# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=209

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 210

---

## [Watcher alert for index sizes](https://discuss.elastic.co/t/watcher-alert-for-index-sizes/305633)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [May 31, 2022, 4:42pm UTC](https://discuss.elastic.co/t/watcher-alert-for-index-sizes/305633 "2022-05-31T16:42:35Z")

</div>

Hi Team, I am trying to create an alert when any one of the index size crosses 200GB. I have created a watcher like below but i am getting an compile error not sure what was wrong. Could you please help me with this. {…

---

## [Kibana Canvas: How can I use a filter to show data per project?](https://discuss.elastic.co/t/kibana-canvas-how-can-i-use-a-filter-to-show-data-per-project/305627)

<div class="topic-metadata">

**Author:** [@Linda\_T](https://discuss.elastic.co/u/Linda_T)\
**Replies:** 1\
**Last updated:** [May 31, 2022, 3:50pm UTC](https://discuss.elastic.co/t/kibana-canvas-how-can-i-use-a-filter-to-show-data-per-project/305627 "2022-05-31T15:50:19Z")

</div>

Hi everyone, I have a question regarding the use of filters in Canvas, because within my Canvas report I want to show programme data as well as filtered data per project. Situation: I have created a Kibana Dashboard f…

---

## [Kibana alerts and actions setup](https://discuss.elastic.co/t/kibana-alerts-and-actions-setup/305758)

<div class="topic-metadata">

**Author:** [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Replies:** 1\
**Last updated:** [May 31, 2022, 3:31pm UTC](https://discuss.elastic.co/t/kibana-alerts-and-actions-setup/305758 "2022-05-31T15:31:41Z")

</div>

i am trying to get alerting and actions working but it seems to be disabled. Kibana points me to Alerting and Actions | Kibana Guide \[7.10\] | Elastic I have security setup already in Elasticsearch for authentication. x…

---

## [String to table](https://discuss.elastic.co/t/string-to-table/305309)

<div class="topic-metadata">

**Author:** [@fredyfredburger](https://discuss.elastic.co/u/fredyfredburger)\
**Replies:** 1\
**Last updated:** [May 31, 2022, 3:25pm UTC](https://discuss.elastic.co/t/string-to-table/305309 "2022-05-31T15:25:44Z")

</div>

I have a data feed that provides the linux df command as a value in my Elasticsearch database. The df output is contianed as a string in a single field. I need to display this in Canvas as a table, but can't figure out…

---

## [Elastic alerts get queued and never run thereafter](https://discuss.elastic.co/t/elastic-alerts-get-queued-and-never-run-thereafter/306049)

<div class="topic-metadata">

**Author:** [@Tesla\_User](https://discuss.elastic.co/u/Tesla_User)\
**Replies:** 0\
**Last updated:** [May 31, 2022, 2:43pm UTC](https://discuss.elastic.co/t/elastic-alerts-get-queued-and-never-run-thereafter/306049 "2022-05-31T14:43:27Z")

</div>

Whenever I create and run an alert, the alert is getting queued but not running thereafter. Is there a way to clear the threadpool queue and make the alerts run faster. Error: { "\_id" : "log\_error\_watch1\_4730bca4-191…

---

## [Kibana - controal {No options found}](https://discuss.elastic.co/t/kibana-controal-no-options-found/305678)

<div class="topic-metadata">

**Author:** [@as\_dh](https://discuss.elastic.co/u/as_dh)\
**Replies:** 6\
**Last updated:** [May 31, 2022, 1:57pm UTC](https://discuss.elastic.co/t/kibana-controal-no-options-found/305678 "2022-05-31T13:57:21Z")

</div>

Hello when i create Controls in dashbord page i got No options found kibana and elastic virsion 8.2 please help :frowning:

---

## [Individual visualization link](https://discuss.elastic.co/t/individual-visualization-link/306039)

<div class="topic-metadata">

**Author:** [@elknick](https://discuss.elastic.co/u/elknick)\
**Replies:** 2\
**Last updated:** [May 31, 2022, 1:45pm UTC](https://discuss.elastic.co/t/individual-visualization-link/306039 "2022-05-31T13:45:41Z")

</div>

Hi, I'm trying to use iFrame links to show my data elsewhere. I see that I can create a link to embed the entire dashboard. Is it possible to share a individual visualization out of the dashboard and not the whole thing…

---

## [Embed Kibana Visualizations in HTML Page](https://discuss.elastic.co/t/embed-kibana-visualizations-in-html-page/306040)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 0\
**Last updated:** [May 31, 2022, 1:34pm UTC](https://discuss.elastic.co/t/embed-kibana-visualizations-in-html-page/306040 "2022-05-31T13:34:16Z")

