading the ELK stack to 8.4.1, i could see that data indices are recovering very often.. Is there any reason for this behavior. GET \_cat/reco…

---

## [No results in Kibana search](https://discuss.elastic.co/t/no-results-in-kibana-search/318378)

<div class="topic-metadata">

**Author:** [@azamf](https://discuss.elastic.co/u/azamf)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 3:09am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378 "2022-11-08T03:09:24Z")

</div>

I'm trying to search against an existing index but the request yields no results. I know there is data since other users can see the index and view data in the same time frame. I am able to view data in most indices in …

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[centrologs\] does not point to index \[centrologs-2022.09.28-000001\] in Kibana 8.2.2](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-centrologs-does-not-point-to-index-centrologs-2022-09-28-000001-in-kibana-8-2-2/315962)

<div class="topic-metadata">

**Author:** [@lakshmiD](https://discuss.elastic.co/u/lakshmiD)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 10:19pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-centrologs-does-not-point-to-index-centrologs-2022-09-28-000001-in-kibana-8-2-2/315962 "2022-10-10T22:19:57Z")

</div>

Hi Team, Index lifecycle error-Policy rollover happening untill hot phase not going to next step illegal\_argument\_exception: index.lifecycle.rollover\_alias \[centrologs\] does not point to index \[centrologs-2022.09.28\] M…

---

## [Visualize Custom Time from a Scripted Field](https://discuss.elastic.co/t/visualize-custom-time-from-a-scripted-field/318272)

<div class="topic-metadata">

**Author:** [@g.bas](https://discuss.elastic.co/u/g.bas)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 4:42pm UTC](https://discuss.elastic.co/t/visualize-custom-time-from-a-scripted-field/318272 "2022-11-07T16:42:51Z")

</div>

Hello I am new to Kibana and would like to create my own visual representation where the horizontal axis represents time which is derived from one of my runtime fields. The field is called Duration and is in milliseconds…

---

## [Is it possible to create sum of counter\_rate across implicit dimensions](https://discuss.elastic.co/t/is-it-possible-to-create-sum-of-counter-rate-across-implicit-dimensions/318343)

<div class="topic-metadata">

**Author:** [@wiki.warx](https://discuss.elastic.co/u/wiki.warx)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 3:45pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-sum-of-counter-rate-across-implicit-dimensions/318343 "2022-11-07T15:45:28Z")

</div>

I have metric reported from application (let's call it) tasks. This metric is reported as counter by multiple instances of application. In addition this metric is reported per clientid and per userid (both are UUIDs). I…

---

## [Time Filter Element in Canvas](https://discuss.elastic.co/t/time-filter-element-in-canvas/318246)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 1:50pm UTC](https://discuss.elastic.co/t/time-filter-element-in-canvas/318246 "2022-11-07T13:50:02Z")

</div>

For this problem, I'm on version 7.11.1 and viewing Kibana in Chrome. When I add the time filter element to a Canvas workpad, it is not functional (when I click on the time control, it doesn't respond to let me select th…

---

## [Need to display only row records that shows only MAX/MIN Value count among all the records.(Kibana table or Enhanced table)](https://discuss.elastic.co/t/need-to-display-only-row-records-that-shows-only-max-min-value-count-among-all-the-records-kibana-table-or-enhanced-table/318116)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [November 7, 2022, 7:48am UTC](https://discuss.elastic.co/t/need-to-display-only-row-records-that-shows-only-max-min-value-count-among-all-the-records-kibana-table-or-enhanced-table/318116 "2022-11-07T07:48:46Z")

</div>

Hello All, I want to achieve this usecase where I just want to display only those records in kibana table whereI need to show only those row records with MAX/MIN count value. Kibana version 7.9.1,How can this be achiev…

---

## [Subqueries in Kibana it that posible?](https://discuss.elastic.co/t/subqueries-in-kibana-it-that-posible/315589)

<div class="topic-metadata">

**Author:** [@Jose\_Javier\_Marti\_Ca](https://discuss.elastic.co/u/Jose_Javier_Marti_Ca)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 9:05am UTC](https://discuss.elastic.co/t/subqueries-in-kibana-it-that-posible/315589 "2022-10-10T09:05:08Z")

</div>

Hi I'm new in Elastic and do not know if it even can be possible. I'd like to perform this "query" i kibana. Select col1 from table1 t1 where NOT exists (select col1 from table1 t2 where t1.col1=t2.col1 and t1.date = …

---

## [How to know influencers list using query](https://discuss.elastic.co/t/how-to-know-influencers-list-using-query/318168)

<div class="topic-metadata">

**Author:** [@minkiyo](https://discuss.elastic.co/u/minkiyo)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 3:57am UTC](https://discuss.elastic.co/t/how-to-know-influencers-list-using-query/318168 "2022-11-07T03:57:27Z")

