# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=182

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 183

---

## [Expose part of a ELK document to another index/user](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028)

<div class="topic-metadata">

**Author:** [@Sylvain35](https://discuss.elastic.co/u/Sylvain35)\
**Replies:** 6\
**Last updated:** [September 8, 2022, 12:05pm UTC](https://discuss.elastic.co/t/expose-part-of-a-elk-document-to-another-index-user/313028 "2022-09-08T12:05:22Z")

</div>

Hello everyone ! I have a streaming process that feeds an ELK index (one new index each day) The object send is a JSON with multiple level and fields. I have a complex mapping on this Index. I want to expose a limited…

---

## [Kibana, canvas, Image reveal problem after upgrade to 8.4.1 from 8.3.1](https://discuss.elastic.co/t/kibana-canvas-image-reveal-problem-after-upgrade-to-8-4-1-from-8-3-1/313986)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 11:15am UTC](https://discuss.elastic.co/t/kibana-canvas-image-reveal-problem-after-upgrade-to-8-4-1-from-8-3-1/313986 "2022-09-08T11:15:30Z")

</div>

Hi I've just upgraded elastic clsuter from 8.3.1 to 8.4.1 and also kibana. After upgrade kibana all the Image reveal images turned exclamation mark, and when I've click on an image I'am getting error "Expression failed …

---

## [Vega tree error key is null](https://discuss.elastic.co/t/vega-tree-error-key-is-null/313946)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 6:15am UTC](https://discuss.elastic.co/t/vega-tree-error-key-is-null/313946 "2022-09-08T06:15:42Z")

</div>

Hello, I am trying to create a vega tree visualization. I am not sure how to complete the starting node. I've tried to put null, -, but nothing works. If the parent of the last node is null I am getting error \_.\_source…

---

## [Kibana Ingest pipeline Convert String to Date?](https://discuss.elastic.co/t/kibana-ingest-pipeline-convert-string-to-date/313836)

<div class="topic-metadata">

**Author:** [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Replies:** 5\
**Last updated:** [September 8, 2022, 2:19am UTC](https://discuss.elastic.co/t/kibana-ingest-pipeline-convert-string-to-date/313836 "2022-09-08T02:19:44Z")

</div>

Installed elastic-agent on the server and Collect Custom Log Data I was Create a pipeline in Kibana (Stack Management -\> Ingest pipelines) And "Message" Field -\> Split Data (Success) How can I Convert String F…

---

## [Custom Domain Names](https://discuss.elastic.co/t/custom-domain-names/313918)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 6:51pm UTC](https://discuss.elastic.co/t/custom-domain-names/313918 "2022-09-07T18:51:48Z")

</div>

Are custom domain names supported yet? There are a series of posts asking for them like Custom Domain Name but each one just says it's "coming soon" I do not want to setup a proxy (e.g. nginx) for this purpose, as the …

---

## [Trace sample logs error KQL](https://discuss.elastic.co/t/trace-sample-logs-error-kql/313703)

<div class="topic-metadata">

**Author:** [@davjl](https://discuss.elastic.co/u/davjl)\
**Replies:** 1\
**Last updated:** [September 6, 2022, 11:38pm UTC](https://discuss.elastic.co/t/trace-sample-logs-error-kql/313703 "2022-09-06T23:38:23Z")

</div>

Hi All, We have recently upgraded our older ELK cluster which was on 7.15.2 to 8.4, We used Log correlation but when upgrade cluster we have the next error When use investigate \> trace logs I have results do i ne…

---

## [What is the tsconfig.json file for?](https://discuss.elastic.co/t/what-is-the-tsconfig-json-file-for/312446)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 4:39pm UTC](https://discuss.elastic.co/t/what-is-the-tsconfig-json-file-for/312446 "2022-09-07T16:39:02Z")

</div>

The below is the tsconfig.json file that comes by default when creating a plugin using kibana plugin generator. What is this file for? The below are the contents in the same. { "extends": "../../tsconfig.json", "…

---

## [Export Transformations Kibana](https://discuss.elastic.co/t/export-transformations-kibana/312708)

<div class="topic-metadata">

**Author:** [@atony](https://discuss.elastic.co/u/atony)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 4:07pm UTC](https://discuss.elastic.co/t/export-transformations-kibana/312708 "2022-09-07T16:07:18Z")

