# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=214

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 215

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/303491)

<div class="topic-metadata">

**Author:** [@MAD\_MIkE](https://discuss.elastic.co/u/MAD_MIkE)\
**Replies:** 6\
**Last updated:** [May 16, 2022, 7:32pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/303491 "2022-05-16T19:32:11Z")

</div>

In order to install ELK in offline mode. I download all three rm package of Elasticsearch, kibana, logstash version 8.1.3 Elasticsearchsearch is installed successefully and service is running. Kibana is installed eithe…

---

## [JSON Filter works but filter refresh doesn't fix cache mapping error](https://discuss.elastic.co/t/json-filter-works-but-filter-refresh-doesnt-fix-cache-mapping-error/304708)

<div class="topic-metadata">

**Author:** [@Jim\_Thunder](https://discuss.elastic.co/u/Jim_Thunder)\
**Replies:** 10\
**Last updated:** [May 16, 2022, 3:44pm UTC](https://discuss.elastic.co/t/json-filter-works-but-filter-refresh-doesnt-fix-cache-mapping-error/304708 "2022-05-16T15:44:48Z")

</div>

Hello, I have JSON messages coming to logstash and they are getting parsed properly, however, I get the error message "no cache mapping, refresh index field list". I have done this multiple times but the error does not g…

---

## [Kibana rules and group by](https://discuss.elastic.co/t/kibana-rules-and-group-by/304572)

<div class="topic-metadata">

**Author:** [@ChristianOelsner](https://discuss.elastic.co/u/ChristianOelsner)\
**Replies:** 1\
**Last updated:** [May 16, 2022, 12:30pm UTC](https://discuss.elastic.co/t/kibana-rules-and-group-by/304572 "2022-05-16T12:30:53Z")

</div>

Hi all, I am trying to create a rule/alert. The rule is working as inteded, but the mail notification is causing my troubles. Hopefully someone smarter than me can point me in the right direction. I am using the UI t…

---

## [Index Lifecycle Policy not deleting - "Waiting for all shard copies to be active"](https://discuss.elastic.co/t/index-lifecycle-policy-not-deleting-waiting-for-all-shard-copies-to-be-active/304801)

<div class="topic-metadata">

**Author:** [@Bavaria](https://discuss.elastic.co/u/Bavaria)\
**Replies:** 5\
**Last updated:** [May 16, 2022, 10:37am UTC](https://discuss.elastic.co/t/index-lifecycle-policy-not-deleting-waiting-for-all-shard-copies-to-be-active/304801 "2022-05-16T10:37:01Z")

</div>

Can anyone help me with this? The policy is not deleting my indices after certain time. I put them to just to several days to see if its working. I am getting the message in my indices: Waiting for all shard copies to be…

---

## [Cannot create an index pattern](https://discuss.elastic.co/t/cannot-create-an-index-pattern/304779)

<div class="topic-metadata">

**Author:** [@lior\_doanis](https://discuss.elastic.co/u/lior_doanis)\
**Replies:** 3\
**Last updated:** [May 16, 2022, 9:49am UTC](https://discuss.elastic.co/t/cannot-create-an-index-pattern/304779 "2022-05-16T09:49:19Z")

</div>

Hi, So I setup ELK on a single server and I try to send telemetry to him, what I did is create index template and pipeline, Now, I try to create index pattern, But I cannot create one all I have from the list is one…

---

## [Integrating ELK 8.0 with Splunk](https://discuss.elastic.co/t/integrating-elk-8-0-with-splunk/303219)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 2\
**Last updated:** [May 16, 2022, 4:02am UTC](https://discuss.elastic.co/t/integrating-elk-8-0-with-splunk/303219 "2022-05-16T04:02:24Z")

</div>

We are planning to integrate ELK 8.0 with Splunk. can some one provide steps how to send elk data to splunk