</div>

When I query to ml result index (.ml-anomalies-\[job-id\]), I can see only influencers score. but I can not get influencers list. How can I get influencers list?? { "\_index" : ".ml-anomalies-shared", "\_t…

---

## [Managing Master Nodes and Data Nodes](https://discuss.elastic.co/t/managing-master-nodes-and-data-nodes/318225)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 5\
**Last updated:** [November 6, 2022, 4:14pm UTC](https://discuss.elastic.co/t/managing-master-nodes-and-data-nodes/318225 "2022-11-06T16:14:09Z")

</div>

Dear all, I am new to ELK Security and I am trying to implement ELK with master nodes and data nodes to handle massive amounts of data but I can not find the good documentation about my use case how to deploy and config…

---

## [Pretty option for kibana rest api?](https://discuss.elastic.co/t/pretty-option-for-kibana-rest-api/318213)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [November 5, 2022, 1:58am UTC](https://discuss.elastic.co/t/pretty-option-for-kibana-rest-api/318213 "2022-11-05T01:58:58Z")

</div>

I tried running this command: curl -X GET -u myuser:mypass "https://localhost:5601/api/alerting/rules/\_find?pretty=true" But I get the error {"statusCode":400,"error":"Bad Request","message":"\[request query.pretty\]: d…

---

## [No runtime directory making kibana failed to start](https://discuss.elastic.co/t/no-runtime-directory-making-kibana-failed-to-start/318199)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [November 4, 2022, 2:29pm UTC](https://discuss.elastic.co/t/no-runtime-directory-making-kibana-failed-to-start/318199 "2022-11-04T14:29:40Z")

</div>

Hi, I installed kibana 8.4.1-1 on a RHEL server using Elastic RPM's. After the first reboot, kibana failed to start because of missing /run/kibana directory: FATAL Error: ENOENT: no such file or directory, open '/run…

---

## [Invalid data view without timeFieldName](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046)

<div class="topic-metadata">

**Author:** [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Replies:** 10\
**Last updated:** [November 4, 2022, 10:48am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046 "2022-11-04T10:48:58Z")

</div>

Hi, I am trying to configure alerts from Kibana console. I using the option from Stack Management -\> Rules and Connector. I want to create the alert for documents in es index. For example: If I index the document where "…

---

## [Link Between indices (Geojson + data)](https://discuss.elastic.co/t/link-between-indices-geojson-data/317959)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 2\
**Last updated:** [November 4, 2022, 8:54am UTC](https://discuss.elastic.co/t/link-between-indices-geojson-data/317959 "2022-11-04T08:54:31Z")

</div>

Hello all, I am using ELK in version 7.17.2 and I need some help. I have 1 Geojson document with the location of my switches (around 80 switches). And I have some indices (logstash-DD-MM-YYYY) about these switches. I…

---

## [Kibana is not able to connect to Elastic Search](https://discuss.elastic.co/t/kibana-is-not-able-to-connect-to-elastic-search/317994)

<div class="topic-metadata">

**Author:** [@dubeyamit620](https://discuss.elastic.co/u/dubeyamit620)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 10:04pm UTC](https://discuss.elastic.co/t/kibana-is-not-able-to-connect-to-elastic-search/317994 "2022-11-03T22:04:58Z")

</div>

We are facing issues connecting Kibana to Elastic Search and getting the following error in the Logs : \["error","elasticsearch","admin"\],"pid":67908,"message":"Request error, retrying\\nGET http://127.0.0.1:9200/.kibana\_…

---

## [No matching indices found: No indices match "apim\_event\_faulty"](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-apim-event-faulty/317814)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 2\
**Last updated:** [November 3, 2022, 8:01pm UTC](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-apim-event-faulty/317814 "2022-11-03T20:01:02Z")

</div>

Hi all, I want to use ELK to monitor the WSO2 API Manager and I have done configurations here https://apim.docs.wso2.com/en/latest/api-analytics/on-prem/elk-installation-guide/ but I got an error when connecting to kib…

---

## [Painless script "Cannot cast from \[boolean\] to \[java.lang.String\]" issue](https://discuss.elastic.co/t/painless-script-cannot-cast-from-boolean-to-java-lang-string-issue/318034)

<div class="topic-metadata">

**Author:** [@alex\_sws](https://discuss.elastic.co/u/alex_sws)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 6:03pm UTC](https://discuss.elastic.co/t/painless-script-cannot-cast-from-boolean-to-java-lang-string-issue/318034 "2022-11-03T18:03:55Z")

</div>

Having trouble spotting the error in my script. "reason": "class\_cast\_exception: Cannot cast from \[boolean\] to \[java.lang.String\]." The Scripted field: Instant Currentdate = Instant.ofEpochMilli(new Date().getTime());…

