# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=206

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 207

---

## [Get most recent distinct rows as kibana table](https://discuss.elastic.co/t/get-most-recent-distinct-rows-as-kibana-table/306524)

<div class="topic-metadata">

**Author:** [@chamod\_maduranga](https://discuss.elastic.co/u/chamod_maduranga)\
**Replies:** 2\
**Last updated:** [June 10, 2022, 3:44am UTC](https://discuss.elastic.co/t/get-most-recent-distinct-rows-as-kibana-table/306524 "2022-06-10T03:44:51Z")

</div>

I created index pattern and it has 4 fields(timestamp,Id,Type,Count). Need to get the most recent(based on the timestamp)rows with unique Type. Sample data: |timestamp|ID|Type|Count| |1/10/2022|1|A|12| |1/11/2022|2|A…

---

## [How to filter an index by the maximum value of a field?](https://discuss.elastic.co/t/how-to-filter-an-index-by-the-maximum-value-of-a-field/306755)

<div class="topic-metadata">

**Author:** [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Replies:** 1\
**Last updated:** [June 10, 2022, 1:21am UTC](https://discuss.elastic.co/t/how-to-filter-an-index-by-the-maximum-value-of-a-field/306755 "2022-06-10T01:21:43Z")

</div>

There is a field in the index by the name of date but the data of that field is not in a proper date format its only a number. So I want a filter to include only the data of maximum data of date field I mean how to creat…

---

## [In Scripted Field 'Create Field' grayed out and 'Name' input box missing only for some index patterns](https://discuss.elastic.co/t/in-scripted-field-create-field-grayed-out-and-name-input-box-missing-only-for-some-index-patterns/306824)

<div class="topic-metadata">

**Author:** [@nofmxc](https://discuss.elastic.co/u/nofmxc)\
**Replies:** 5\
**Last updated:** [June 9, 2022, 7:52pm UTC](https://discuss.elastic.co/t/in-scripted-field-create-field-grayed-out-and-name-input-box-missing-only-for-some-index-patterns/306824 "2022-06-09T19:52:38Z")

</div>

I'm trying to create a scripted field for an index. For my 'dev-logs' index it works great, but for my 'logs' index, the UI won't let me save the scripted field since the button is greyed out. Also weirdly there is no op…

---

## [Kibana behind nginx relative path](https://discuss.elastic.co/t/kibana-behind-nginx-relative-path/306764)

<div class="topic-metadata">

**Author:** [@hookenful](https://discuss.elastic.co/u/hookenful)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 4:52pm UTC](https://discuss.elastic.co/t/kibana-behind-nginx-relative-path/306764 "2022-06-09T16:52:03Z")

</div>

Hi there! Trying to achieve working kibana behing nginx relative path. Mydomain.com/kibana and it is not working. Mine docker-compose.yml kibana: image: reg.registry/only/kibana:7.11.2 environment: - SER…

---

## [Average count record per Min using LENS](https://discuss.elastic.co/t/average-count-record-per-min-using-lens/306379)

<div class="topic-metadata">

**Author:** [@dfraz](https://discuss.elastic.co/u/dfraz)\
**Replies:** 3\
**Last updated:** [June 9, 2022, 1:38pm UTC](https://discuss.elastic.co/t/average-count-record-per-min-using-lens/306379 "2022-06-09T13:38:44Z")

</div>

I need to calculate the Average count record ( orders ) per Min and then multiply by 60 to get an estimation of orders per hour. Can it be done with LENS ? Thanks in advance

---

## [Error executing 'postInstallation': EACCES: permission denied, mkdir '/bitnami/kibana/data'](https://discuss.elastic.co/t/error-executing-postinstallation-eacces-permission-denied-mkdir-bitnami-kibana-data/306798)

<div class="topic-metadata">

**Author:** [@mohamed\_atef](https://discuss.elastic.co/u/mohamed_atef)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 2:03pm UTC](https://discuss.elastic.co/t/error-executing-postinstallation-eacces-permission-denied-mkdir-bitnami-kibana-data/306798 "2022-06-09T14:03:57Z")

</div>

i have issue when i try to run kibana on K8S cluster via helm chart Error executing 'postInstallation': EACCES: permission denied, mkdir '/bitnami/kibana/data'

---

## [Snapshots in Kibana show failed while running](https://discuss.elastic.co/t/snapshots-in-kibana-show-failed-while-running/306702)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 1:45pm UTC](https://discuss.elastic.co/t/snapshots-in-kibana-show-failed-while-running/306702 "2022-06-09T13:45:04Z")

