# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=175

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 176

---

## [Restoring Kibana related indices and users in 7.17?](https://discuss.elastic.co/t/restoring-kibana-related-indices-and-users-in-7-17/316433)

<div class="topic-metadata">

**Author:** [@NetwarSystem](https://discuss.elastic.co/u/NetwarSystem)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 11:57am UTC](https://discuss.elastic.co/t/restoring-kibana-related-indices-and-users-in-7-17/316433 "2022-10-12T11:57:47Z")

</div>

I have a system running Elasticsearch and Kibana 7.17.6. This is a single host with roughly 600 million items in 300 indices. The host OS is Ubuntu 22.04. Earlier today a clumsy rsync command on my part stepped on some …

---

## [Error Starting Kibana 8.4.3 Onpremise](https://discuss.elastic.co/t/error-starting-kibana-8-4-3-onpremise/316454)

<div class="topic-metadata">

**Author:** [@LeoCP](https://discuss.elastic.co/u/LeoCP)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 9:26pm UTC](https://discuss.elastic.co/t/error-starting-kibana-8-4-3-onpremise/316454 "2022-10-12T21:26:50Z")

</div>

respectful greeting, I am evaluating the onpremise version of elasticsearch & Kibana 8.4.3 on windows 10, starting Elasticsearch, it works ok, I can see it http://localhost:9200/...... but when I try to run kibana. I ge…

---

## [Kibana 8.4.2 dashboard date filter not working in firefox](https://discuss.elastic.co/t/kibana-8-4-2-dashboard-date-filter-not-working-in-firefox/316437)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 2:04pm UTC](https://discuss.elastic.co/t/kibana-8-4-2-dashboard-date-filter-not-working-in-firefox/316437 "2022-10-12T14:04:42Z")

</div>

Hello, when i try to add a filter for a date field with the add filter menu in firefox, the date given is not recognized. In chrome it works fine. I type for example 1.1.22, press tab and the date is there: Trying …

---

## [Can I convert a string column type to a timestamp?](https://discuss.elastic.co/t/can-i-convert-a-string-column-type-to-a-timestamp/316385)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 1:38pm UTC](https://discuss.elastic.co/t/can-i-convert-a-string-column-type-to-a-timestamp/316385 "2022-10-12T13:38:06Z")

</div>

I ingested a bunch of documents. They have a property "time" containing strings of the form "2015-01-20 07:52:05.013047". I let Elastic automatically detect the data types and it treated "time" as a string. The schema ha…

---

## [What's the Lucene equivalent of KQL query: now/d](https://discuss.elastic.co/t/whats-the-lucene-equivalent-of-kql-query-now-d/316230)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 3\
**Last updated:** [October 12, 2022, 10:58am UTC](https://discuss.elastic.co/t/whats-the-lucene-equivalent-of-kql-query-now-d/316230 "2022-10-12T10:58:21Z")

</div>

Hi I'm trying to filter my data based on a date field to show me everything for today, in Kibana I can use the KQL query using now/d but I need the equivalent for Lucene, any help? I wouldve thought it'd be the same but…

---

## [Date histogram that doesn't look at the entire date bucket?](https://discuss.elastic.co/t/date-histogram-that-doesnt-look-at-the-entire-date-bucket/316415)

<div class="topic-metadata">

**Author:** [@netzer](https://discuss.elastic.co/u/netzer)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 8:06am UTC](https://discuss.elastic.co/t/date-histogram-that-doesnt-look-at-the-entire-date-bucket/316415 "2022-10-12T08:06:33Z")

</div>

I'm wondering if the following is possible. I have events with metrics sent every 10 minutes, so when I create a dashboard looking at the past 15 minutes I can see the "latest status". I can also do a "SUM" of a field o…

---

## [Osquery View in Discover issue](https://discuss.elastic.co/t/osquery-view-in-discover-issue/315367)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 7:38pm UTC](https://discuss.elastic.co/t/osquery-view-in-discover-issue/315367 "2022-10-11T19:38:56Z")

</div>

We are running Elastic-Stack 8.4.2 (All components, inclusive the agents) and started to use Osquery. It is a great technology, however there are some problems we've encountered: Displaying the Data in Discover with the…

---

## [Continous Alerting without rules](https://discuss.elastic.co/t/continous-alerting-without-rules/316207)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 6:49pm UTC](https://discuss.elastic.co/t/continous-alerting-without-rules/316207 "2022-10-11T18:49:58Z")