---

## [Filtering in lists in Bar chart](https://discuss.elastic.co/t/filtering-in-lists-in-bar-chart/317673)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 5:30pm UTC](https://discuss.elastic.co/t/filtering-in-lists-in-bar-chart/317673 "2022-11-03T17:30:04Z")

</div>

Hi all, I'm trying to filter values in lists in Bar charts. But I end up displaying all values of list in Bar Charts Example: Here I'm trying to filter with language - English Below field with list: contentepisodes…

---

## [Kibana DAU/MAU ratio](https://discuss.elastic.co/t/kibana-dau-mau-ratio/317371)

<div class="topic-metadata">

**Author:** [@Bamboo\_Leylo](https://discuss.elastic.co/u/Bamboo_Leylo)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 4:22pm UTC](https://discuss.elastic.co/t/kibana-dau-mau-ratio/317371 "2022-11-03T16:22:28Z")

</div>

Greetings! Faced with the problem of creating a fairly banal visualisation. I'd like to get information on the so-called stikness ratio, or dau/mau ratio (daily active users/monthly active users). Technically, it can p…

---

## [Kibana Time Series Visualization: group fields by values of another field](https://discuss.elastic.co/t/kibana-time-series-visualization-group-fields-by-values-of-another-field/318048)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 4:06pm UTC](https://discuss.elastic.co/t/kibana-time-series-visualization-group-fields-by-values-of-another-field/318048 "2022-11-03T16:06:39Z")

</div>

Hi, Context: we have performance testing data coming from JMeter and from multiple test machines/hosts as well. So we've added a jmeter\_host\_id field to all of our samples to be able to distinguish inbetween these. Go…

---

## [Kibana data visualization](https://discuss.elastic.co/t/kibana-data-visualization/318109)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 3:28pm UTC](https://discuss.elastic.co/t/kibana-data-visualization/318109 "2022-11-03T15:28:16Z")

</div>

Hi, I have built a dashboard. can I enforce a method, where the data is shown only after at least one filter is selected and by default the entire dashboard should be empty?

---

## [Could not configure kibana verification code in Kibana version 8.3.3](https://discuss.elastic.co/t/could-not-configure-kibana-verification-code-in-kibana-version-8-3-3/314045)

<div class="topic-metadata">

**Author:** [@rt\_888](https://discuss.elastic.co/u/rt_888)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 3:10pm UTC](https://discuss.elastic.co/t/could-not-configure-kibana-verification-code-in-kibana-version-8-3-3/314045 "2022-11-03T15:10:14Z")

</div>

I started the Kibana where it required enrollment token. Once i filled in the enrollment token from running the elastic bin with this path " /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token ", then it a…

---

## [Two Filter at The Same Time (Kibana)](https://discuss.elastic.co/t/two-filter-at-the-same-time-kibana/318063)

<div class="topic-metadata">

**Author:** [@Xenial](https://discuss.elastic.co/u/Xenial)\
**Replies:** 2\
**Last updated:** [November 3, 2022, 9:54am UTC](https://discuss.elastic.co/t/two-filter-at-the-same-time-kibana/318063 "2022-11-03T09:54:20Z")

</div>

Hello, I want to use two filter at the same time. how to scoring total alert with filter, source.ip and destination.ip at the same time? Thankyou

---

## [How to import customized dashboard gist to Kibana?](https://discuss.elastic.co/t/how-to-import-customized-dashboard-gist-to-kibana/37088)

<div class="topic-metadata">

**Author:** [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Replies:** 4\
**Last updated:** [June 13, 2017, 12:35pm UTC](https://discuss.elastic.co/t/how-to-import-customized-dashboard-gist-to-kibana/37088 "2017-06-13T12:35:11Z")

</div>

Hi, I am running Kibana Version 4.1.1 Build 7489. I want to import the following gist to Kibana, how can I do it? https://gist.githubusercontent.com/elijahpaul/4b9cd98715c0ba2a75de/raw/9324f7c637e486fb53c8e66e1552595…

---

## [How to get sum of some last values correctly in KIBANA](https://discuss.elastic.co/t/how-to-get-sum-of-some-last-values-correctly-in-kibana/317878)

<div class="topic-metadata">

**Author:** [@Joko\_Eliyanto](https://discuss.elastic.co/u/Joko_Eliyanto)\
**Replies:** 4\
**Last updated:** [November 3, 2022, 4:37am UTC](https://discuss.elastic.co/t/how-to-get-sum-of-some-last-values-correctly-in-kibana/317878 "2022-11-03T04:37:25Z")

</div>

I am a new user in KIBANA dashboard, I just want to create a card that contain sum of certain days last value(for example 1day, 2day, 3day or so on). I think I can get the result I need by change the last value interval …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=171)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=173)
