# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=19

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 20

---

## [Kibana Dashboards controls not interactive](https://discuss.elastic.co/t/kibana-dashboards-controls-not-interactive/369713)

<div class="topic-metadata">

**Author:** [@phani\_kumar](https://discuss.elastic.co/u/phani_kumar)\
**Replies:** 5\
**Last updated:** [March 31, 2025, 8:53am UTC](https://discuss.elastic.co/t/kibana-dashboards-controls-not-interactive/369713 "2025-03-31T08:53:24Z")

</div>

I've couple of dashboards in my kibana space. For both the dashboards, using controls \[optionlist\], created a filter using one field in my index. Also using links, formed horizontal menu / tabs to navigate between one a…

---

## [Can't use @timestamp in WHERE clause](https://discuss.elastic.co/t/cant-use-timestamp-in-where-clause/376517)

<div class="topic-metadata">

**Author:** [@JensHaglof](https://discuss.elastic.co/u/JensHaglof)\
**Replies:** 4\
**Last updated:** [March 28, 2025, 1:32pm UTC](https://discuss.elastic.co/t/cant-use-timestamp-in-where-clause/376517 "2025-03-28T13:32:45Z")

</div>

This query works: query=" SELECT COUNT(1) as value FROM "drs-fija-order" WHERE 1 = 1" This doesn't: query=" SELECT COUNT(1) as value FROM "drs-fija-order" WHERE 1 = 1 and @timestamp \> NOW() - interval 1 hour" …

---

## [Last\_value sorting by date value](https://discuss.elastic.co/t/last-value-sorting-by-date-value/376417)

<div class="topic-metadata">

**Author:** [@kimraik](https://discuss.elastic.co/u/kimraik)\
**Replies:** 2\
**Last updated:** [March 27, 2025, 2:53pm UTC](https://discuss.elastic.co/t/last-value-sorting-by-date-value/376417 "2025-03-27T14:53:48Z")

</div>

when using "last\_value" to display certain data, there is an option based on which date field the last\_value is sorted but this option is gone when using "last\_value" in a formula. Or at least I did not see any. In case …

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. self signed certificate](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes-self-signed-certificate/376240)

<div class="topic-metadata">

**Author:** [@Rupavathi](https://discuss.elastic.co/u/Rupavathi)\
**Replies:** 21\
**Last updated:** [March 27, 2025, 10:21am UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes-self-signed-certificate/376240 "2025-03-27T10:21:19Z")

</div>

Hi, I am facing an issue while integrating kibana with elasticsearch. I have created my own company rootCA and created kibana.crt and kibana.key and registered with rootCA. After I run the docker compose up , I was not …

---

## [MISP Elastic Intergration using Filebeat](https://discuss.elastic.co/t/misp-elastic-intergration-using-filebeat/376196)

<div class="topic-metadata">

**Author:** [@Muhammadh\_Zakir\_Huss](https://discuss.elastic.co/u/Muhammadh_Zakir_Huss)\
**Replies:** 1\
**Last updated:** [March 27, 2025, 4:53am UTC](https://discuss.elastic.co/t/misp-elastic-intergration-using-filebeat/376196 "2025-03-27T04:53:04Z")

</div>

Hi, I have installed a MISP instance and Filebeat in a Ubuntu server. I have configured the filebeat to query the MISP instance for IOCs and upload it to Elasticsearch. I am getting the logs but I see an error.message: U…

---

## [Kibana Logs Authentication Failure](https://discuss.elastic.co/t/kibana-logs-authentication-failure/376385)

<div class="topic-metadata">

**Author:** [@Echo\_01](https://discuss.elastic.co/u/Echo_01)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 3:02pm UTC](https://discuss.elastic.co/t/kibana-logs-authentication-failure/376385 "2025-03-25T15:02:11Z")

</div>

Kibana is generating failure logs like the following: \[2025-03-25T15:49:06.652+01:00\]\[INFO \]\[plugins.security.authentication\] Authentication attempt failed: {"error":{"root\_cause":\[{"type":"security\_exception","reason":…

---

## [Pass angular parameter to Kibana dashboard](https://discuss.elastic.co/t/pass-angular-parameter-to-kibana-dashboard/376372)

<div class="topic-metadata">

**Author:** [@mittal\_rawal1](https://discuss.elastic.co/u/mittal_rawal1)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 10:08am UTC](https://discuss.elastic.co/t/pass-angular-parameter-to-kibana-dashboard/376372 "2025-03-25T10:08:57Z")

</div>

Hi Team, We have a requirement to access parameters from angular to Kibana Dashboard/ visualization charts. Is there any way we can pass angular parameter to Kibana Dashboard?