</div>

Good evening, everyone. So i just enabled alert rules and connectors to send {{context.reason}} in elasticsearch 8.4. since we know alert only triggers when the requirements are met, is there anyway i could do to send …

---

## [Filter on Aggragted Result](https://discuss.elastic.co/t/filter-on-aggragted-result/316315)

<div class="topic-metadata">

**Author:** [@ahmet\_erkol](https://discuss.elastic.co/u/ahmet_erkol)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 5:24pm UTC](https://discuss.elastic.co/t/filter-on-aggragted-result/316315 "2022-10-11T17:24:23Z")

</div>

Hi, We made a map layer that calculates the average of success. We want to filter the map based on the succes rate. For example we want to show geo fileds only succes rate higher than %70. In the picture we want to fil…

---

## [Why "View single document" is "button" tag in HTML and not a "a" tag with URL?](https://discuss.elastic.co/t/why-view-single-document-is-button-tag-in-html-and-not-a-a-tag-with-url/315583)

<div class="topic-metadata">

**Author:** [@bryancev](https://discuss.elastic.co/u/bryancev)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 5:04pm UTC](https://discuss.elastic.co/t/why-view-single-document-is-button-tag-in-html-and-not-a-a-tag-with-url/315583 "2022-10-11T17:04:14Z")

</div>

Hi all! Why in Kibana version 8.1.2 the "View single document" document view is implemented via the button tag? This is extremely inconvenient, since I would like to open documents in a new tab by clicking the mouse wh…

---

## [Kibana (8.4.2) visualization does not show metadata fields](https://discuss.elastic.co/t/kibana-8-4-2-visualization-does-not-show-metadata-fields/316279)

<div class="topic-metadata">

**Author:** [@amirfarsi](https://discuss.elastic.co/u/amirfarsi)\
**Replies:** 3\
**Last updated:** [October 11, 2022, 12:32pm UTC](https://discuss.elastic.co/t/kibana-8-4-2-visualization-does-not-show-metadata-fields/316279 "2022-10-11T12:32:07Z")

</div>

Hello friends. We updated our ELK from 7.\* to 8.4.2, and we used from our backups to restoring visualization, dashboards, data views (index pattern) and ... We had problems that were fixed, except for the following : …

---

## [Duplicate : Scripted metric not working inside transform](https://discuss.elastic.co/t/duplicate-scripted-metric-not-working-inside-transform/316269)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee](https://discuss.elastic.co/u/Hemabh_Ravee)\
**Replies:** 4\
**Last updated:** [October 11, 2022, 6:40am UTC](https://discuss.elastic.co/t/duplicate-scripted-metric-not-working-inside-transform/316269 "2022-10-11T06:40:23Z")

</div>

First of all, I'd like to clarify that the reason I'm posting this question because I am unable to add any replies or edits to the original one. I'm finding myself unable to post questions as well using that account(err…

---

## [Automatically move old documents from a index, to a new index, without deleting the original index](https://discuss.elastic.co/t/automatically-move-old-documents-from-a-index-to-a-new-index-without-deleting-the-original-index/316161)

<div class="topic-metadata">

**Author:** [@jinlauter94](https://discuss.elastic.co/u/jinlauter94)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 10:24pm UTC](https://discuss.elastic.co/t/automatically-move-old-documents-from-a-index-to-a-new-index-without-deleting-the-original-index/316161 "2022-10-10T22:24:12Z")

</div>

There is a lot of helpful documents showing how to turn a hot index into a warm or cold one. But, in my case, I have a lot of independent applications that do the "same" thing, and can be very different. I would like to …

---

## [Kibana field filter suggester settings](https://discuss.elastic.co/t/kibana-field-filter-suggester-settings/315665)

<div class="topic-metadata">

**Author:** [@gribna](https://discuss.elastic.co/u/gribna)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 10:39am UTC](https://discuss.elastic.co/t/kibana-field-filter-suggester-settings/315665 "2022-10-10T10:39:18Z")

</div>

Which setting affects the appearance of value suggestion list in filters and in queries? We have several environments and it doesn't work for one of them. The difference between environments is that the one that doesn't…

---

## [Kibana cannot startup - always tried to migrate](https://discuss.elastic.co/t/kibana-cannot-startup-always-tried-to-migrate/316200)

<div class="topic-metadata">

**Author:** [@misterking7](https://discuss.elastic.co/u/misterking7)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 9:47am UTC](https://discuss.elastic.co/t/kibana-cannot-startup-always-tried-to-migrate/316200 "2022-10-10T09:47:42Z")

