# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=178

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 179

---

## [Facing issue in kibana after upgrading 8.4](https://discuss.elastic.co/t/facing-issue-in-kibana-after-upgrading-8-4/315082)

<div class="topic-metadata">

**Author:** [@gone](https://discuss.elastic.co/u/gone)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 6:51pm UTC](https://discuss.elastic.co/t/facing-issue-in-kibana-after-upgrading-8-4/315082 "2022-09-26T18:51:17Z")

</div>

Hi All, we are facing one issue with kibana after upgarding SO to 2.3.160 version. whenever i am clicking on any of the kibana dashboard field its throwing me thi s error.

---

## [Authentication failed for null](https://discuss.elastic.co/t/authentication-failed-for-null/314389)

<div class="topic-metadata">

**Author:** [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 6:48pm UTC](https://discuss.elastic.co/t/authentication-failed-for-null/314389 "2022-09-26T18:48:53Z")

</div>

Hello everyone! I'm setting up a new elastic cluster and I have an issue with with alerts in Kibana. I have the following error for each alert in jarvis-cluster.log \[2022-09-14T10:43:56,623\]\[WARN \]\[c.f.s.a.b.RequestAu…

---

## [Error restoring state from URL Unable to completely restore the URL, be sure to use the share functionality](https://discuss.elastic.co/t/error-restoring-state-from-url-unable-to-completely-restore-the-url-be-sure-to-use-the-share-functionality/314925)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 5:46pm UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-unable-to-completely-restore-the-url-be-sure-to-use-the-share-functionality/314925 "2022-09-26T17:46:13Z")

</div>

When I open Kibana, it show error like this. I search on discussion and nobody answer. How to fix it?

---

## [Kibana Canvas error: Invalid string. Length must be a multiple of 4](https://discuss.elastic.co/t/kibana-canvas-error-invalid-string-length-must-be-a-multiple-of-4/314286)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 5:42pm UTC](https://discuss.elastic.co/t/kibana-canvas-error-invalid-string-length-must-be-a-multiple-of-4/314286 "2022-09-26T17:42:40Z")

</div>

I am using version 7.16.2 of Kibana. I am adding a dropdown filter in Canvas. Let's say the index pattern is \*-\*\_stage. This index pattern includes 100 data streams. When trying to add this index pattern in the Canva…

---

## [Data table with time shift](https://discuss.elastic.co/t/data-table-with-time-shift/315172)

<div class="topic-metadata">

**Author:** [@Samuele\_Mosci](https://discuss.elastic.co/u/Samuele_Mosci)\
**Replies:** 3\
**Last updated:** [September 26, 2022, 1:53pm UTC](https://discuss.elastic.co/t/data-table-with-time-shift/315172 "2022-09-26T13:53:52Z")

</div>

Hi, I'm using Kibana 8.4. I am trying to make a visualization (in particular a data table) where I can view documents that I do not have in a timestamp but which are present in the timestamp of the previous day. I tried …

---

## [\[Kibana 7.17.1\] Index patterns disappear after restoring VM snaphots of ES cluster machines](https://discuss.elastic.co/t/kibana-7-17-1-index-patterns-disappear-after-restoring-vm-snaphots-of-es-cluster-machines/313457)

<div class="topic-metadata">

**Author:** [@gerib](https://discuss.elastic.co/u/gerib)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 1:52pm UTC](https://discuss.elastic.co/t/kibana-7-17-1-index-patterns-disappear-after-restoring-vm-snaphots-of-es-cluster-machines/313457 "2022-09-26T13:52:19Z")

</div>

We're running an ES test cluster of 3 machines with the following nodes: master, coordinating only, data master, coordinating only, data master, ingest, data We have three index types in this cluster: shop-\<YYYY.MM.…