---

## [Missing response option in transaction section](https://discuss.elastic.co/t/missing-response-option-in-transaction-section/376365)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 0\
**Last updated:** [March 25, 2025, 7:14am UTC](https://discuss.elastic.co/t/missing-response-option-in-transaction-section/376365 "2025-03-25T07:14:49Z")

</div>

Hi all, in above image as highlighted, i can see only request in dropdown. how can i unable response option? basically inside Observability -\> APM -\>Services -\>service\_name -\> Transactions-\> specific transaction in…

---

## [Increase Fields Statistics on Discover Tab Kibana](https://discuss.elastic.co/t/increase-fields-statistics-on-discover-tab-kibana/376322)

<div class="topic-metadata">

**Author:** [@Sohaib\_Khan](https://discuss.elastic.co/u/Sohaib_Khan)\
**Replies:** 2\
**Last updated:** [March 25, 2025, 7:36am UTC](https://discuss.elastic.co/t/increase-fields-statistics-on-discover-tab-kibana/376322 "2025-03-25T07:36:34Z")

</div>

Hi, I want to increase the count of field statistics on Kibana. Currently, I have more than a million records but on-field statistics give results based on 55000 records. I want to increase it to match the exact count …

---

## [Blocked by virus software Kibana 8.3.17](https://discuss.elastic.co/t/blocked-by-virus-software-kibana-8-3-17/376349)

<div class="topic-metadata">

**Author:** [@ripacheco1967](https://discuss.elastic.co/u/ripacheco1967)\
**Replies:** 0\
**Last updated:** [March 24, 2025, 9:39pm UTC](https://discuss.elastic.co/t/blocked-by-virus-software-kibana-8-3-17/376349 "2025-03-24T21:39:31Z")

</div>

Norton is blocking us from downloading Kibana 8.3.17 to a Mac (Silicon M1) Threat name: PwrSh:Obfuscated-AH \[Cryp\] Severity: 2 Threat type: Cryptic File name: kibana-8.17.3-darwin-aarch64.tar File path: /Users/rober…

---

## [.siem-signals-default doesn't exists](https://discuss.elastic.co/t/siem-signals-default-doesnt-exists/376342)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 0\
**Last updated:** [March 24, 2025, 5:49pm UTC](https://discuss.elastic.co/t/siem-signals-default-doesnt-exists/376342 "2025-03-24T17:49:54Z")

</div>

Hi, I can't see the .siem-signals-default index on Index Management. I'm trying to use the detection API on signals but it always returns 0 results. The version is 8.17.2. Thank you

---

## [Preserving time filter in Kibana dashboard item url panel options](https://discuss.elastic.co/t/preserving-time-filter-in-kibana-dashboard-item-url-panel-options/375716)

<div class="topic-metadata">

**Author:** [@kbfirebreather](https://discuss.elastic.co/u/kbfirebreather)\
**Replies:** 2\
**Last updated:** [March 24, 2025, 5:08pm UTC](https://discuss.elastic.co/t/preserving-time-filter-in-kibana-dashboard-item-url-panel-options/375716 "2025-03-24T17:08:39Z")

</div>

I have a dashboard that aggregate K8s pods over a given time span. When I click the entry in the table, it takes me to the logs for that pod. The time filter resets back to last 15 minutes. Is there a way to reference th…

---

## [Kibana Dashboard Slowdowns with Large Elasticsearch Indexes](https://discuss.elastic.co/t/kibana-dashboard-slowdowns-with-large-elasticsearch-indexes/376273)

<div class="topic-metadata">

**Author:** [@SamuelPrice](https://discuss.elastic.co/u/SamuelPrice)\
**Replies:** 1\
**Last updated:** [March 23, 2025, 11:38pm UTC](https://discuss.elastic.co/t/kibana-dashboard-slowdowns-with-large-elasticsearch-indexes/376273 "2025-03-23T23:38:04Z")

</div>

Hi everyone, I’m running into performance issues with my Kibana dashboards when working with large Elasticsearch indexes. The dashboards, especially those that include multiple visualizations, are starting to load slowe…

---

## [Disk IO - How to visualize Max Disk Throughput](https://discuss.elastic.co/t/disk-io-how-to-visualize-max-disk-throughput/360803)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [March 23, 2025, 6:52pm UTC](https://discuss.elastic.co/t/disk-io-how-to-visualize-max-disk-throughput/360803 "2025-03-23T18:52:34Z")

</div>

Hello is there a way to visualize the Disk Throughput using Lens? I want to do a line graph but it seems like its not possible to do it with Lens. Here's the fields: system.diskio.read.bytes The total number of bytes…