</div>

We upgraded from 7.11 to 7.16.3 and after the upgrade when we run snapshots of indices Kibana will show all the shards failed while the snapshot runs. Then once the snapshot completes it will have updated info and will …

---

## [Splunk vs. Elastic: Lookup Tables](https://discuss.elastic.co/t/splunk-vs-elastic-lookup-tables/306669)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 12:07pm UTC](https://discuss.elastic.co/t/splunk-vs-elastic-lookup-tables/306669 "2022-06-09T12:07:32Z")

</div>

Good Morning, I have been working with a customer for a while and they have chosen to migrate from Splunk to Elastic. One sticking point has been lookup tables. They had very specific lookup tables that provided them wi…

---

## [Alerting error: Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/alerting-error-cant-get-text-on-a-start-object/306781)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 11:25am UTC](https://discuss.elastic.co/t/alerting-error-cant-get-text-on-a-start-object/306781 "2022-06-09T11:25:04Z")

</div>

Hi all, I'm trying to create an alert for a query so that it sends an email when that query condition is met. When i try to create monitor & action, when i click on create -it throws an error-: \[illegal\_state\_except…

---

## [Unable to restore snapshot](https://discuss.elastic.co/t/unable-to-restore-snapshot/306771)

<div class="topic-metadata">

**Author:** [@noob2](https://discuss.elastic.co/u/noob2)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 8:53am UTC](https://discuss.elastic.co/t/unable-to-restore-snapshot/306771 "2022-06-09T08:53:44Z")

</div>

I logged in as admin user , still not able to restore snapshot from aws s3 , while creating snapshot , the response was "Success". while restoring the snapshot, i get the following response, { "error" : { "root…

---

## [Appending data to existing index](https://discuss.elastic.co/t/appending-data-to-existing-index/306533)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 6:23am UTC](https://discuss.elastic.co/t/appending-data-to-existing-index/306533 "2022-06-09T06:23:40Z")

</div>

I have an index that already has data. One of the lines in the CSV that was uploaded, had location field which reflects the co-ordinates for Vietname, showing null values due to which that particular line from the CSV d…

---

## [$ in Top N graph of TSVB](https://discuss.elastic.co/t/in-top-n-graph-of-tsvb/306666)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 6:04am UTC](https://discuss.elastic.co/t/in-top-n-graph-of-tsvb/306666 "2022-06-09T06:04:22Z")

</div>

Hi, I have a run time field "Abs Delta Value" which has format as $0,0.\[000\]. The $ sign is showing on all charts in lens and elsewhere except on TSVB. In the "Top N" chart under TSVB, it is only showing the number wi…

---

## [Index pattern doesn't have a UUID](https://discuss.elastic.co/t/index-pattern-doesnt-have-a-uuid/306596)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 3\
**Last updated:** [June 9, 2022, 5:02am UTC](https://discuss.elastic.co/t/index-pattern-doesnt-have-a-uuid/306596 "2022-06-09T05:02:46Z")

</div>

Hi, I exported all the objects (index patterns, visualizations, dashboards, etc.) to my new cluster. I need to change the index pattern to our visualizations. I noticed the old index pattern url doesn't have a UUID in i…

---

## [Memory leakage of Vega visualization when refreshing data](https://discuss.elastic.co/t/memory-leakage-of-vega-visualization-when-refreshing-data/306751)

<div class="topic-metadata">

**Author:** [@kyh119](https://discuss.elastic.co/u/kyh119)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 4:59am UTC](https://discuss.elastic.co/t/memory-leakage-of-vega-visualization-when-refreshing-data/306751 "2022-06-09T04:59:20Z")

</div>

Hi. I created a dashboard with my Vega visualizations that display the latest data. It's kind of real-time monitoring dashboard so I have to refresh every certain period. When it refreshes every 10 seconds, the heap s…

---

## [Line and barchart on same visualization for one sample point makes the linechart a single point](https://discuss.elastic.co/t/line-and-barchart-on-same-visualization-for-one-sample-point-makes-the-linechart-a-single-point/306748)

<div class="topic-metadata">

**Author:** [@tee101](https://discuss.elastic.co/u/tee101)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 12:59am UTC](https://discuss.elastic.co/t/line-and-barchart-on-same-visualization-for-one-sample-point-makes-the-linechart-a-single-point/306748 "2022-06-09T00:59:43Z")

</div>

In the following snapshot metric U is a barchart and metric A is a linechart. If there is one sample point, the linechart is just a point, and gets immersed in a big wide bar. Is there a way to have the point extrapolate…