---

## [Terms Query by index in dashboards](https://discuss.elastic.co/t/terms-query-by-index-in-dashboards/313717)

<div class="topic-metadata">

**Author:** [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Replies:** 4\
**Last updated:** [September 26, 2022, 1:52pm UTC](https://discuss.elastic.co/t/terms-query-by-index-in-dashboards/313717 "2022-09-26T13:52:00Z")

</div>

I am currently using Terms Query by index to filter a query: { "query": { "bool": { "must": \[ { "terms": { "test.type.name": { …

---

## [Ordering results based on derivate aggregation](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954)

<div class="topic-metadata">

**Author:** [@Toni\_Heinonen](https://discuss.elastic.co/u/Toni_Heinonen)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 1:32pm UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954 "2022-09-26T13:32:39Z")

</div>

I'm working with a audit trail data and trying to make a graph (or even a table) that would list users that have a greatest drop on usage since last month. So far I have tried the following. TSVB: I can get a percenta…

---

## [Creating a line chart in kibana without aggregation](https://discuss.elastic.co/t/creating-a-line-chart-in-kibana-without-aggregation/314383)

<div class="topic-metadata">

**Author:** [@Manasa\_reddy09](https://discuss.elastic.co/u/Manasa_reddy09)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 12:48pm UTC](https://discuss.elastic.co/t/creating-a-line-chart-in-kibana-without-aggregation/314383 "2022-09-26T12:48:09Z")

</div>

Hello Folks, I am new to Kibana, although i have worked with other visualization tools before. Kibana is new to me. I know that Kibana is based on Buckets and we need an aggregation to create charts in Kibana.. But when…

---

## [Basic license expires today?](https://discuss.elastic.co/t/basic-license-expires-today/315148)

<div class="topic-metadata">

**Author:** [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Replies:** 3\
**Last updated:** [September 26, 2022, 10:04am UTC](https://discuss.elastic.co/t/basic-license-expires-today/315148 "2022-09-26T10:04:20Z")

</div>

Hi, I am running the latest 8.4.2 stack. stack monitoring (/app/monitoring#/home) reports that my basic license expires today. If I go to /app/monitoring#/license?\_g=(cluster\_uuid:xxxxxx) it says: Your Basic license …

---

## [Dashboards based on a subquery](https://discuss.elastic.co/t/dashboards-based-on-a-subquery/315153)

<div class="topic-metadata">

**Author:** [@shinobu](https://discuss.elastic.co/u/shinobu)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 9:40am UTC](https://discuss.elastic.co/t/dashboards-based-on-a-subquery/315153 "2022-09-26T09:40:06Z")

</div>

Hello, I would like to aggregate data into a pie chart based on the newest data for a specific type id. In other words something like category | type\_id | @timestamp category1 | abcd | 2022-08-26 category1 | abcd |…

---

## [Kibana is now available (was degraded), No ML saved objects in need of synchronization](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded-no-ml-saved-objects-in-need-of-synchronization/315121)

<div class="topic-metadata">

**Author:** [@Tushar\_Singh1](https://discuss.elastic.co/u/Tushar_Singh1)\
**Replies:** 5\
**Last updated:** [September 26, 2022, 9:26am UTC](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded-no-ml-saved-objects-in-need-of-synchronization/315121 "2022-09-26T09:26:53Z")

</div>

I am not able to open kibana GUI , It is continuously throwing error as \[2022-09-25T22:39:48.677+00:00\]\[INFO \]\[plugins.monitoring.monitoring\] config sourced from: production cluster \[2022-09-25T22:39:50.434+00:00\]\[INF…

---

## [Multiple Kibana on multiple cluster with same data](https://discuss.elastic.co/t/multiple-kibana-on-multiple-cluster-with-same-data/313550)

<div class="topic-metadata">

**Author:** [@baneinc](https://discuss.elastic.co/u/baneinc)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 9:10am UTC](https://discuss.elastic.co/t/multiple-kibana-on-multiple-cluster-with-same-data/313550 "2022-09-26T09:10:19Z")