</div>

Hello team, I have issue with Kibana that cannot start up . before it was deployed into Openshift3 , Kibana version showed as 7.9.3 - Elasticsearch is 7.9.2 now, I tried to shutdown old cluster instance on Openshift3 …

---

## [Linking Dashboard and Discover tab to view documents based on filter](https://discuss.elastic.co/t/linking-dashboard-and-discover-tab-to-view-documents-based-on-filter/315687)

<div class="topic-metadata">

**Author:** [@ashit\_pupu](https://discuss.elastic.co/u/ashit_pupu)\
**Replies:** 3\
**Last updated:** [October 10, 2022, 7:13am UTC](https://discuss.elastic.co/t/linking-dashboard-and-discover-tab-to-view-documents-based-on-filter/315687 "2022-10-10T07:13:05Z")

</div>

Hi Team, I am looking for any feature availability in Kibana which would enable me to link my dashboard to the discover tab to view the documents. So the idea is I have a dashboard created based on field aggregation I …

---

## [Case Insensitive search in kibana dahboard](https://discuss.elastic.co/t/case-insensitive-search-in-kibana-dahboard/315653)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:11am UTC](https://discuss.elastic.co/t/case-insensitive-search-in-kibana-dahboard/315653 "2022-10-10T07:11:12Z")

</div>

Hi, I created dashboard with some visualization and add filters on it. But these are case sensitive. Is it possible to search with lower or upper case. For exam Adam name searchable from Adam or adam or aDaM. Thanks

---

## [Same index pattern in multiple namespaces](https://discuss.elastic.co/t/same-index-pattern-in-multiple-namespaces/316085)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:07am UTC](https://discuss.elastic.co/t/same-index-pattern-in-multiple-namespaces/316085 "2022-10-10T07:07:26Z")

</div>

Hi I am using Kibana/Elasticsearch version 7.16.3. I have trouble creating the same index pattern within multiple namespaces. I am using bulk create API to create multiple index patterns and for one of the patterns …

---

## [Group by query with select case when gives error: Connot use non-grouped column (Canvas elasticsearch sql)](https://discuss.elastic.co/t/group-by-query-with-select-case-when-gives-error-connot-use-non-grouped-column-canvas-elasticsearch-sql/315880)

<div class="topic-metadata">

**Author:** [@Houssam](https://discuss.elastic.co/u/Houssam)\
**Replies:** 4\
**Last updated:** [October 10, 2022, 7:04am UTC](https://discuss.elastic.co/t/group-by-query-with-select-case-when-gives-error-connot-use-non-grouped-column-canvas-elasticsearch-sql/315880 "2022-10-10T07:04:39Z")

</div>

Hello everyone I face a problem with a certain group by elasticsearch sql query when i try to use a field in select case condition but not group by it because it doubles my rows and leaves null values, i get the followin…

---

## [Scripted Field Help](https://discuss.elastic.co/t/scripted-field-help/316156)

<div class="topic-metadata">

**Author:** [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Replies:** 11\
**Last updated:** [October 9, 2022, 6:44pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156 "2022-10-09T18:44:40Z")

</div>

Hello, I am trying to use a scripted field to compare the value of one field against another. A sample document extract is below: Field1 C2\_Host: \["check.example.workers.dev"\] Field2 HostHeader: "Host: check.example.w…

---

## [Merging two indexes by a column](https://discuss.elastic.co/t/merging-two-indexes-by-a-column/315163)

<div class="topic-metadata">

**Author:** [@Juanfer](https://discuss.elastic.co/u/Juanfer)\
**Replies:** 2\
**Last updated:** [October 9, 2022, 10:38am UTC](https://discuss.elastic.co/t/merging-two-indexes-by-a-column/315163 "2022-10-09T10:38:41Z")

</div>

Hello there, I am a beginner in Elasticsearch and I have been reading about how to merge 2 indexes based on two different names columns with the same values. I understand the NoSQL performance of elastic but still havin…

---

## [Handling changes between Kibana instances](https://discuss.elastic.co/t/handling-changes-between-kibana-instances/315640)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 8, 2022, 11:25am UTC](https://discuss.elastic.co/t/handling-changes-between-kibana-instances/315640 "2022-10-08T11:25:14Z")

</div>

I have a dozen or so Kibans with the same basic configuration, but they differ slightly from one another (e.g. the selected queries are slightly altered). Is there a good option for handling this? What I have in mind, fo…

---

## [Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/316000)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 8\
**Last updated:** [October 7, 2022, 8:41pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/316000 "2022-10-07T20:41:43Z")