---

## [Unable to create ingest pipeline. Error 504](https://discuss.elastic.co/t/unable-to-create-ingest-pipeline-error-504/306640)

<div class="topic-metadata">

**Author:** [@haopv](https://discuss.elastic.co/u/haopv)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 11:40pm UTC](https://discuss.elastic.co/t/unable-to-create-ingest-pipeline-error-504/306640 "2022-06-08T23:40:06Z")

</div>

When I try to create a new pipeline or update an old pipeline there's the response from UI says "Unable to create pipeline 504 Gateway timeout" although any other function in the cluster like indexing and searching w…

---

## [How to solve elastic error of "Readiness probe failed: Error: Got HTTP code 503 but expected a 200" in GKE?](https://discuss.elastic.co/t/how-to-solve-elastic-error-of-readiness-probe-failed-error-got-http-code-503-but-expected-a-200-in-gke/306726)

<div class="topic-metadata">

**Author:** [@Samuel\_Arogbonlo](https://discuss.elastic.co/u/Samuel_Arogbonlo)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 4:22pm UTC](https://discuss.elastic.co/t/how-to-solve-elastic-error-of-readiness-probe-failed-error-got-http-code-503-but-expected-a-200-in-gke/306726 "2022-06-08T16:22:02Z")

</div>

0 I am installing Elastic on GKE with the helm chart here. But after running this command helm upgrade kibana elastic/kibana --values kibana.yaml , it runs successfully but the pod gives this error Readiness probe faile…

---

## [So many layers with same data in MAP](https://discuss.elastic.co/t/so-many-layers-with-same-data-in-map/306676)

<div class="topic-metadata">

**Author:** [@akshay\_bhardwaj](https://discuss.elastic.co/u/akshay_bhardwaj)\
**Replies:** 3\
**Last updated:** [June 8, 2022, 9:25pm UTC](https://discuss.elastic.co/t/so-many-layers-with-same-data-in-map/306676 "2022-06-08T21:25:57Z")

</div>

When i draw a map with data there are so many layers on hover showing same data how i can reduce the same.

---

## [Index\_out\_of\_bounds\_exception](https://discuss.elastic.co/t/index-out-of-bounds-exception/306736)

<div class="topic-metadata">

**Author:** [@magedmakled](https://discuss.elastic.co/u/magedmakled)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/index-out-of-bounds-exception/306736 "2022-06-08T18:29:53Z")

</div>

Hello All, I have a query that was working but all the sudden it is returning index\_out\_of\_bounds\_exception. The document has a nested field events . I ran this directly from Kibana Elasticsearch 6. GET event\_lists/\_…

---

## [No alert on missing data - Kibana](https://discuss.elastic.co/t/no-alert-on-missing-data-kibana/305792)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 2:16pm UTC](https://discuss.elastic.co/t/no-alert-on-missing-data-kibana/305792 "2022-06-08T14:16:09Z")

</div>

Hello, I have set up alerts on the metric threshold like the one below. But when I stop the metricbeat on a server the state from "Active" changes to "Recovered" and no missing data alert is created. I was testin…

---

## [Opendistro Alerting indices retrieves nothing](https://discuss.elastic.co/t/opendistro-alerting-indices-retrieves-nothing/306707)

<div class="topic-metadata">

**Author:** [@noob2](https://discuss.elastic.co/u/noob2)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 2:05pm UTC](https://discuss.elastic.co/t/opendistro-alerting-indices-retrieves-nothing/306707 "2022-06-08T14:05:25Z")

</div>

Hi Team, I am facing some issue in opendistro kibana v7.10.2, The created alerts are not stored in Alerting index .opendistro-alerting-config as per opendistro documentation. But i can the see functionality working we…

---

## [How to write kql query in kibana to include only 9 characters of a field?](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672)

<div class="topic-metadata">

**Author:** [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Replies:** 5\
**Last updated:** [June 8, 2022, 11:02am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672 "2022-06-08T11:02:04Z")

</div>

I am using kibana 8.1 so I want to filter the data in discover section. Tha index has a field whic is in number format and it has different kinds of numbers which range from 4 characters up to 12 or 13 characters. So I w…

---

## [Numeric values on timeline](https://discuss.elastic.co/t/numeric-values-on-timeline/306548)

<div class="topic-metadata">

**Author:** [@g\_k\_b](https://discuss.elastic.co/u/g_k_b)\
**Replies:** 6\
**Last updated:** [June 8, 2022, 9:36am UTC](https://discuss.elastic.co/t/numeric-values-on-timeline/306548 "2022-06-08T09:36:20Z")

