# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=226

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 227

---

## [Why my snapshot produced many folders for only one snapshots?](https://discuss.elastic.co/t/why-my-snapshot-produced-many-folders-for-only-one-snapshots/300958)

<div class="topic-metadata">

**Author:** [@renatoa12](https://discuss.elastic.co/u/renatoa12)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 9:59pm UTC](https://discuss.elastic.co/t/why-my-snapshot-produced-many-folders-for-only-one-snapshots/300958 "2022-03-30T21:59:12Z")

</div>

Why my snapshot produced many folders for only one snapshots??

---

## [Unable to add Remote Cluster for Cross Cluster Replication](https://discuss.elastic.co/t/unable-to-add-remote-cluster-for-cross-cluster-replication/299299)

<div class="topic-metadata">

**Author:** [@Prabakar](https://discuss.elastic.co/u/Prabakar)\
**Replies:** 1\
**Last updated:** [March 30, 2022, 7:29pm UTC](https://discuss.elastic.co/t/unable-to-add-remote-cluster-for-cross-cluster-replication/299299 "2022-03-30T19:29:00Z")

</div>

Hello Team, We are using Elastic Enterprise edition license. We have created on-premise ECK (Kubenetes) clusters (2 clusters). We are trying to create remote cluster from Kibana(Cluster1) to test Cross Cluster Replicati…

---

## [Kibana stuck after upgrading to 7.17.1](https://discuss.elastic.co/t/kibana-stuck-after-upgrading-to-7-17-1/301139)

<div class="topic-metadata">

**Author:** [@danilopc](https://discuss.elastic.co/u/danilopc)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 7:22pm UTC](https://discuss.elastic.co/t/kibana-stuck-after-upgrading-to-7-17-1/301139 "2022-03-30T19:22:29Z")

</div>

Hi everyone I've upgraded my Elasticsearch cluster from 7.16.3 to 7.17.1. The process ran without problems and no errors occurred. When I upgraded the kibana from 7.16.3 to 7.17.1 it got stuck at initialization. The lo…

---

## [Changing the Font size or Font Color in Kibana widget Title](https://discuss.elastic.co/t/changing-the-font-size-or-font-color-in-kibana-widget-title/299417)

<div class="topic-metadata">

**Author:** [@Kirubanandhan](https://discuss.elastic.co/u/Kirubanandhan)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 4:36pm UTC](https://discuss.elastic.co/t/changing-the-font-size-or-font-color-in-kibana-widget-title/299417 "2022-03-30T16:36:10Z")

</div>

I need to update the Font styles (color, size, ..) in Kibana widgets. Please let me know the options to do that in Kibana UI.

---

## [ERROR: for kibana Container "ee1a9f613d4a" is unhealthy](https://discuss.elastic.co/t/error-for-kibana-container-ee1a9f613d4a-is-unhealthy/301081)

<div class="topic-metadata">

**Author:** [@Arraso26](https://discuss.elastic.co/u/Arraso26)\
**Replies:** 1\
**Last updated:** [March 30, 2022, 4:29pm UTC](https://discuss.elastic.co/t/error-for-kibana-container-ee1a9f613d4a-is-unhealthy/301081 "2022-03-30T16:29:03Z")

</div>

good, I was using the installation guide for elk 8.0.1 and everything was already configured when I went to start it and I got this error. WARNING: Found orphan containers (docker\_elasticsearch\_1, docker\_logstash\_1) for…

---

## [Drilldown Based on Query Results](https://discuss.elastic.co/t/drilldown-based-on-query-results/301122)

<div class="topic-metadata">

**Author:** [@DamiaRita](https://discuss.elastic.co/u/DamiaRita)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 4:16pm UTC](https://discuss.elastic.co/t/drilldown-based-on-query-results/301122 "2022-03-30T16:16:26Z")

</div>

Hi, I want to connect two dashboards via Drilldown (or a similar feature). I have been reading the docs regarding drilldown and did not find a way to do precisely what I want. So, I am hoping for someone with more exper…

---

## [Can i apply a KQL query that works on all indices present?](https://discuss.elastic.co/t/can-i-apply-a-kql-query-that-works-on-all-indices-present/301008)