---

## [Getaddrinfo EAI\_AGAIN elasticsearch](https://discuss.elastic.co/t/getaddrinfo-eai-again-elasticsearch/304757)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [May 15, 2022, 9:39pm UTC](https://discuss.elastic.co/t/getaddrinfo-eai-again-elasticsearch/304757 "2022-05-15T21:39:12Z")

</div>

I have following problem with Kibana, which just installed with whole ELK stack on fresh system Ubuntu 20.04.4 LTS: Kibana server is not ready yet. Error in logs: {"ecs":{"version":"8.0.0"},"@timestamp":"2022-05-15T15…

---

## [8.2 Rule Preview Not Working](https://discuss.elastic.co/t/8-2-rule-preview-not-working/304739)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 0\
**Last updated:** [May 15, 2022, 2:04am UTC](https://discuss.elastic.co/t/8-2-rule-preview-not-working/304739 "2022-05-15T02:04:21Z")

</div>

We just upgraded to 8.2 and we create different roles for users to allow for certain behavior. I'm following this guide, and I want to allow users to preview rules but not give them full admin access - Detections prereq…

---

## [Need to add time range filter condition in below watcher](https://discuss.elastic.co/t/need-to-add-time-range-filter-condition-in-below-watcher/304719)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [May 14, 2022, 5:36am UTC](https://discuss.elastic.co/t/need-to-add-time-range-filter-condition-in-below-watcher/304719 "2022-05-14T05:36:24Z")

</div>

Hello team, Need to add time range filter condition in below watcher. i am unable to identify where i need to exactly put below condions: I think my script is checking whole data if i not mentioned any range filter. I …

---

## [Kibana - Nginx 502 Bad Gateway](https://discuss.elastic.co/t/kibana-nginx-502-bad-gateway/304709)

<div class="topic-metadata">

**Author:** [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 7:54pm UTC](https://discuss.elastic.co/t/kibana-nginx-502-bad-gateway/304709 "2022-05-13T19:54:33Z")

</div>

I tried logging into Kibana and was greeted with a 502 Bad Gateway error. Our setup is a single server hosting elastic, logstash and kibana. On the server, I got a 302 redirect when running curl -i http://localhost:5601.…

---

## [Error when accessing Security module on Elasticsearch 8.1 (Error: n is undefined)](https://discuss.elastic.co/t/error-when-accessing-security-module-on-elasticsearch-8-1-error-n-is-undefined/301278)

<div class="topic-metadata">

**Author:** [@aanton](https://discuss.elastic.co/u/aanton)\
**Replies:** 4\
**Last updated:** [May 13, 2022, 2:10pm UTC](https://discuss.elastic.co/t/error-when-accessing-security-module-on-elasticsearch-8-1-error-n-is-undefined/301278 "2022-05-13T14:10:07Z")

</div>

Greetings, When trying to access the Security module on Kibana for the Elasticsearch 8.1, I get the following error: Error Error: n is undefined c@http://127.0.0.1:5601/50609/bundles/plugin/securitySolution/8.0.0/sec…

---

## [Upgrade from version 7.17.3 to 8.1.3 can't get past xpack logging error in upgrade assistant](https://discuss.elastic.co/t/upgrade-from-version-7-17-3-to-8-1-3-cant-get-past-xpack-logging-error-in-upgrade-assistant/304616)

<div class="topic-metadata">

**Author:** [@Moxey](https://discuss.elastic.co/u/Moxey)\
**Replies:** 4\
**Last updated:** [May 13, 2022, 12:10pm UTC](https://discuss.elastic.co/t/upgrade-from-version-7-17-3-to-8-1-3-cant-get-past-xpack-logging-error-in-upgrade-assistant/304616 "2022-05-13T12:10:49Z")

</div>

Upgrade deployment Generally available versions 8.1.3 selected Error: Your changes cannot be applied Kibana - 'xpack.security.audit.appender.type' is not allowed Upgrade is greyed out. This is not a just a warning…