</div>

Similarly to this question we want to embed a vizualisation in an external web page. However, the solution given there, "use the iframe src from the dashboard" does not work. The dashboard does not use iframes and when w…

---

## [Need table format of ELK watcher](https://discuss.elastic.co/t/need-table-format-of-elk-watcher/306033)

<div class="topic-metadata">

**Author:** [@Sumanth\_Varma](https://discuss.elastic.co/u/Sumanth_Varma)\
**Replies:** 0\
**Last updated:** [May 31, 2022, 12:35pm UTC](https://discuss.elastic.co/t/need-table-format-of-elk-watcher/306033 "2022-05-31T12:35:06Z")

</div>

I am trying to get action of watcher output in a table format and the values will be added from aggr buckets. I am able to get it in table but all the values are getting printed in a single column.

---

## [Easy way to remove keywords mapping](https://discuss.elastic.co/t/easy-way-to-remove-keywords-mapping/305478)

<div class="topic-metadata">

**Author:** [@Evgeny\_Barykin](https://discuss.elastic.co/u/Evgeny_Barykin)\
**Replies:** 4\
**Last updated:** [May 31, 2022, 11:42am UTC](https://discuss.elastic.co/t/easy-way-to-remove-keywords-mapping/305478 "2022-05-31T11:42:01Z")

</div>

Hello! I am looking for an easy way to remove any keywords mapping from my metricbeat index. Can you give me an example of how can I do it, please?

---

## [Kibana maintenance mode](https://discuss.elastic.co/t/kibana-maintenance-mode/305909)

<div class="topic-metadata">

**Author:** [@andresf](https://discuss.elastic.co/u/andresf)\
**Replies:** 4\
**Last updated:** [May 31, 2022, 9:01am UTC](https://discuss.elastic.co/t/kibana-maintenance-mode/305909 "2022-05-31T09:01:34Z")

</div>

Hi, Currently at our office, we have maintenance schedule every night for the next couple of month. How can we ignore alert that happen from 7 PM to 7 AM? In other monitoring solution we have maintenance mode to tackle…

---

## [Kibana crashing when storing complex items on Elasticsearch](https://discuss.elastic.co/t/kibana-crashing-when-storing-complex-items-on-elasticsearch/305984)

<div class="topic-metadata">

**Author:** [@robjennings](https://discuss.elastic.co/u/robjennings)\
**Replies:** 6\
**Last updated:** [May 31, 2022, 1:32am UTC](https://discuss.elastic.co/t/kibana-crashing-when-storing-complex-items-on-elasticsearch/305984 "2022-05-31T01:32:31Z")

</div>

Hello, This is my first post in the community. I've been following this forum over the last months as I started to use more and more Elasticsearch on my day to day. I've been using Elasticsearch to store data from sever…

---

## [Trace queries and filters for audit](https://discuss.elastic.co/t/trace-queries-and-filters-for-audit/305821)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 5:57pm UTC](https://discuss.elastic.co/t/trace-queries-and-filters-for-audit/305821 "2022-05-30T17:57:04Z")

</div>

Hello, I enabled audit logs in Kibana but I cant find a way to track what is being put in the search bar, and which filters are being applied to dashboards/search sessions. Is there a way to achieve this? Thanks

---

## [Script exception runtime error](https://discuss.elastic.co/t/script-exception-runtime-error/305689)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [May 30, 2022, 3:07pm UTC](https://discuss.elastic.co/t/script-exception-runtime-error/305689 "2022-05-30T15:07:19Z")

</div>

Hi there, i have created scripted field for one of my index and here is the script: def path = doc\['request\_id.keyword'\].value; if (path != null) { def first = path.indexOf("\_"); def second = first + 1 + pat…

---

## [Rename Kibana space id](https://discuss.elastic.co/t/rename-kibana-space-id/305941)

<div class="topic-metadata">

**Author:** [@pranay\_jain](https://discuss.elastic.co/u/pranay_jain)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 2:19pm UTC](https://discuss.elastic.co/t/rename-kibana-space-id/305941 "2022-05-30T14:19:35Z")

</div>

Hi, I want to rename space name and id in Kibana. I noticed that using update API we can rename the space but not the space id. And if I rename the space, the dashboard title still displays the space id. So my question …

---

## [Inconsistent results when searching/deleting documents containing quotes](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 8\
**Last updated:** [May 30, 2022, 1:02pm UTC](https://discuss.elastic.co/t/inconsistent-results-when-searching-deleting-documents-containing-quotes/305698 "2022-05-30T13:02:11Z")

