# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=221

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 222

---

## [Elastic Agent 8.1.1 fails updates to 8.1.3](https://discuss.elastic.co/t/elastic-agent-8-1-1-fails-updates-to-8-1-3/302850)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 4\
**Last updated:** [April 20, 2022, 9:10pm UTC](https://discuss.elastic.co/t/elastic-agent-8-1-1-fails-updates-to-8-1-3/302850 "2022-04-20T21:10:17Z")

</div>

Elastic agent fails to update from 8.1.1 to 8.1.3. On-prim elastic instance. Pulling from elastic directly for software downloads. Start upgrade by selecting agents in Fleet. Fleet policy consist of Endpoint only. Cl…

---

## [Create rule with data from multiple documents](https://discuss.elastic.co/t/create-rule-with-data-from-multiple-documents/302854)

<div class="topic-metadata">

**Author:** [@ChristianOelsner](https://discuss.elastic.co/u/ChristianOelsner)\
**Replies:** 0\
**Last updated:** [April 20, 2022, 8:28pm UTC](https://discuss.elastic.co/t/create-rule-with-data-from-multiple-documents/302854 "2022-04-20T20:28:21Z")

</div>

Hi forum, I am trying to setup an alert/rule with audit data from Confluent Cloud. When I invite a user into the organization the following among others are generated and visible in Kibana under discover. { "\_index"…

---

## [TSVB show missing buckets when doing term aggs](https://discuss.elastic.co/t/tsvb-show-missing-buckets-when-doing-term-aggs/302232)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 5:26pm UTC](https://discuss.elastic.co/t/tsvb-show-missing-buckets-when-doing-term-aggs/302232 "2022-04-20T17:26:10Z")

</div>

Hello, Is there any option, in TSVB, to show missing buckets when doing term aggs ?

---

## [Counting the SEARCH term/phrase in a specific field](https://discuss.elastic.co/t/counting-the-search-term-phrase-in-a-specific-field/302107)

<div class="topic-metadata">

**Author:** [@Navanit\_dubey](https://discuss.elastic.co/u/Navanit_dubey)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 5:19pm UTC](https://discuss.elastic.co/t/counting-the-search-term-phrase-in-a-specific-field/302107 "2022-04-20T17:19:49Z")

</div>

Hi, I have this type of data { "name\_id": 2145 "address": "Antartica" "characteristics" : "He is a very nice person with very nice personality. the nicest thing about him is his nice dog" } now I am running this qu…

---

## [Reports Visualizing with Kibana](https://discuss.elastic.co/t/reports-visualizing-with-kibana/302231)

<div class="topic-metadata">

**Author:** [@bhaskar53777](https://discuss.elastic.co/u/bhaskar53777)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 5:15pm UTC](https://discuss.elastic.co/t/reports-visualizing-with-kibana/302231 "2022-04-20T17:15:19Z")

</div>

Dear Team, We have 15 reports producing from various tools in Excel /CSV format. How to configure/send these reports every 15 days automatically to Kibana for visualizing/dashboard? What could be the process/Steps? Reg…

---

## [Unable to view elastic-agent(Zeek) & (windows) logs in Fleet](https://discuss.elastic.co/t/unable-to-view-elastic-agent-zeek-windows-logs-in-fleet/302574)

<div class="topic-metadata">

**Author:** [@Mayuresh\_More](https://discuss.elastic.co/u/Mayuresh_More)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 4:49pm UTC](https://discuss.elastic.co/t/unable-to-view-elastic-agent-zeek-windows-logs-in-fleet/302574 "2022-04-20T16:49:24Z")

</div>

Hello all, I have successfully configured the Fleet-server A fleet of ELK(Fleet-server), Linux(Zeek-elastic agent), Windows (-elastic-agent) however unable to view logs of elastic-agent in Fleet \> Agents \> osboxes & F…