</div>

Hi forum, I have multiple (two) elasticsearch clusters, with kafka in front, so both clusters have identical data. How to setup HA kibana (two kibana, one on eachcluster) with loadbalancer in front, so all kibana setti…

---

## [Logstash Pipeline details result in HTTP response code 404](https://discuss.elastic.co/t/logstash-pipeline-details-result-in-http-response-code-404/315151)

<div class="topic-metadata">

**Author:** [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 9:09am UTC](https://discuss.elastic.co/t/logstash-pipeline-details-result-in-http-response-code-404/315151 "2022-09-26T09:09:29Z")

</div>

Hi, I am running the latest 8.4.2 Elastic stack. If I go to stack monitoring (/app/monitoring#/logstash/pipelines?\_g=(cluster\_uuid:xxxxxx), I get an overview of my pipelines. If I click on the only pipeline that is li…

---

## [Field \[gcp.audit.response.status.conditions.lastHeartbeatTime\] of type \[flattened\] doesn't support formats](https://discuss.elastic.co/t/field-gcp-audit-response-status-conditions-lastheartbeattime-of-type-flattened-doesnt-support-formats/315028)

<div class="topic-metadata">

**Author:** [@AndreiRD](https://discuss.elastic.co/u/AndreiRD)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 9:08am UTC](https://discuss.elastic.co/t/field-gcp-audit-response-status-conditions-lastheartbeattime-of-type-flattened-doesnt-support-formats/315028 "2022-09-26T09:08:46Z")

</div>

So, I have enabled GCP Audit logs collection using the GCP integration from Elastic Agent 8.3.3. I've had no problems so far running searches in this dataset, but as of today the next error keeps appearing, and now I ca…

---

## [Confusing with bucket score and record score in advanced multi metric](https://discuss.elastic.co/t/confusing-with-bucket-score-and-record-score-in-advanced-multi-metric/315134)

<div class="topic-metadata">

**Author:** [@minkiyo](https://discuss.elastic.co/u/minkiyo)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 7:01am UTC](https://discuss.elastic.co/t/confusing-with-bucket-score-and-record-score-in-advanced-multi-metric/315134 "2022-09-26T07:01:10Z")

</div>

I am confusing about anomaly score now. I make advanced multi metric ml job using below two single metric. Would you explain why bucket score is 84 as record score is only 2 ?? \< advanced multi metric \> And also I…

---

## [How to acheive multiple filter in elastic search using API](https://discuss.elastic.co/t/how-to-acheive-multiple-filter-in-elastic-search-using-api/315131)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 6:45am UTC](https://discuss.elastic.co/t/how-to-acheive-multiple-filter-in-elastic-search-using-api/315131 "2022-09-26T06:45:29Z")

</div>

How could I be able to add multiple filters on my index like in an image I have filtered that result by first\_name and then by category using elasticsearch client @app.route('/get-data') @login\_required def get\_permiss…

---

## [Want to set ssl.verification\_mode as none for default fleet output in kibana.yml](https://discuss.elastic.co/t/want-to-set-ssl-verification-mode-as-none-for-default-fleet-output-in-kibana-yml/315098)

<div class="topic-metadata">

**Author:** [@Naveen\_Kumar\_Reddy\_S](https://discuss.elastic.co/u/Naveen_Kumar_Reddy_S)\
**Replies:** 0\
**Last updated:** [September 25, 2022, 11:30am UTC](https://discuss.elastic.co/t/want-to-set-ssl-verification-mode-as-none-for-default-fleet-output-in-kibana-yml/315098 "2022-09-25T11:30:51Z")

</div>

HI I am trying to send data from fleet managed Elastic agent to elastic master node with self-signed certificate. The auto generated self signed certificate doesnot have the publicip of the node. So to send data i want …