---

## [Vega Error - Node Not Found](https://discuss.elastic.co/t/vega-error-node-not-found/376268)

<div class="topic-metadata">

**Author:** [@adwaitjoshi](https://discuss.elastic.co/u/adwaitjoshi)\
**Replies:** 0\
**Last updated:** [March 22, 2025, 9:51pm UTC](https://discuss.elastic.co/t/vega-error-node-not-found/376268 "2025-03-22T21:51:21Z")

</div>

I am getting an vega error Node Not Found XXX i dont know whats going on. { "$schema": "https://vega.github.io/schema/vega/v5.json", "title": "Merchant Transaction Network", "width": 800, "height": 600, "autos…

---

## [The contribution docs seems to be broken](https://discuss.elastic.co/t/the-contribution-docs-seems-to-be-broken/376267)

<div class="topic-metadata">

**Author:** [@ArtistBanda](https://discuss.elastic.co/u/ArtistBanda)\
**Replies:** 0\
**Last updated:** [March 22, 2025, 7:04pm UTC](https://discuss.elastic.co/t/the-contribution-docs-seems-to-be-broken/376267 "2025-03-22T19:04:22Z")

</div>

I was planning to contribute to Kibana but the contributions docs seems to be broken here LINK. The new link is only open for employees and the old link is 404.

---

## [How to test a pipeline with a CSV processor](https://discuss.elastic.co/t/how-to-test-a-pipeline-with-a-csv-processor/376197)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 2\
**Last updated:** [March 21, 2025, 10:50pm UTC](https://discuss.elastic.co/t/how-to-test-a-pipeline-with-a-csv-processor/376197 "2025-03-21T22:50:14Z")

</div>

I want to ingest this csv file: text,value The triangle is blue.,10 The square is red.,20 There are two red circles.,30 The triangle is green.,40 I created this ingestion pipeline: \[ { "csv": { "field": "m…

---

## [Why multi-fields display in kibana?](https://discuss.elastic.co/t/why-multi-fields-display-in-kibana/376206)

<div class="topic-metadata">

**Author:** [@Anson5](https://discuss.elastic.co/u/Anson5)\
**Replies:** 0\
**Last updated:** [March 20, 2025, 9:47pm UTC](https://discuss.elastic.co/t/why-multi-fields-display-in-kibana/376206 "2025-03-20T21:47:08Z")

</div>

I have three indexes: ta-logs-info, ta-logs-error, and ta-logs-trace, all using the same mapping. I’ve also created four different index patterns: ta-logs-info ta-logs-error ta-logs-trace ta-logs\* (covering all three i…

---

## [Index search: What is the opposite of is:isManaged](https://discuss.elastic.co/t/index-search-what-is-the-opposite-of-is-ismanaged/376192)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [March 20, 2025, 8:27pm UTC](https://discuss.elastic.co/t/index-search-what-is-the-opposite-of-is-ismanaged/376192 "2025-03-20T20:27:54Z")

</div>

I'm on Stack Management/Ingest Pipelines in Kibana. I can search for all the managed pipelines by entering is:isManaged. What query string do I enter to find all the non-managed pipelines? I don't know what query langua…

---

## [Split function not working when canvas is created](https://discuss.elastic.co/t/split-function-not-working-when-canvas-is-created/375899)

<div class="topic-metadata">

**Author:** [@JensHaglof](https://discuss.elastic.co/u/JensHaglof)\
**Replies:** 3\
**Last updated:** [March 20, 2025, 7:24am UTC](https://discuss.elastic.co/t/split-function-not-working-when-canvas-is-created/375899 "2025-03-20T07:24:38Z")

</div>

Hi everyone! I'm experiencing a strange issue. We have data coming into Elastic as a CSV file, delimited by semicolons. When I create a table in Canvas, some rows contain data from another column. Additionally, in one…

---

## [Lens reference line that scales with bucket/window size](https://discuss.elastic.co/t/lens-reference-line-that-scales-with-bucket-window-size/376092)

<div class="topic-metadata">

**Author:** [@dpotter](https://discuss.elastic.co/u/dpotter)\
**Replies:** 1\
**Last updated:** [March 19, 2025, 4:30pm UTC](https://discuss.elastic.co/t/lens-reference-line-that-scales-with-bucket-window-size/376092 "2025-03-19T16:30:09Z")

</div>

Hi - I'd like to add a static reference line to my Kibana Lens visualization, but I'd like the line to scale based on the bucket/window size. For example, I'd like to set the reference line to 1,000 per minute. If th…

---

## [Kibana Visualization Transformation Layer](https://discuss.elastic.co/t/kibana-visualization-transformation-layer/376126)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 2:16pm UTC](https://discuss.elastic.co/t/kibana-visualization-transformation-layer/376126 "2025-03-19T14:16:08Z")

</div>

Hello, I have been exploring other data visualization solutions like Grafana and Power BI. One big thing I have noticed is they offer a transformation layer when building your visualization. This transformation layer ac…