---

## [Optimize / combine number of watcher](https://discuss.elastic.co/t/optimize-combine-number-of-watcher/302670)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 4:22pm UTC](https://discuss.elastic.co/t/optimize-combine-number-of-watcher/302670 "2022-04-20T16:22:34Z")

</div>

Hello all, We have created lots of alerts in our cluster and we are unbale to manage those alerts. Requirement: We need to 2 or more than 2 watcher in one watch. Like: for index Metrickbeat-\* we have 3 alerts for if: …

---

## [Cross Cluster Indices on in Index Management tab](https://discuss.elastic.co/t/cross-cluster-indices-on-in-index-management-tab/302768)

<div class="topic-metadata">

**Author:** [@subham](https://discuss.elastic.co/u/subham)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 3:43pm UTC](https://discuss.elastic.co/t/cross-cluster-indices-on-in-index-management-tab/302768 "2022-04-20T15:43:55Z")

</div>

Hi, I am not able to find my indices from remote cluster in Index Management tab. However, I am able to create index patterns using pattern cluster-name:index-name. Can someone tell if it's possible to search remote clu…

---

## [Access Management to Kibana production](https://discuss.elastic.co/t/access-management-to-kibana-production/302794)

<div class="topic-metadata">

**Author:** [@CP-AssafM](https://discuss.elastic.co/u/CP-AssafM)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 3:24pm UTC](https://discuss.elastic.co/t/access-management-to-kibana-production/302794 "2022-04-20T15:24:41Z")

</div>

Hi All, How do you manage your user's access to Kibana in production? I want to provide access to a user to specific customer logs (and not all the customer's logs), We have thousands of customers logs in the same ind…

---

## [Top Hit / last value metrics aggregation doesn't work on Runtime fields](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924)

<div class="topic-metadata">

**Author:** [@BitBucketUser\_user](https://discuss.elastic.co/u/BitBucketUser_user)\
**Replies:** 7\
**Last updated:** [April 20, 2022, 5:28am UTC](https://discuss.elastic.co/t/top-hit-last-value-metrics-aggregation-doesnt-work-on-runtime-fields/301924 "2022-04-20T05:28:03Z")

</div>

Hello All, I use Kibana version 7.15.2. I'm not able to perform TopHits or last value metrics aggregation on runtime fields. I just see blanks or dashes '-' when I do so. Here is an example: On the kibana\_sample\_data…

---

## [Security error in kibana container](https://discuss.elastic.co/t/security-error-in-kibana-container/302728)

<div class="topic-metadata">

**Author:** [@jrcartmell](https://discuss.elastic.co/u/jrcartmell)\
**Replies:** 1\
**Last updated:** [April 19, 2022, 6:21pm UTC](https://discuss.elastic.co/t/security-error-in-kibana-container/302728 "2022-04-19T18:21:25Z")

</div>

Below is an error I am getting in my kibana container. And at the bottom is my yaml config file. I am trying to run 3 instances of ES and 1 Kibana with security enabled. Error: {"type":"log","@timestamp":"2022-04-19T…

---

## [Kibana server is not ready yet RHEL 8](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-rhel-8/301455)

<div class="topic-metadata">

**Author:** [@ashisharyan](https://discuss.elastic.co/u/ashisharyan)\
**Replies:** 7\
**Last updated:** [April 19, 2022, 5:19pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-rhel-8/301455 "2022-04-19T17:19:33Z")

</div>

Hi , I am installing ELK stack (elasticsearch-7.10.2)on RHEL8 Elasticsearch and Kibana both installed Successfully but when we open Kibana web console it is showing kibana server is not ready yet. Below is Yml files. …

---

## [Warning and Error Messages - Kibana Dashboard](https://discuss.elastic.co/t/warning-and-error-messages-kibana-dashboard/301397)

<div class="topic-metadata">

**Author:** [@TS-021](https://discuss.elastic.co/u/TS-021)\
**Replies:** 2\
**Last updated:** [April 19, 2022, 3:40pm UTC](https://discuss.elastic.co/t/warning-and-error-messages-kibana-dashboard/301397 "2022-04-19T15:40:55Z")