---

## [Wordcloud code changes](https://discuss.elastic.co/t/wordcloud-code-changes/315083)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 0\
**Last updated:** [September 24, 2022, 4:29pm UTC](https://discuss.elastic.co/t/wordcloud-code-changes/315083 "2022-09-24T16:29:06Z")

</div>

Is there any way we can change the colors in the WORD CLOUD for a specific purpose? For ex. I am having some values like negative and positive. For negative, I want red color and for positive I want green color. So do we…

---

## [Consult, send the alerts by rules created through mail](https://discuss.elastic.co/t/consult-send-the-alerts-by-rules-created-through-mail/315067)

<div class="topic-metadata">

**Author:** [@Hector\_miran](https://discuss.elastic.co/u/Hector_miran)\
**Replies:** 2\
**Last updated:** [September 24, 2022, 3:09am UTC](https://discuss.elastic.co/t/consult-send-the-alerts-by-rules-created-through-mail/315067 "2022-09-24T03:09:00Z")

</div>

Good morning everyone, currently I have managed to create alert rules and I have validated that alerts are being generated. I would like to be able to send these alerts to my email to be able to better monitor them. Is …

---

## [Okta SSO not working](https://discuss.elastic.co/t/okta-sso-not-working/315053)

<div class="topic-metadata">

**Author:** [@sean.doody](https://discuss.elastic.co/u/sean.doody)\
**Replies:** 3\
**Last updated:** [September 23, 2022, 10:32pm UTC](https://discuss.elastic.co/t/okta-sso-not-working/315053 "2022-09-23T22:32:00Z")

</div>

I am having trouble getting SAML integrated with Elastic. I used a 14-day Trail and got it to work there, but now that I tried to integrate it into our production environment I am getting errors. Below is the yaml for o…

---

## [Visualize inequality with a Lorenz Curve](https://discuss.elastic.co/t/visualize-inequality-with-a-lorenz-curve/315048)

<div class="topic-metadata">

**Author:** [@Andreas\_Schennings](https://discuss.elastic.co/u/Andreas_Schennings)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 6:41pm UTC](https://discuss.elastic.co/t/visualize-inequality-with-a-lorenz-curve/315048 "2022-09-23T18:41:21Z")

</div>

Hi! I am quite new to Kibana. But I must say I really like its diversity and possibilites. Lets say I would like to visualize inequalities e.g. income over population. I have heard that this could be achieved by using …

---

## [How to clone multiple indices at once within Kibana DevTools](https://discuss.elastic.co/t/how-to-clone-multiple-indices-at-once-within-kibana-devtools/314939)

<div class="topic-metadata">

**Author:** [@fim01](https://discuss.elastic.co/u/fim01)\
**Replies:** 4\
**Last updated:** [September 23, 2022, 12:29pm UTC](https://discuss.elastic.co/t/how-to-clone-multiple-indices-at-once-within-kibana-devtools/314939 "2022-09-23T12:29:22Z")

</div>

Hello Is it possible to clone multiple indices in one shot? I tried: POST /test-13,test-14,test-15/\_clone/test-clone Unfortunately I'll get an error: { "error" : { "root\_cause" : \[ { "type" : "…

---

## [Kibana - Canvas - Conditional coloring in a Table (If Statut = KO -\> Cell Red)](https://discuss.elastic.co/t/kibana-canvas-conditional-coloring-in-a-table-if-statut-ko-cell-red/315008)

<div class="topic-metadata">

**Author:** [@riwalco](https://discuss.elastic.co/u/riwalco)\
**Replies:** 1\
**Last updated:** [September 23, 2022, 11:00am UTC](https://discuss.elastic.co/t/kibana-canvas-conditional-coloring-in-a-table-if-statut-ko-cell-red/315008 "2022-09-23T11:00:42Z")

</div>

Hello, I would like to highlight in RED the cells that have the value KO for column Statut : Juste below the code that I have : filters | essql query="SELECT Check\_Date, ID, Statut, Minimum, Valeur, Commentair…