</div>

Hello guys, I would like to export all my dashboards, transformations and new indexes from a Kibana instance to another one. I have found that with saved objects -\> export, I can export all dashboards and related object…

---

## [Output Heap Space Usage for Kibana](https://discuss.elastic.co/t/output-heap-space-usage-for-kibana/313827)

<div class="topic-metadata">

**Author:** [@andreakatie](https://discuss.elastic.co/u/andreakatie)\
**Replies:** 2\
**Last updated:** [September 7, 2022, 3:45pm UTC](https://discuss.elastic.co/t/output-heap-space-usage-for-kibana/313827 "2022-09-07T15:45:25Z")

</div>

Hello all -- I was wondering if there was a way to gather heap space usage data for Kibana (and NGINX) specifically. Using JMeter, I am able to gather real-time heap data usage for the Elasticsearch service, but I have …

---

## [Rollover index lifecycle error](https://discuss.elastic.co/t/rollover-index-lifecycle-error/313900)

<div class="topic-metadata">

**Author:** [@artax\_sb](https://discuss.elastic.co/u/artax_sb)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 3:26pm UTC](https://discuss.elastic.co/t/rollover-index-lifecycle-error/313900 "2022-09-07T15:26:09Z")

</div>

Hi all! I know there are plenty post about this error but although i read them and all the doc I cant understand what is the error. I have an index already created which contains many logs--\> intextest I want to a…

---

## [Need to get documents with field have length \> 200 words](https://discuss.elastic.co/t/need-to-get-documents-with-field-have-length-200-words/312432)

<div class="topic-metadata">

**Author:** [@mani7](https://discuss.elastic.co/u/mani7)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 3:04pm UTC](https://discuss.elastic.co/t/need-to-get-documents-with-field-have-length-200-words/312432 "2022-09-07T15:04:01Z")

</div>

Trying to find the documents having field values lenght \> 200 characters

---

## [How to use multiple operators in EQL (Event query language)?](https://discuss.elastic.co/t/how-to-use-multiple-operators-in-eql-event-query-language/313852)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 7:09am UTC](https://discuss.elastic.co/t/how-to-use-multiple-operators-in-eql-event-query-language/313852 "2022-09-07T07:09:31Z")

</div>

Hi, I was wondering how to use multiple operators using EQL (Event Query Language). My EQL query is : any where office\_hours == false and winlog.event\_id == 4624 or winlog.event\_id == 4625 I would like to add parenth…

---

## [Facing issues in Metric format to replicate query from Grafana to KIBANA](https://discuss.elastic.co/t/facing-issues-in-metric-format-to-replicate-query-from-grafana-to-kibana/313892)

<div class="topic-metadata">

**Author:** [@ISHIKA](https://discuss.elastic.co/u/ISHIKA)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 2:02pm UTC](https://discuss.elastic.co/t/facing-issues-in-metric-format-to-replicate-query-from-grafana-to-kibana/313892 "2022-09-07T14:02:44Z")

</div>

Hello, I am trying to replicate the below query from prometheus GRFANA to KIBANA. I am not able to get same results, not even close. sum(node\_namespace\_pod\_container:container\_cpu\_usage\_seconds\_total:sum\_irate{namespa…

---

## [Is it Better to use Elastic UI with other framework?](https://discuss.elastic.co/t/is-it-better-to-use-elastic-ui-with-other-framework/313846)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 1:55pm UTC](https://discuss.elastic.co/t/is-it-better-to-use-elastic-ui-with-other-framework/313846 "2022-09-07T13:55:39Z")

</div>

Can I use Elastic UI with other Technology like Django? or with any other backends it's Says Elastic UI The framework powering the Elastic Stack I have been wondering if I could use it with Django or Node etc

---

## [Options List Control Ignores Filters and Queries](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/308962)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 7\
**Last updated:** [September 7, 2022, 1:52pm UTC](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/308962 "2022-09-07T13:52:44Z")

</div>

The Controls visualization has now been available for quite some time, but it is still being noted as a technical preview. Is there any plan to move this to GA? Since it was first introduced, it seems the Options List co…

---

## [Monitoring Elastic License On Prometheus](https://discuss.elastic.co/t/monitoring-elastic-license-on-prometheus/313870)

<div class="topic-metadata">

**Author:** [@takshika\_jambhule](https://discuss.elastic.co/u/takshika_jambhule)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 12:34pm UTC](https://discuss.elastic.co/t/monitoring-elastic-license-on-prometheus/313870 "2022-09-07T12:34:50Z")