</div>

Hi, I am running T-Pot via AWS and included with T-Pot is Kibana. Every time I launch the Kibana dashboard I get the following messages - Message 1: Configuration missing server.publicBaseUrl is missing and should b…

---

## [Filtering duplicate fields in Error Watchers](https://discuss.elastic.co/t/filtering-duplicate-fields-in-error-watchers/302710)

<div class="topic-metadata">

**Author:** [@HughEvans](https://discuss.elastic.co/u/HughEvans)\
**Replies:** 0\
**Last updated:** [April 19, 2022, 11:10am UTC](https://discuss.elastic.co/t/filtering-duplicate-fields-in-error-watchers/302710 "2022-04-19T11:10:35Z")

</div>

I'm trying to filter out duplicates hits in the following error watcher. Currently when there are multiple hits in the same namespace the output looks like this: "body": "{\\"link\_names\\": \\"1\\", \\"username\\": \\"Kibana …

---

## [Can't get Filebeat and Metricbeat DashBoard Setup](https://discuss.elastic.co/t/cant-get-filebeat-and-metricbeat-dashboard-setup/302655)

<div class="topic-metadata">

**Author:** [@asher-lab](https://discuss.elastic.co/u/asher-lab)\
**Replies:** 1\
**Last updated:** [April 19, 2022, 12:54am UTC](https://discuss.elastic.co/t/cant-get-filebeat-and-metricbeat-dashboard-setup/302655 "2022-04-19T00:54:30Z")

</div>

Hi, I have a problem setting up the dashboards for metricbeat and filebeat on my Kibana dashboard. I am using the OSS Version of ELK, MetricBeat and Filebeat 7.10.2 Here are the specs of my ELK Stack, MetricBeat and F…

---

## [400 The plain HTTP request was sent to HTTPS port](https://discuss.elastic.co/t/400-the-plain-http-request-was-sent-to-https-port/302284)

<div class="topic-metadata">

**Author:** [@safarial.fatemeh](https://discuss.elastic.co/u/safarial.fatemeh)\
**Replies:** 3\
**Last updated:** [April 18, 2022, 6:23pm UTC](https://discuss.elastic.co/t/400-the-plain-http-request-was-sent-to-https-port/302284 "2022-04-18T18:23:46Z")

</div>

Hi, I'm using python client only (have not installed Elasticsearch on my machine) and I'm trying to query kibana and I get following error message: Elasticsearch.exceptions.RequestError: RequestError(400, '\\r\\n400 The p…

---

## [Displaying a signal element in Vega visualization within a Kibana dashboard](https://discuss.elastic.co/t/displaying-a-signal-element-in-vega-visualization-within-a-kibana-dashboard/302562)

<div class="topic-metadata">

**Author:** [@mbsnider](https://discuss.elastic.co/u/mbsnider)\
**Replies:** 5\
**Last updated:** [April 18, 2022, 1:11pm UTC](https://discuss.elastic.co/t/displaying-a-signal-element-in-vega-visualization-within-a-kibana-dashboard/302562 "2022-04-18T13:11:13Z")

</div>

I'm building my own visualizations in Vega, and I am adding signals to my Vega code using the "bind" option to have a "range" or "select" object that the user of my Kibana dashboard can use to customize the visualization…

---

## [One standalone node formed in monitoring cluster](https://discuss.elastic.co/t/one-standalone-node-formed-in-monitoring-cluster/302422)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [April 18, 2022, 6:22am UTC](https://discuss.elastic.co/t/one-standalone-node-formed-in-monitoring-cluster/302422 "2022-04-18T06:22:00Z")

</div>

Hello team, One standalone cluster formed when we upgraded from 7.2 to 7.16.3 in moniotring cluster. Does any one have any idea how to remove this

---

## [Using token to enrol kibana without a local browser](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 6\
**Last updated:** [April 17, 2022, 6:53am UTC](https://discuss.elastic.co/t/using-token-to-enrol-kibana-without-a-local-browser/302426 "2022-04-17T06:53:02Z")