---

## [Scheduling the generation of a visualisation and saving/caching the result or automated CSV export](https://discuss.elastic.co/t/scheduling-the-generation-of-a-visualisation-and-saving-caching-the-result-or-automated-csv-export/315002)

<div class="topic-metadata">

**Author:** [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Replies:** 1\
**Last updated:** [September 23, 2022, 10:46am UTC](https://discuss.elastic.co/t/scheduling-the-generation-of-a-visualisation-and-saving-caching-the-result-or-automated-csv-export/315002 "2022-09-23T10:46:06Z")

</div>

Hello, We are currently using Elastic table visualisations to obtain a record of network connections from a certain group of machines, an example: We are manually generating these on a machine-by-machine basis and e…

---

## [No monitoring data found](https://discuss.elastic.co/t/no-monitoring-data-found/314412)

<div class="topic-metadata">

**Author:** [@P-T-I](https://discuss.elastic.co/u/P-T-I)\
**Replies:** 17\
**Last updated:** [September 23, 2022, 10:13am UTC](https://discuss.elastic.co/t/no-monitoring-data-found/314412 "2022-09-23T10:13:51Z")

</div>

I'm running kibana/elasticsearch/metricbeats 8.4.1 in a docker configuration. Although I'm seeing the monitoring indexes being created ( .ds-metricbeat-8.4.1-2022.09.14-000001, .ds-.monitoring-kibana-8-mb-2022.09.14-0…

---

## [How to curl elastic or kibana api for alerts?](https://discuss.elastic.co/t/how-to-curl-elastic-or-kibana-api-for-alerts/314455)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [September 22, 2022, 3:11pm UTC](https://discuss.elastic.co/t/how-to-curl-elastic-or-kibana-api-for-alerts/314455 "2022-09-22T15:11:35Z")

</div>

I am learning to use the ELK stack. Both kibana and elasticsearch are installed on my localhost. I just learnt how to install metricbeat and how to set up alerts. When setting up the alerts, I used the index connector…

---

## [Error fetching fields for data in Security Dashboard](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573)

<div class="topic-metadata">

**Author:** [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Replies:** 13\
**Last updated:** [September 22, 2022, 1:12pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-in-security-dashboard/313573 "2022-09-22T13:12:16Z")

</div>

Hello guys, I am getting the error below when I go to the security dashboard overview: Error fetching fields for data view .alerts-security.alerts-default,apm--transaction,auditbeat-,endgame-,filebeat-,logs-,packetbeat…

---

## [Subtracting two lines in vega chart](https://discuss.elastic.co/t/subtracting-two-lines-in-vega-chart/314847)

<div class="topic-metadata">

**Author:** [@michalruszczyk](https://discuss.elastic.co/u/michalruszczyk)\
**Replies:** 2\
**Last updated:** [September 22, 2022, 10:08am UTC](https://discuss.elastic.co/t/subtracting-two-lines-in-vega-chart/314847 "2022-09-22T10:08:02Z")

</div>

Hi, I am trying to create a chart which shows some kind of risk. The logic behind is that I have an index which has Dalue, startDate and endDate. I would like to show the line which is cumulative sum of value with startd…

---

## [Guidance on running Kibana with a CDN](https://discuss.elastic.co/t/guidance-on-running-kibana-with-a-cdn/314598)

<div class="topic-metadata">

**Author:** [@HockeyFan0000](https://discuss.elastic.co/u/HockeyFan0000)\
**Replies:** 4\
**Last updated:** [September 21, 2022, 3:58pm UTC](https://discuss.elastic.co/t/guidance-on-running-kibana-with-a-cdn/314598 "2022-09-21T15:58:59Z")

</div>

When we upgraded Kibana recently, the scripts for the plugins stopped working. It seems they were attempting to pull from the CDN but they would fail. We finally cleared the cache on the CDN and everything started work…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=177)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=179)