</div>

Hello Kibana users! Can anyone suggest me how can I represent numeric values on a timeline?he fields I'm referrering to are @timestamp and used.bytes; I want to see the distribution of this field over time. thank you in…

---

## [Group by kibana Query](https://discuss.elastic.co/t/group-by-kibana-query/306617)

<div class="topic-metadata">

**Author:** [@chamod\_maduranga](https://discuss.elastic.co/u/chamod_maduranga)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 9:08am UTC](https://discuss.elastic.co/t/group-by-kibana-query/306617 "2022-06-08T09:08:46Z")

</div>

I have fields ID, Type, Count and timestamp as follows: { "ID": "15211", "Type": "C", "count": "17", "timestamp": "Jun 3, 2022 @ 12:26:34.000",....}, { "ID": "11243", "Type": "C", "count": "64", "timestamp": "Jun 1, 202…

---

## [Timelion Aggregate graph with different interval/condition](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651)

<div class="topic-metadata">

**Author:** [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651 "2022-06-08T08:15:40Z")

</div>

Hello, I'm trying to create a Timelion aggregation and wondering if its possible. Basically the case is, I have documents that includes http response codes. What i'm trying to do is: The default interval could be day…

---

## [Aggregration buckets can access in Elasticsearch query of "Rules and Connectors"](https://discuss.elastic.co/t/aggregration-buckets-can-access-in-elasticsearch-query-of-rules-and-connectors/306641)

<div class="topic-metadata">

**Author:** [@hari\_priya1](https://discuss.elastic.co/u/hari_priya1)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 7:17am UTC](https://discuss.elastic.co/t/aggregration-buckets-can-access-in-elasticsearch-query-of-rules-and-connectors/306641 "2022-06-08T07:17:58Z")

</div>

I am trying to trigger an alert if BindRequestCount is zero for the last 30 mins. So I have created a rule using the Elasticsearch query rule type. { "query": { "bool": { "must": \[ { "term"…

---

## [Visualize datatable : reformat aggrated value](https://discuss.elastic.co/t/visualize-datatable-reformat-aggrated-value/306562)

<div class="topic-metadata">

**Author:** [@Espen\_Schulstad](https://discuss.elastic.co/u/Espen_Schulstad)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 5:38am UTC](https://discuss.elastic.co/t/visualize-datatable-reformat-aggrated-value/306562 "2022-06-08T05:38:44Z")

</div>

Hi, I'd like to use a value in an aggregation to create a link in the datatable. Is this possible? Eg; in the datatable I have a value "specific app name", I'd like to reformat that value to be a string that ends up as…

---

## [Enable control access to user in Kibana 8](https://discuss.elastic.co/t/enable-control-access-to-user-in-kibana-8/306539)

<div class="topic-metadata">

**Author:** [@eduhernandezm](https://discuss.elastic.co/u/eduhernandezm)\
**Replies:** 3\
**Last updated:** [June 8, 2022, 4:07am UTC](https://discuss.elastic.co/t/enable-control-access-to-user-in-kibana-8/306539 "2022-06-08T04:07:27Z")

</div>

Hello, I have recently installed and configured the ELK architecture on three different linux servers. The configuration that has been implemented is the one that comes by default. Right now, I'm at the point where I …

---

## [Time Filter in Kibana Disappeared for Some Users](https://discuss.elastic.co/t/time-filter-in-kibana-disappeared-for-some-users/306494)

<div class="topic-metadata">

**Author:** [@Datt\_Mamon](https://discuss.elastic.co/u/Datt_Mamon)\
**Replies:** 5\
**Last updated:** [June 7, 2022, 7:57pm UTC](https://discuss.elastic.co/t/time-filter-in-kibana-disappeared-for-some-users/306494 "2022-06-07T19:57:06Z")

</div>

Hey all! Ran into a little issue with my Kibana instance that I'm hoping the wonderful community can help me out with. I created a new space and roles for a group of users to look at logs specific to their groups' work…

---

## [Not getting the latest logs in kibana](https://discuss.elastic.co/t/not-getting-the-latest-logs-in-kibana/306167)

<div class="topic-metadata">

**Author:** [@Dev220](https://discuss.elastic.co/u/Dev220)\
**Replies:** 5\
**Last updated:** [June 7, 2022, 9:01pm UTC](https://discuss.elastic.co/t/not-getting-the-latest-logs-in-kibana/306167 "2022-06-07T21:01:39Z")

</div>

Hi Team, I am new to kibana. For collecting the logs from my application pods I am using fluent-bit configuration as a pod. Both the Elasticsearch and kiban services are up and running. I am able to see the logs in k…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=205)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=207)