<div class="topic-metadata">

**Author:** [@Matthew\_Dominic\_Ramp](https://discuss.elastic.co/u/Matthew_Dominic_Ramp)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 4:12pm UTC](https://discuss.elastic.co/t/can-i-apply-a-kql-query-that-works-on-all-indices-present/301008 "2022-03-30T16:12:58Z")

</div>

Scenario: I have a dashboard which displays info from two indices, a & b both a& b have a field (which acts as a primary key would in sql) called id i want to type into the search/query bar a filter that searches for d…

---

## [Copy dashboard](https://discuss.elastic.co/t/copy-dashboard/301111)

<div class="topic-metadata">

**Author:** [@Marjolein](https://discuss.elastic.co/u/Marjolein)\
**Replies:** 1\
**Last updated:** [March 30, 2022, 3:14pm UTC](https://discuss.elastic.co/t/copy-dashboard/301111 "2022-03-30T15:14:38Z")

</div>

Hi! I'm a very new user of Kibana and running into some issues. I have a dashboard from a colleague and I want to copy the dashboard and make some alterations while the dashboard of my colleague stays the same. I tried …

---

## [Grouping legend entries](https://discuss.elastic.co/t/grouping-legend-entries/301058)

<div class="topic-metadata">

**Author:** [@Marjolein](https://discuss.elastic.co/u/Marjolein)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 3:08pm UTC](https://discuss.elastic.co/t/grouping-legend-entries/301058 "2022-03-30T15:08:05Z")

</div>

Hi! I'm currently making my first Kibana dashboards and I'm running into an issue. I want to make a Pie chart of values with tags that look like this: Node1-1 Node1-2 Node1-3 Node2-1 Node2-2 Node2-3 etc I want t…

---

## [Can I use Vega Lite with multiple indexes?](https://discuss.elastic.co/t/can-i-use-vega-lite-with-multiple-indexes/300960)

<div class="topic-metadata">

**Author:** [@ivanhoe-dev](https://discuss.elastic.co/u/ivanhoe-dev)\
**Replies:** 1\
**Last updated:** [March 30, 2022, 11:13am UTC](https://discuss.elastic.co/t/can-i-use-vega-lite-with-multiple-indexes/300960 "2022-03-30T11:13:08Z")

</div>

I have a use case which data sources are from two separated indexes, is it possible to plot a single chart from two indexes by vega? Thanks

---

## [Updating the kibana.yml to increate max size of CSV export](https://discuss.elastic.co/t/updating-the-kibana-yml-to-increate-max-size-of-csv-export/300906)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 10:37am UTC](https://discuss.elastic.co/t/updating-the-kibana-yml-to-increate-max-size-of-csv-export/300906 "2022-03-30T10:37:32Z")

</div>

this might be a silly question, but if i am running the cloud instance of Kibana, where can i access the Kibana.yml from to adjust the limit on the max size when exporting to csv? the video tutorials show how to do it w…

---

## [Need to set alert which would trigger when API key expires in Elastic stack](https://discuss.elastic.co/t/need-to-set-alert-which-would-trigger-when-api-key-expires-in-elastic-stack/301073)

<div class="topic-metadata">

**Author:** [@sidharth\_vijayakumar](https://discuss.elastic.co/u/sidharth_vijayakumar)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 10:31am UTC](https://discuss.elastic.co/t/need-to-set-alert-which-would-trigger-when-api-key-expires-in-elastic-stack/301073 "2022-03-30T10:31:36Z")

</div>

Need to set an alert that would trigger 10days before my API key expiry. So in elastic stack am trying to use API key for authentication in the Kubernetes cluster. The API key needs to have an expiry of 1 year but when i…

---

## [Count status but only for last events](https://discuss.elastic.co/t/count-status-but-only-for-last-events/300104)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 10:24am UTC](https://discuss.elastic.co/t/count-status-but-only-for-last-events/300104 "2022-03-30T10:24:14Z")

</div>

Hello, I come here to ask you for help. Thank you in advance to those who will answer me :slight\_smile: I have a index with processing status by city. Status are : UP -\> DEGRADED -\> DOWN Here is an example of a collec…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/301065)