---

## [ELK Kibana Angular](https://discuss.elastic.co/t/elk-kibana-angular/304555)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 2\
**Last updated:** [May 13, 2022, 10:10am UTC](https://discuss.elastic.co/t/elk-kibana-angular/304555 "2022-05-13T10:10:30Z")

</div>

Hello I am a beginner in Elastic I want to ask if I can create an authentication interface with angular , so that an admin add users who can and interact with dashboards of kibana I mean can I integrate elk in a whole…

---

## [How does the kibana "search profiler" "Query Profile" timing work?](https://discuss.elastic.co/t/how-does-the-kibana-search-profiler-query-profile-timing-work/304600)

<div class="topic-metadata">

**Author:** [@stefan.tolksdorf](https://discuss.elastic.co/u/stefan.tolksdorf)\
**Replies:** 2\
**Last updated:** [May 13, 2022, 9:38am UTC](https://discuss.elastic.co/t/how-does-the-kibana-search-profiler-query-profile-timing-work/304600 "2022-05-13T09:38:42Z")

</div>

I use version 7.13.1 Query I profile { "query": { "bool": { "must": \[ { "match": { "title": "logstash" } } \], "must\_not": \[ { "m…

---

## [Error upgrade 8.2](https://discuss.elastic.co/t/error-upgrade-8-2/304594)

<div class="topic-metadata">

**Author:** [@jojodd](https://discuss.elastic.co/u/jojodd)\
**Replies:** 2\
**Last updated:** [May 13, 2022, 8:04am UTC](https://discuss.elastic.co/t/error-upgrade-8-2/304594 "2022-05-13T08:04:32Z")

</div>

How can I fix this error that occurs after installing the new version of kibana ? \[FATAL\]\[root\] Error: Unable to complete saved object migrations for the \[.kibana\] index: The Elasticsearch cluster has cluster routing al…

---

## [Is it possible to extract value of data within a field in Kibana?](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626)

<div class="topic-metadata">

**Author:** [@thiton](https://discuss.elastic.co/u/thiton)\
**Replies:** 1\
**Last updated:** [May 13, 2022, 7:47am UTC](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626 "2022-05-13T07:47:29Z")

</div>

Hi, I am trying to extract value of data with a field, but no luck. Please help. Many thanks in advance. For example, I run below script to get the data GET xx-prod-transaction-\*/\_search { "query": { "bool"…

---

## [Create Dashboards Dropdown](https://discuss.elastic.co/t/create-dashboards-dropdown/304574)

<div class="topic-metadata">

**Author:** [@dheeru11](https://discuss.elastic.co/u/dheeru11)\
**Replies:** 2\
**Last updated:** [May 13, 2022, 5:31am UTC](https://discuss.elastic.co/t/create-dashboards-dropdown/304574 "2022-05-13T05:31:04Z")

</div>

Hi I have around 10 dashboards already created. I want to have 1 single dashboard which has a dropdown option to select 1 dashboard name and display relevant dashboard data. How to design this ? Thanks, Dheeru

---

## [Change default timestamp field of Index](https://discuss.elastic.co/t/change-default-timestamp-field-of-index/304522)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 2\
**Last updated:** [May 13, 2022, 3:20am UTC](https://discuss.elastic.co/t/change-default-timestamp-field-of-index/304522 "2022-05-13T03:20:03Z")

</div>

I have an index pattern in kibana whose timestamp is in UTC, I want to change this default timestamp to another date field. Is there a way to achieve this?