---

## [Any Vega Community Examples](https://discuss.elastic.co/t/any-vega-community-examples/376034)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [March 19, 2025, 1:35pm UTC](https://discuss.elastic.co/t/any-vega-community-examples/376034 "2025-03-19T13:35:24Z")

</div>

Hello All, I am curious to learn about other's implementations of Vega in their dashboards? I would like to explore more ways to visualize my data (open to any use case) using Vega, and I feel like I just ask to see wha…

---

## [False alert for watcher](https://discuss.elastic.co/t/false-alert-for-watcher/376115)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 10:40am UTC](https://discuss.elastic.co/t/false-alert-for-watcher/376115 "2025-03-19T10:40:42Z")

</div>

We have a watcher to check a java process for an application on two servers. But issue is that the application team use to get false alerts from ELK even the processes are up . { "trigger": { "schedule": { "…

---

## [I am working to get the metrics onboarded for brocade san switches to kibana](https://discuss.elastic.co/t/i-am-working-to-get-the-metrics-onboarded-for-brocade-san-switches-to-kibana/376107)

<div class="topic-metadata">

**Author:** [@gvp1983](https://discuss.elastic.co/u/gvp1983)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 6:52am UTC](https://discuss.elastic.co/t/i-am-working-to-get-the-metrics-onboarded-for-brocade-san-switches-to-kibana/376107 "2025-03-19T06:52:53Z")

</div>

I am using telegraf and snmp to get the performance metrics from brocade san switches and the output to Kafka and sending the same to elastic and u want to create a dashboard and need to know how to we plot the counter32…

---

## [Kibana Canvas - dropdownControl v. 8.9.2](https://discuss.elastic.co/t/kibana-canvas-dropdowncontrol-v-8-9-2/376096)

<div class="topic-metadata">

**Author:** [@emmanuel.sanchez](https://discuss.elastic.co/u/emmanuel.sanchez)\
**Replies:** 1\
**Last updated:** [March 18, 2025, 9:52pm UTC](https://discuss.elastic.co/t/kibana-canvas-dropdowncontrol-v-8-9-2/376096 "2025-03-18T21:52:36Z")

</div>

Hi there, I'm trying to use a dropdownControl in order to filter values from a datatable, but i was unable to do that, i followed some post here but i can't fix it. The currently behaviour is the following: In my dropd…

---

## [Watcher for monitor a process does not work](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 1\
**Last updated:** [March 18, 2025, 1:35pm UTC](https://discuss.elastic.co/t/watcher-for-monitor-a-process-does-not-work/376064 "2025-03-18T13:35:39Z")

</div>

We have created a watcher to monitor a process in a linux server but it does not fired and only taking the sleeping state of the process . { "trigger": { "schedule": { "interval": "5m" } }, "input": …

---

## [All users are listed in the alerts assignees](https://discuss.elastic.co/t/all-users-are-listed-in-the-alerts-assignees/376047)

<div class="topic-metadata">

**Author:** [@tarek](https://discuss.elastic.co/u/tarek)\
**Replies:** 0\
**Last updated:** [March 18, 2025, 7:20am UTC](https://discuss.elastic.co/t/all-users-are-listed-in-the-alerts-assignees/376047 "2025-03-18T07:20:02Z")

</div>

Hi, Is there a way to limit the list of users that can be shown in the alerts assignees dropdown list? lets say we have user1 with role: role1 and this role has only access to space1. can we configure kibana so that wh…

---

## [Lens Metric with Graph Underlay](https://discuss.elastic.co/t/lens-metric-with-graph-underlay/376035)

<div class="topic-metadata">

**Author:** [@ArielC](https://discuss.elastic.co/u/ArielC)\
**Replies:** 2\
**Last updated:** [March 17, 2025, 10:31pm UTC](https://discuss.elastic.co/t/lens-metric-with-graph-underlay/376035 "2025-03-17T22:31:47Z")

</div>

I would like to create a Metric visualization using Lens similar to one mentioned in the post below: https://discuss.elastic.co/t/metric-background-change-based-on-last-week-value/345082 How can I add a graph under…

---

## [Warning messages in kibana - not connecting to elasticsearch](https://discuss.elastic.co/t/warning-messages-in-kibana-not-connecting-to-elasticsearch/376015)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 1\
**Last updated:** [March 17, 2025, 8:41pm UTC](https://discuss.elastic.co/t/warning-messages-in-kibana-not-connecting-to-elasticsearch/376015 "2025-03-17T20:41:33Z")

</div>

elasticsearch and kibana seems to be working but kibana cannot connect to elasticsearch # systemctl status kibana ● kibana.service - Kibana Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; vendor pr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=18)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=20)