<div class="topic-metadata">

**Author:** [@Mayuresh\_More](https://discuss.elastic.co/u/Mayuresh_More)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 9:30am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/301065 "2022-03-30T09:30:41Z")

</div>

Hi, I have installed the latest version of all Elasticsearch & Kibana I am able to connect elastic URL but unable to see dashboard (PFA) and give the error "Kibana server is not ready yet." in the browser. 1:) How C…

---

## [Advanced Watcher - If Failed % is greater than some defined threshold value](https://discuss.elastic.co/t/advanced-watcher-if-failed-is-greater-than-some-defined-threshold-value/300727)

<div class="topic-metadata">

**Author:** [@Freddy.Raj](https://discuss.elastic.co/u/Freddy.Raj)\
**Replies:** 6\
**Last updated:** [March 30, 2022, 8:18am UTC](https://discuss.elastic.co/t/advanced-watcher-if-failed-is-greater-than-some-defined-threshold-value/300727 "2022-03-30T08:18:26Z")

</div>

Hi All, I need some help to achieve below monitoring condition to enable watcher alert. We have a domain named "XYZ" as a value to one of the term field - "main.domain" Under this domain "XYZ", we see logs for several…

---

## [Kibana drill down fields](https://discuss.elastic.co/t/kibana-drill-down-fields/300970)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 5\
**Last updated:** [March 30, 2022, 8:09am UTC](https://discuss.elastic.co/t/kibana-drill-down-fields/300970 "2022-03-30T08:09:11Z")

</div>

Hi, I have some logs like this: country = France, city = Paris, value = 6 country = France, city = Marseille, value = 2 country = Italy, city = Roma, value = 8 In a Kibana dashboards, I can display the countries and s…

---

## [Kibana Sharepoint Connector | ingest pipeline question](https://discuss.elastic.co/t/kibana-sharepoint-connector-ingest-pipeline-question/301046)

<div class="topic-metadata">

**Author:** [@msanz-acclaro](https://discuss.elastic.co/u/msanz-acclaro)\
**Replies:** 0\
**Last updated:** [March 30, 2022, 7:40am UTC](https://discuss.elastic.co/t/kibana-sharepoint-connector-ingest-pipeline-question/301046 "2022-03-30T07:40:28Z")

</div>

Hi everyone, I am implementing the ELK stack in our company, which so far has gone pretty well. I have a question regarding the Sharepoint connector, I read the doc but have not found (googling) anyone with a similar u…

---

## [How filter range date in CreateDate](https://discuss.elastic.co/t/how-filter-range-date-in-createdate/300844)

<div class="topic-metadata">

**Author:** [@Damas\_Mahardi](https://discuss.elastic.co/u/Damas_Mahardi)\
**Replies:** 3\
**Last updated:** [March 30, 2022, 6:48am UTC](https://discuss.elastic.co/t/how-filter-range-date-in-createdate/300844 "2022-03-30T06:48:06Z")

</div>

---

## [Possible to search multiple indices in one rule?](https://discuss.elastic.co/t/possible-to-search-multiple-indices-in-one-rule/301010)

<div class="topic-metadata">

**Author:** [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 9:59pm UTC](https://discuss.elastic.co/t/possible-to-search-multiple-indices-in-one-rule/301010 "2022-03-29T21:59:14Z")

</div>

Dear all =) When I read this it doesn't mention, if I just can add multiple indices in the index array, and the rule will search them all? Does anyone know this? Hugs Sandra =)

---

## [Plugin root dir issues](https://discuss.elastic.co/t/plugin-root-dir-issues/300990)

<div class="topic-metadata">

**Author:** [@WhatImIDoing](https://discuss.elastic.co/u/WhatImIDoing)\
**Replies:** 0\
**Last updated:** [March 29, 2022, 4:18pm UTC](https://discuss.elastic.co/t/plugin-root-dir-issues/300990 "2022-03-29T16:18:05Z")

</div>

I am developing a plugin for 8.1 and am having trouble setting up the tsconfig.json I am refencing an interface at /src/plugins/discover/public/application/doc\_views\_types and getting this error '/home/user/Desktop/kib…