</div>

I'm trying to use ssl certificates created by Let's Encrypt for elasticsearch and kibana version 8.4. Kibana fails at start up with this error message: Unable to retrieve version information from Elasticsearch nodes. u…

---

## [Unable to download Kibana Discover logs into csv/excel in Kibana 8.2.2](https://discuss.elastic.co/t/unable-to-download-kibana-discover-logs-into-csv-excel-in-kibana-8-2-2/315966)

<div class="topic-metadata">

**Author:** [@lakshmiD](https://discuss.elastic.co/u/lakshmiD)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 7:44pm UTC](https://discuss.elastic.co/t/unable-to-download-kibana-discover-logs-into-csv-excel-in-kibana-8-2-2/315966 "2022-10-07T19:44:18Z")

</div>

Hi Team, How to download kibana discover tab logs into csv/excel when I tired to generate from share--\>csv reports--\>Generate CSV ,getting request timed out error Is there any extensions available in chrome to downloa…

---

## [How to create table by month grouped by year](https://discuss.elastic.co/t/how-to-create-table-by-month-grouped-by-year/316044)

<div class="topic-metadata">

**Author:** [@LucasTavernier](https://discuss.elastic.co/u/LucasTavernier)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 7:39pm UTC](https://discuss.elastic.co/t/how-to-create-table-by-month-grouped-by-year/316044 "2022-10-07T19:39:44Z")

</div>

Hello everyone, i'm new in the ELK stack. I have to to make a table but it's really hard can you please help me. To help you understand what i have to do, i will explain my datas. I got bugs tickets with the id/name o…

---

## [Hide value of legend in Timelion](https://discuss.elastic.co/t/hide-value-of-legend-in-timelion/315470)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 2\
**Last updated:** [October 7, 2022, 6:41pm UTC](https://discuss.elastic.co/t/hide-value-of-legend-in-timelion/315470 "2022-10-07T18:41:08Z")

</div>

Hello! could anyone tell me how can i hide the value of the legend without hide the whole legend? Thanks in advanced!

---

## [Alert Message Data Kibana 8.3](https://discuss.elastic.co/t/alert-message-data-kibana-8-3/315876)

<div class="topic-metadata">

**Author:** [@quixter](https://discuss.elastic.co/u/quixter)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 12:34pm UTC](https://discuss.elastic.co/t/alert-message-data-kibana-8-3/315876 "2022-10-05T12:34:47Z")

</div>

I'm creating alerts using the new Alert GUI. Wondering how I would add available fields from the log entries. For an example we have a field called rcm.serverdesc that provided the friendly name of the server the error w…

---

## [Rollup job date histogram bucket starts at 00.00 for day interval instead of current time](https://discuss.elastic.co/t/rollup-job-date-histogram-bucket-starts-at-00-00-for-day-interval-instead-of-current-time/316063)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 11:05am UTC](https://discuss.elastic.co/t/rollup-job-date-histogram-bucket-starts-at-00-00-for-day-interval-instead-of-current-time/316063 "2022-10-07T11:05:45Z")

</div>

Hello, i tried using rollup job and set date histogram bucket to interval of 24h. After starting the job, creating data view, and viewing it in kibana, the interval starts at 24h from 7 october at 00.00 until yesterday a…

---

## [Get POST URL for PDF reports with API](https://discuss.elastic.co/t/get-post-url-for-pdf-reports-with-api/315814)

<div class="topic-metadata">

**Author:** [@Saliinger](https://discuss.elastic.co/u/Saliinger)\
**Replies:** 2\
**Last updated:** [October 7, 2022, 4:48am UTC](https://discuss.elastic.co/t/get-post-url-for-pdf-reports-with-api/315814 "2022-10-07T04:48:22Z")

</div>

Hello! Hope you are doing good :smiley: I have a question: It is possible get the URL POST for PDF reports using API? Getting the Copy POST URL with cURL or Postman and not doing it manually as always. Is there an…

---

## [Service token causes index\_not\_found\_exception](https://discuss.elastic.co/t/service-token-causes-index-not-found-exception/315900)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 5\
**Last updated:** [October 6, 2022, 11:42pm UTC](https://discuss.elastic.co/t/service-token-causes-index-not-found-exception/315900 "2022-10-06T23:42:44Z")

</div>

I want to learn to use service tokens. I followed the instructions here: Specifically, I ran this command from bash CLI of the server 139.177.199.119 bin/elasticsearch-service-tokens create elastic/kibana my-token W…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=174)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=176)