---

## [Kibana not sorting by descending order](https://discuss.elastic.co/t/kibana-not-sorting-by-descending-order/304527)

<div class="topic-metadata">

**Author:** [@Jonas1](https://discuss.elastic.co/u/Jonas1)\
**Replies:** 3\
**Last updated:** [May 13, 2022, 1:18am UTC](https://discuss.elastic.co/t/kibana-not-sorting-by-descending-order/304527 "2022-05-13T01:18:02Z")

</div>

I clicked the arrow thats facing down but why is it not still in descending order? Please help

---

## [How to disable kibana 7.17.3 TLS version 1.1](https://discuss.elastic.co/t/how-to-disable-kibana-7-17-3-tls-version-1-1/304437)

<div class="topic-metadata">

**Author:** [@Oskars\_Apinis](https://discuss.elastic.co/u/Oskars_Apinis)\
**Replies:** 1\
**Last updated:** [May 12, 2022, 9:30pm UTC](https://discuss.elastic.co/t/how-to-disable-kibana-7-17-3-tls-version-1-1/304437 "2022-05-12T21:30:58Z")

</div>

Hello! How to disable Kibana 7.17.3 TLS 1.1 ? I tryed to use this kibana configuration option server.ssl.supportedProtocols : \["TLSv1.2"\] and this not working.

---

## [Custom logs alert](https://discuss.elastic.co/t/custom-logs-alert/304357)

<div class="topic-metadata">

**Author:** [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Replies:** 4\
**Last updated:** [May 12, 2022, 8:08pm UTC](https://discuss.elastic.co/t/custom-logs-alert/304357 "2022-05-12T20:08:56Z")

</div>

Hi, I want to create a rule in kibana that checks if there is a new ip address (like in the picture) in the log file and sends an alert to mail if there is a new one

---

## [How to add custom Kibana Plugin App as Visualization Plugin in a Dashboard](https://discuss.elastic.co/t/how-to-add-custom-kibana-plugin-app-as-visualization-plugin-in-a-dashboard/303993)

<div class="topic-metadata">

**Author:** [@kashifqazi](https://discuss.elastic.co/u/kashifqazi)\
**Replies:** 1\
**Last updated:** [May 12, 2022, 7:25pm UTC](https://discuss.elastic.co/t/how-to-add-custom-kibana-plugin-app-as-visualization-plugin-in-a-dashboard/303993 "2022-05-12T19:25:06Z")

</div>

Hi all, I developed a custom Kibana Plugin App. It's a React App which is visualizing data queried from an Elasticsearch index in its React components. It also has buttons in it, e.g. for filtering and updating data. N…

---

## [Snapshot of system indexes no longer working](https://discuss.elastic.co/t/snapshot-of-system-indexes-no-longer-working/304063)

<div class="topic-metadata">

**Author:** [@UweW](https://discuss.elastic.co/u/UweW)\
**Replies:** 4\
**Last updated:** [May 12, 2022, 4:20pm UTC](https://discuss.elastic.co/t/snapshot-of-system-indexes-no-longer-working/304063 "2022-05-12T16:20:44Z")

</div>

Hi, I have snapshot which saves the system files like .kibana\* . This is no longer working since one of the latest updates. In my case with a pattern of .kibana\* only .kibana-event\* are saved. Nothing else. I see th…

---

## [Unique metric count status not showing correctly due to duplication of serverid within timerange](https://discuss.elastic.co/t/unique-metric-count-status-not-showing-correctly-due-to-duplication-of-serverid-within-timerange/304604)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [May 12, 2022, 3:55pm UTC](https://discuss.elastic.co/t/unique-metric-count-status-not-showing-correctly-due-to-duplication-of-serverid-within-timerange/304604 "2022-05-12T15:55:32Z")

</div>

Hello All, I'm doing a use case where in I need to able to diaplay correct "unique count" of "idle" and "Active" session and server session count(IDLE+ACTIVE=Total Session).Here I'm unable to get unique count of "idle"…

---

## [This site is inaccsessible kibana](https://discuss.elastic.co/t/this-site-is-inaccsessible-kibana/303163)

<div class="topic-metadata">

**Author:** [@Abderraouf\_ZAYEN](https://discuss.elastic.co/u/Abderraouf_ZAYEN)\
**Replies:** 10\
**Last updated:** [May 12, 2022, 11:02am UTC](https://discuss.elastic.co/t/this-site-is-inaccsessible-kibana/303163 "2022-05-12T11:02:29Z")