</div>

ES question in my document i have .... "message": "10.42.224.236 - 26/May/2022:06:15:58 +0000 "GET /index.php" 200" and i would like to match from GET to 200. If i query with GET /index\_prod\*/\_search { "query": …

---

## [How to calculate & draw metrics of scripted metrics](https://discuss.elastic.co/t/how-to-calculate-draw-metrics-of-scripted-metrics/305281)

<div class="topic-metadata">

**Author:** [@ultimate](https://discuss.elastic.co/u/ultimate)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 10:07am UTC](https://discuss.elastic.co/t/how-to-calculate-draw-metrics-of-scripted-metrics/305281 "2022-05-30T10:07:26Z")

</div>

Problem description we have log files from different devices parsed into our Elasticsearch database, line by line. The log files are built as a ring buffer, so they always have a fixed size of 1000 lines. They can be man…

---

## [Kibana reloads while updating query](https://discuss.elastic.co/t/kibana-reloads-while-updating-query/305370)

<div class="topic-metadata">

**Author:** [@gora](https://discuss.elastic.co/u/gora)\
**Replies:** 2\
**Last updated:** [May 30, 2022, 9:46am UTC](https://discuss.elastic.co/t/kibana-reloads-while-updating-query/305370 "2022-05-30T09:46:14Z")

</div>

Hi Team, Am using kibana from version 5.6.4 recently i have upgraded to 7.13.0 version. Am facing reload issue while updating the query. Before version 7.x.x when i change the time duration and click refresh only the wid…

---

## [Number\_of\_replicas is 1 for new indices, even in the template is set to 0](https://discuss.elastic.co/t/number-of-replicas-is-1-for-new-indices-even-in-the-template-is-set-to-0/305686)

<div class="topic-metadata">

**Author:** [@Daniel\_Rinzis](https://discuss.elastic.co/u/Daniel_Rinzis)\
**Replies:** 2\
**Last updated:** [May 30, 2022, 9:03am UTC](https://discuss.elastic.co/t/number-of-replicas-is-1-for-new-indices-even-in-the-template-is-set-to-0/305686 "2022-05-30T09:03:41Z")

</div>

Hello! Why is the number\_of\_replicas 1 for new indices in the cluster even though if I use GET \_template the number appears to be 0? "settings" : { "index" : { "refresh\_interval" : "30s", …

---

## [How to avoid “failed to find nested object under path” on Kibana?](https://discuss.elastic.co/t/how-to-avoid-failed-to-find-nested-object-under-path-on-kibana/303257)

<div class="topic-metadata">

**Author:** [@pranay\_jain](https://discuss.elastic.co/u/pranay_jain)\
**Replies:** 5\
**Last updated:** [May 30, 2022, 8:48am UTC](https://discuss.elastic.co/t/how-to-avoid-failed-to-find-nested-object-under-path-on-kibana/303257 "2022-05-30T08:48:35Z")

</div>

Hi, I have a Kibana dashboard which contains many widgets. The widgets displays data from multiple indices lets say index1 and index2. When I try to filter data by nested field for index1 using KQL I get 'failed to find…

---

## [Kibana Visual Library Controls](https://discuss.elastic.co/t/kibana-visual-library-controls/305767)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 8:18am UTC](https://discuss.elastic.co/t/kibana-visual-library-controls/305767 "2022-05-30T08:18:27Z")

</div>

Hi, In the Controls section of the Visual library is it possible to rearrange the order of the controls? E.g. in the added controls in the screenshot, I want to get the product related filters in one line. Thanks

---

## [TSVB Markdown to show sum of variables](https://discuss.elastic.co/t/tsvb-markdown-to-show-sum-of-variables/305878)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 2\
**Last updated:** [May 30, 2022, 7:50am UTC](https://discuss.elastic.co/t/tsvb-markdown-to-show-sum-of-variables/305878 "2022-05-30T07:50:24Z")

</div>

Hi guys, I have some problem with using markdown on TSVB: I would like to show a simple KPI (i.e: 1200) but this number should be a sum of 2 variables. In my documents I can select two filters: variable\_1 (filter fie…

---

## [How to Grab props from TopNavigationBar and use it in plugin](https://discuss.elastic.co/t/how-to-grab-props-from-topnavigationbar-and-use-it-in-plugin/305904)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 0\
**Last updated:** [May 30, 2022, 7:48am UTC](https://discuss.elastic.co/t/how-to-grab-props-from-topnavigationbar-and-use-it-in-plugin/305904 "2022-05-30T07:48:50Z")

</div>

I have rendered a data of movies how could I grab these props dataRangeFrom and dateRangeTo from TopNavigationBar in my plugin BM55 so that filtered my movies data manually the data which is been rendered is stored…