</div>

I have installed elasticsearch\_exporter on my elastic boxes to set up alerts and monitoring on Prometheus.(GitHub - prometheus-community/elasticsearch\_exporter: Elasticsearch stats exporter for Prometheus) However, elast…

---

## [Use case Kibana Alerts vs Watcher](https://discuss.elastic.co/t/use-case-kibana-alerts-vs-watcher/313844)

<div class="topic-metadata">

**Author:** [@vwong](https://discuss.elastic.co/u/vwong)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 12:29pm UTC](https://discuss.elastic.co/t/use-case-kibana-alerts-vs-watcher/313844 "2022-09-07T12:29:06Z")

</div>

Hi, As I read from document, Kibana Alerts and watcher are both used to detect conditions and can trigger actions in response. As they offer similar function, would there use cases that can share for using either one o…

---

## [Kibana Canvas](https://discuss.elastic.co/t/kibana-canvas/313786)

<div class="topic-metadata">

**Author:** [@RobinIT](https://discuss.elastic.co/u/RobinIT)\
**Replies:** 8\
**Last updated:** [September 7, 2022, 11:59am UTC](https://discuss.elastic.co/t/kibana-canvas/313786 "2022-09-07T11:59:49Z")

</div>

Hello, I have a dashboard with a Pie, including some filters to specify the Slices of the pie. I want to build the Pie in canvas, but I don't know how. Can someone guide me a little bit, with some hints....how to get t…

---

## [Copy paste Kibana settings to multiple clusters](https://discuss.elastic.co/t/copy-paste-kibana-settings-to-multiple-clusters/313464)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 11:49am UTC](https://discuss.elastic.co/t/copy-paste-kibana-settings-to-multiple-clusters/313464 "2022-09-07T11:49:53Z")

</div>

We are running several elasticsearch/kibana clusters, with some modifications to the "advanced settings" in kibana Is there a way that we can automatically sync/propagate settings from one instance to another, to avoid …

---

## [Log alerting: trigger alert when specific log string has not been logged on specific time](https://discuss.elastic.co/t/log-alerting-trigger-alert-when-specific-log-string-has-not-been-logged-on-specific-time/313868)

<div class="topic-metadata">

**Author:** [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 9:49am UTC](https://discuss.elastic.co/t/log-alerting-trigger-alert-when-specific-log-string-has-not-been-logged-on-specific-time/313868 "2022-09-07T09:49:50Z")

</div>

Hello everbody, Hopefully somebody can help me out. For specific monitoring purposes i'm trying to achieve the following: We curruntly running ELK v 7.13.2 in our environment. We have a specific application server in w…

---

## [Sorting by date in log stream](https://discuss.elastic.co/t/sorting-by-date-in-log-stream/313339)

<div class="topic-metadata">

**Author:** [@conor\_c](https://discuss.elastic.co/u/conor_c)\
**Replies:** 4\
**Last updated:** [September 7, 2022, 8:55am UTC](https://discuss.elastic.co/t/sorting-by-date-in-log-stream/313339 "2022-09-07T08:55:48Z")

</div>

Hi All, I've been searching and searching for a solution, but I've not managed to find any relevant answers. I suspect I am looking in the wrong place or have misunderstood how some of the ELK stack tools are connected. …

---

## [Kibana TSVB to filter out aggregated result](https://discuss.elastic.co/t/kibana-tsvb-to-filter-out-aggregated-result/313859)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 8:01am UTC](https://discuss.elastic.co/t/kibana-tsvb-to-filter-out-aggregated-result/313859 "2022-09-07T08:01:43Z")

</div>

Anyone knows how to filter tsvb aggregated result? In my example below, I used 3 aggregations then grouped by Cluster, to capture the remaining memory % avg (MemoryUsageGB) avg(MemoryTotalGB) bucket script to get the …

---

## [How to create a runtime field to create an alert?](https://discuss.elastic.co/t/how-to-create-a-runtime-field-to-create-an-alert/312997)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 7\
**Last updated:** [September 7, 2022, 6:48am UTC](https://discuss.elastic.co/t/how-to-create-a-runtime-field-to-create-an-alert/312997 "2022-09-07T06:48:42Z")