</div>

Hi, systemctl status kibana & systemctl status Elasticsearch & systemctl status logstash & systemctl status filebeat all active (running) . my problem in browser localhost:9200 it works but localhost:5601 didn't work (…

---

## [AWS integration CloudWatch tags filter](https://discuss.elastic.co/t/aws-integration-cloudwatch-tags-filter/303724)

<div class="topic-metadata">

**Author:** [@kalbusse](https://discuss.elastic.co/u/kalbusse)\
**Replies:** 6\
**Last updated:** [May 12, 2022, 10:33am UTC](https://discuss.elastic.co/t/aws-integration-cloudwatch-tags-filter/303724 "2022-05-12T10:33:59Z")

</div>

Hello, I am trying to collect metrics from only a subset of resources with the AWS CloudWatch integration. I used the following configuration: - namespace: AWS/ApplicationELB tags: - key: "Application" val…

---

## [How to install sigma rule elk version 8](https://discuss.elastic.co/t/how-to-install-sigma-rule-elk-version-8/304237)

<div class="topic-metadata">

**Author:** [@CodeRed](https://discuss.elastic.co/u/CodeRed)\
**Replies:** 2\
**Last updated:** [May 12, 2022, 10:09am UTC](https://discuss.elastic.co/t/how-to-install-sigma-rule-elk-version-8/304237 "2022-05-12T10:09:56Z")

</div>

I am trying to install sigma rule on kibana I followed the instructions but it failed The document of sigma rule has instructions for me to execute the command: /usr/share/kibana/bin/./kibana-plugin install file:///PAT…

---

## [How to use our index name in data section in vega?](https://discuss.elastic.co/t/how-to-use-our-index-name-in-data-section-in-vega/304416)

<div class="topic-metadata">

**Author:** [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Replies:** 2\
**Last updated:** [May 12, 2022, 6:46am UTC](https://discuss.elastic.co/t/how-to-use-our-index-name-in-data-section-in-vega/304416 "2022-05-12T06:46:16Z")

</div>

I want to create tree layout graph in vega from my index which its name is 123. the index has many fields but I want only two fields of the index to be showed in the graph which is A and B. The question is how to use my…

---

## [Kibana 7.17 dashboard URL in iframe sid cookie getting rejected by browser](https://discuss.elastic.co/t/kibana-7-17-dashboard-url-in-iframe-sid-cookie-getting-rejected-by-browser/303523)

<div class="topic-metadata">

**Author:** [@homesh\_joshi](https://discuss.elastic.co/u/homesh_joshi)\
**Replies:** 9\
**Last updated:** [May 12, 2022, 6:16am UTC](https://discuss.elastic.co/t/kibana-7-17-dashboard-url-in-iframe-sid-cookie-getting-rejected-by-browser/303523 "2022-05-12T06:16:21Z")

</div>

Hi, I am trying to embed kibana dashboard in to another URL. My kibana URL is dashboard.example.com My other URL is reports.example.com (SSL enabled) My kibana is behind apache reverse proxy ( SSL is enabled only on…

---

## [Renewing Let's Encrypt Certification - Kibana](https://discuss.elastic.co/t/renewing-lets-encrypt-certification-kibana/304390)

<div class="topic-metadata">

**Author:** [@Hunter\_Goncalves](https://discuss.elastic.co/u/Hunter_Goncalves)\
**Replies:** 2\
**Last updated:** [May 12, 2022, 1:57am UTC](https://discuss.elastic.co/t/renewing-lets-encrypt-certification-kibana/304390 "2022-05-12T01:57:56Z")

</div>

I'm stumped on renewing these lets encrypt certifications for kibana. There seems to be a permissions error but i'm not sure where. Screenshots show error message and permissions for lets encrypt files and kibana ssl sym…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=213)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=215)