---

## [KIBANA ENHANCED DATATABLE DYNAMIC ASSIGN FIELD VALUE](https://discuss.elastic.co/t/kibana-enhanced-datatable-dynamic-assign-field-value/305722)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 7:18am UTC](https://discuss.elastic.co/t/kibana-enhanced-datatable-dynamic-assign-field-value/305722 "2022-05-30T07:18:06Z")

</div>

Hello All, I'm doing a usecase where in Role ,Group,User column in kibana I'm showing "string" value in bytes and need to know if there is possibility in kibana if this string value is converted to URL in kibana through…

---

## [Mapping Fields not loading with index pattern](https://discuss.elastic.co/t/mapping-fields-not-loading-with-index-pattern/305508)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 1\
**Last updated:** [May 30, 2022, 3:13am UTC](https://discuss.elastic.co/t/mapping-fields-not-loading-with-index-pattern/305508 "2022-05-30T03:13:55Z")

</div>

I have an custom index with name beat-testing while i trying to create an index in timestamp its not showing all fields. But when i view in index management the all mapping fields are existing there. How can i load the …

---

## [Error fetching fields for index pattern abcd-\* (ID: 9dffc420-9ea5-11ec-93d5-xxxxxxxxxx)](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-abcd-id-9dffc420-9ea5-11ec-93d5-xxxxxxxxxx/304552)

<div class="topic-metadata">

**Author:** [@homesh\_joshi](https://discuss.elastic.co/u/homesh_joshi)\
**Replies:** 7\
**Last updated:** [May 30, 2022, 3:04am UTC](https://discuss.elastic.co/t/error-fetching-fields-for-index-pattern-abcd-id-9dffc420-9ea5-11ec-93d5-xxxxxxxxxx/304552 "2022-05-30T03:04:30Z")

</div>

Hi , I am using kibana 7.17.0 , started getting this error "Error fetching fields for index pattern abcd-\* (ID: 9dffc420-9ea5-11ec-93d5-xxxxxxxxxx) undefined Response" from today. it was working from last 2 months. it p…

---

## [Kibana email connector "unable to verify the first certificate"](https://discuss.elastic.co/t/kibana-email-connector-unable-to-verify-the-first-certificate/304892)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 4\
**Last updated:** [May 29, 2022, 3:26pm UTC](https://discuss.elastic.co/t/kibana-email-connector-unable-to-verify-the-first-certificate/304892 "2022-05-29T15:26:47Z")

</div>

Dears, ELK in version: 7.16 I want to test and deploy email notification in Kibana. During configuration of email connector I've got error message like this: {"type":"log","@timestamp":"2022-05-17T08:51:18+02:00","tag…

---

## [Exporting kibana spaces & objects from all spaces](https://discuss.elastic.co/t/exporting-kibana-spaces-objects-from-all-spaces/305861)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 0\
**Last updated:** [May 28, 2022, 4:26pm UTC](https://discuss.elastic.co/t/exporting-kibana-spaces-objects-from-all-spaces/305861 "2022-05-28T16:26:35Z")

</div>

Hi, Is there a way to export entire Kibana spaces & its objects (like dashboards) to ndjson file in one go. Kibana 8.0 Thanks

---

## [Seems Role Kibana privileges are not the same as the DOCS](https://discuss.elastic.co/t/seems-role-kibana-privileges-are-not-the-same-as-the-docs/305846)

<div class="topic-metadata">

**Author:** [@Miguel\_Frazao](https://discuss.elastic.co/u/Miguel_Frazao)\
**Replies:** 2\
**Last updated:** [May 28, 2022, 3:26pm UTC](https://discuss.elastic.co/t/seems-role-kibana-privileges-are-not-the-same-as-the-docs/305846 "2022-05-28T15:26:31Z")

</div>

Hello I'm trying to create an User/Role to view only dashboard, I'm following this Kibana role management | Kibana Guide \[8.0\] | Elastic . However on this section Kibana role management | Kibana Guide \[8.0\] | Elastic as…

---

## [Filter in multiple docs](https://discuss.elastic.co/t/filter-in-multiple-docs/305741)

<div class="topic-metadata">

**Author:** [@Thiago\_Paiva](https://discuss.elastic.co/u/Thiago_Paiva)\
**Replies:** 1\
**Last updated:** [May 28, 2022, 2:24pm UTC](https://discuss.elastic.co/t/filter-in-multiple-docs/305741 "2022-05-28T14:24:58Z")

</div>

Hi, I have an index that has a tracking by ID. For each step that id pass writes a DOC to elastic. But I'm trying to make a filter that does the following validation. It passed Step2 but did not pass at Step4. Exempl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=208)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=210)