</div>

Hi, I've created a field with a script to set the boolean "office\_hours" to true of false depending on the log hours. My painless script is : def office; if (doc\['@timestamp'\].value.hour \< 5 || doc\['@timestamp'\].value.…

---

## [Fail to run pre-built alerts due to non-existing fields](https://discuss.elastic.co/t/fail-to-run-pre-built-alerts-due-to-non-existing-fields/313801)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 1:53pm UTC](https://discuss.elastic.co/t/fail-to-run-pre-built-alerts-due-to-non-existing-fields/313801 "2022-09-06T13:53:35Z")

</div>

Hi, I am trying to use the pre-built alerts in Security \> Rules but the alert " Remote Computer Account DnsHostName Update" doesn't work. Here's the execution log of the rule "Remote Computer Account DnsHostName Updat…

---

## [If possible to increase that ILM Condition](https://discuss.elastic.co/t/if-possible-to-increase-that-ilm-condition/313440)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 4\
**Last updated:** [September 7, 2022, 2:45am UTC](https://discuss.elastic.co/t/if-possible-to-increase-that-ilm-condition/313440 "2022-09-07T02:45:04Z")

</div>

Hi team, we are having that 5.1 TB Hot node and 8.34 TB warm node in production with below condition Condition 1: 2 Days Condition 2: 50 GB We are using 4.5 TB disk Usage only and we can see more spaces are free in o…

---

## [Add Custom Anomaly Jobs to Kibana Metric Inventory](https://discuss.elastic.co/t/add-custom-anomaly-jobs-to-kibana-metric-inventory/313805)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 2:38pm UTC](https://discuss.elastic.co/t/add-custom-anomaly-jobs-to-kibana-metric-inventory/313805 "2022-09-06T14:38:25Z")

</div>

Hi All, I was wondering if there is a way to have Custom Anomaly Jobs to the Observability -\> Metrics -\> Inventory section. Context: Kibana 8.3.2 If I have a custom anomaly job that matches a host, it doesn't show up …

---

## [Input Controls in dark mode in v.8.4.1](https://discuss.elastic.co/t/input-controls-in-dark-mode-in-v-8-4-1/313760)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 2\
**Last updated:** [September 7, 2022, 1:14am UTC](https://discuss.elastic.co/t/input-controls-in-dark-mode-in-v-8-4-1/313760 "2022-09-07T01:14:28Z")

</div>

I upgraded ElastcCloud v.7.17.6 to v.8.4.1. Input controls seem to be not a better look and became unreadable in the suggestion list. The same data is in the suggestion list in v.7.17.6.

---

## [Kibana - Metricbeat Calculate time in application](https://discuss.elastic.co/t/kibana-metricbeat-calculate-time-in-application/313832)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 0\
**Last updated:** [September 6, 2022, 10:00pm UTC](https://discuss.elastic.co/t/kibana-metricbeat-calculate-time-in-application/313832 "2022-09-06T22:00:44Z")

</div>

I am trying to get a total time a user has spent in an application through metricbeat process.name field. I am able to show the following, but cannot work out a way to calculate a total time in the application. Any idea…

---

## [Packetbeat DNS response time nanoseconds instead of microseconds](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 4\
**Last updated:** [September 6, 2022, 8:33pm UTC](https://discuss.elastic.co/t/packetbeat-dns-response-time-nanoseconds-instead-of-microseconds/313710 "2022-09-06T20:33:44Z")

</div>

Dear All, I am running ELK stack 8.4.1 on latest Debian. Kibana/Packetbeat shows nice data in the DNS overview. When I move the mouse at DNS Min/Max/Avg Response Time Histogram over the graph I see for example max resp…

---

## [Visualize Library - Tools - Controls have wrong fields in filter section](https://discuss.elastic.co/t/visualize-library-tools-controls-have-wrong-fields-in-filter-section/312382)

<div class="topic-metadata">

**Author:** [@Wojciech\_Kwiecien](https://discuss.elastic.co/u/Wojciech_Kwiecien)\
**Replies:** 2\
**Last updated:** [September 6, 2022, 4:24pm UTC](https://discuss.elastic.co/t/visualize-library-tools-controls-have-wrong-fields-in-filter-section/312382 "2022-09-06T16:24:22Z")

</div>

Hello everyone. I tried to add some filterthe s into visualization section and like you the see on screen I selecthe ted in controls panel on the right side Index patter apm-\*-transaction and I tried to add in filter ur…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=181)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=183)