</div>

Hi, I have two virtual machines, one running Elasticsearch, one running kibana. I have generated a token to enrol kibana, but have been unable to apply it. I start kibana and can see the link generated to apply the to…

---

## [Handle big numbers in elasticsearch](https://discuss.elastic.co/t/handle-big-numbers-in-elasticsearch/302535)

<div class="topic-metadata">

**Author:** [@max4b](https://discuss.elastic.co/u/max4b)\
**Replies:** 4\
**Last updated:** [April 17, 2022, 6:34am UTC](https://discuss.elastic.co/t/handle-big-numbers-in-elasticsearch/302535 "2022-04-17T06:34:31Z")

</div>

Hi, I need to store big ints that can have more than 20 numbers. I tried with long and double in the mappings for my numeric fields, but none of them work. I can't put them in text fields either, because that doesn't al…

---

## [Kibana Maps features not displaying (failed net::ERR\_CONTENT\_DECODING\_FAILED)](https://discuss.elastic.co/t/kibana-maps-features-not-displaying-failed-net-err-content-decoding-failed/302424)

<div class="topic-metadata">

**Author:** [@quentin.renoux](https://discuss.elastic.co/u/quentin.renoux)\
**Replies:** 7\
**Last updated:** [April 15, 2022, 6:38pm UTC](https://discuss.elastic.co/t/kibana-maps-features-not-displaying-failed-net-err-content-decoding-failed/302424 "2022-04-15T18:38:06Z")

</div>

Hi, All layers on my Kibana maps are reporting No result found. with the minusInCircle icon from EUI (Elastic UI Framework | Elastic UI Framework). When I use the term "features", it is in reference of the Elastic Guid…

---

## [Monitor logs and create alert](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495)

<div class="topic-metadata">

**Author:** [@bdaniel7](https://discuss.elastic.co/u/bdaniel7)\
**Replies:** 1\
**Last updated:** [April 15, 2022, 10:04am UTC](https://discuss.elastic.co/t/monitor-logs-and-create-alert/302495 "2022-04-15T10:04:52Z")

</div>

Hi, Is there a way to monitor incoming logs (from fluent-bit, in my case) and trigger an alert when specific keywords appear in logs? I'm just beginning to use the ELK stack, so forgive me if I say silly things.

---

## [Facing error - Creation from saved object not supported by type dashboard](https://discuss.elastic.co/t/facing-error-creation-from-saved-object-not-supported-by-type-dashboard/300302)

<div class="topic-metadata">

**Author:** [@Shreeya\_Rajguru](https://discuss.elastic.co/u/Shreeya_Rajguru)\
**Replies:** 7\
**Last updated:** [April 15, 2022, 5:26am UTC](https://discuss.elastic.co/t/facing-error-creation-from-saved-object-not-supported-by-type-dashboard/300302 "2022-04-15T05:26:02Z")

</div>

Hi, I am trying to embed an existing dashboard in a custom plugin using its id as savedObjectID. I have referred the example plugin dashboard\_embeddable\_examples for the same. But I am facing the error - Creation from …

---

## [Kibana asking for Enrollment Token when xpack.security.enabled: false in Elasticsearch](https://discuss.elastic.co/t/kibana-asking-for-enrollment-token-when-xpack-security-enabled-false-in-elasticsearch/302118)

<div class="topic-metadata">

**Author:** [@AdmiralGT](https://discuss.elastic.co/u/AdmiralGT)\
**Replies:** 1\
**Last updated:** [April 15, 2022, 4:12am UTC](https://discuss.elastic.co/t/kibana-asking-for-enrollment-token-when-xpack-security-enabled-false-in-elasticsearch/302118 "2022-04-15T04:12:13Z")

</div>

I have Kibana and Elasticsearch running in a kubernetes cluster, both v8.1.2 In my Elasticsearch.yml I have xpack.security.enabled: false This is confirmed by trying to create the enrollment token in Elasticsearch …

---

## [Rules and Connector is not sending ot email;](https://discuss.elastic.co/t/rules-and-connector-is-not-sending-ot-email/301223)

<div class="topic-metadata">

**Author:** [@Amisha\_Thakkar1](https://discuss.elastic.co/u/Amisha_Thakkar1)\
**Replies:** 12\
**Last updated:** [April 14, 2022, 7:48pm UTC](https://discuss.elastic.co/t/rules-and-connector-is-not-sending-ot-email/301223 "2022-04-14T19:48:52Z")

</div>

Hi Team I have setup rule under rules and connectors. I am trying to send out an email to my gmail. But its not working. But if i use watcher to send out an email. I am receiving emails.

---

## [Array in Scripted Field](https://discuss.elastic.co/t/array-in-scripted-field/302278)

<div class="topic-metadata">

**Author:** [@Alejandra\_Mata1](https://discuss.elastic.co/u/Alejandra_Mata1)\
**Replies:** 1\
**Last updated:** [April 14, 2022, 7:20pm UTC](https://discuss.elastic.co/t/array-in-scripted-field/302278 "2022-04-14T19:20:17Z")

</div>

Hi @LeeDr I saw a publication, the cula you explained how to work with array in a scripted field, I had a question, if I want to pivot in a table, an array so that in each cell a value of the array is assigned, how woul…

---

## [Kibana server is not ready yet, unavailable\_shards\_exception](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-unavailable-shards-exception/302459)

<div class="topic-metadata">

**Author:** [@Dave\_G](https://discuss.elastic.co/u/Dave_G)\
**Replies:** 1\
**Last updated:** [April 14, 2022, 5:24pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-unavailable-shards-exception/302459 "2022-04-14T17:24:58Z")

</div>

We have a four-node Elasticsearch cluster running ES 7.16.2 and Kibana 7.16.2. Since the last upgrade, our Kibana page is showing Kibana server is not ready yet The Kibana log shows this error repeated numerous times: …

---

## [Fleet-server failed: context canceled](https://discuss.elastic.co/t/fleet-server-failed-context-canceled/302348)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 2\
**Last updated:** [April 14, 2022, 3:00pm UTC](https://discuss.elastic.co/t/fleet-server-failed-context-canceled/302348 "2022-04-14T15:00:01Z")

</div>

Hi Having trouble enrolling fleet server Elasticsearch kibana and elastic agent versions 7.17.2 command I used is .\\elastic-agent.exe install --url=https://fleet server ip:8220 --fleet-server-es=https://elasticsearch…

---

## [How to export Kibana search query results to CSV file with more than one million records](https://discuss.elastic.co/t/how-to-export-kibana-search-query-results-to-csv-file-with-more-than-one-million-records/301412)

<div class="topic-metadata">

**Author:** [@fymaterials](https://discuss.elastic.co/u/fymaterials)\
**Replies:** 3\
**Last updated:** [April 14, 2022, 7:39am UTC](https://discuss.elastic.co/t/how-to-export-kibana-search-query-results-to-csv-file-with-more-than-one-million-records/301412 "2022-04-14T07:39:27Z")

</div>

I used Kibana to query the index, and use export under resource tab to export query results. How can I export query results if there are million records?

---

## [Display data from external REST API in Kibana](https://discuss.elastic.co/t/display-data-from-external-rest-api-in-kibana/301317)

<div class="topic-metadata">

**Author:** [@SuprithaAradhya](https://discuss.elastic.co/u/SuprithaAradhya)\
**Replies:** 2\
**Last updated:** [April 14, 2022, 6:06am UTC](https://discuss.elastic.co/t/display-data-from-external-rest-api-in-kibana/301317 "2022-04-14T06:06:32Z")

</div>

I want to display some data in Kibana but this data is not present in Elasticsearch or Kibana. I want to read this data from an external REST API, i would be happy if I can do this inside Kibana page or can I add a new p…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=220)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=222)