---

## [Requests per second with Kibana Lens](https://discuss.elastic.co/t/requests-per-second-with-kibana-lens/300826)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 2\
**Last updated:** [March 29, 2022, 4:09pm UTC](https://discuss.elastic.co/t/requests-per-second-with-kibana-lens/300826 "2022-03-29T16:09:37Z")

</div>

Hello, How can we display a metric showing Requests per \[timeframe\] with a Metric Lens? In older Kibana versions this was possible: It's not a derivative, nor a counter\_rate but rather the average number of recor…

---

## [Kibana windows notifications possibility](https://discuss.elastic.co/t/kibana-windows-notifications-possibility/299957)

<div class="topic-metadata">

**Author:** [@John\_McAfee1](https://discuss.elastic.co/u/John_McAfee1)\
**Replies:** 2\
**Last updated:** [March 29, 2022, 3:19pm UTC](https://discuss.elastic.co/t/kibana-windows-notifications-possibility/299957 "2022-03-29T15:19:04Z")

</div>

Good Morning, I know that Kibana/Elasticsearch is capable for providing e-mails by using watches/alerts. But is it possible for Kibana to provide windows notification similar to Slack or other web based tools? Is there…

---

## [Using DNS processors in built in integration in Kibana](https://discuss.elastic.co/t/using-dns-processors-in-built-in-integration-in-kibana/300863)

<div class="topic-metadata">

**Author:** [@Tom\_Box](https://discuss.elastic.co/u/Tom_Box)\
**Replies:** 0\
**Last updated:** [March 28, 2022, 3:04pm UTC](https://discuss.elastic.co/t/using-dns-processors-in-built-in-integration-in-kibana/300863 "2022-03-28T15:04:11Z")

</div>

Hi, I have a built in integration application (for example: Office 365) which has an IP address field in the logs which i would like to reverse using a DNS lookup and i tried to achieve that using the DNS processor unde…

---

## [Pie chart on accumulated data](https://discuss.elastic.co/t/pie-chart-on-accumulated-data/300545)

<div class="topic-metadata">

**Author:** [@MarioRojas](https://discuss.elastic.co/u/MarioRojas)\
**Replies:** 3\
**Last updated:** [March 29, 2022, 1:25pm UTC](https://discuss.elastic.co/t/pie-chart-on-accumulated-data/300545 "2022-03-29T13:25:38Z")

</div>

Hi All, I'm very new to Kibana and I need to create a pie chart based on the sum of the values present in different logs, marginalized from a given term in yet another log... In Discover the data looks like this: W…

---

## [Kibana.yml map.regionmap](https://discuss.elastic.co/t/kibana-yml-map-regionmap/300935)

<div class="topic-metadata">

**Author:** [@rhsnfl1122](https://discuss.elastic.co/u/rhsnfl1122)\
**Replies:** 2\
**Last updated:** [March 29, 2022, 1:10pm UTC](https://discuss.elastic.co/t/kibana-yml-map-regionmap/300935 "2022-03-29T13:10:50Z")

</div>

I'm using Kibana version 8.1.0 In my kibana.yml, I append code as follow for use "configured GeoJSON menu" map.regionmap: layers: - name: "SEOUL ZIPCODE" url: "http://localhost/TL\_KODIS\_BAS\_11.geojson" …

---

## [Sum index size based on unique identifier](https://discuss.elastic.co/t/sum-index-size-based-on-unique-identifier/300581)

<div class="topic-metadata">

**Author:** [@phager](https://discuss.elastic.co/u/phager)\
**Replies:** 3\
**Last updated:** [March 29, 2022, 12:33pm UTC](https://discuss.elastic.co/t/sum-index-size-based-on-unique-identifier/300581 "2022-03-29T12:33:29Z")

</div>

I have data within Elasticsearch indexed by customer, i.e. index-custnumber-2022-w11, that I would like to sum index size per unique customer into a chart in Kibana. I can run curl -X GET "localhost:9200/\_cat/indices/ind…

---

## [Metricbeat SQL module date fields](https://discuss.elastic.co/t/metricbeat-sql-module-date-fields/297348)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 3\
**Last updated:** [March 29, 2022, 12:30pm UTC](https://discuss.elastic.co/t/metricbeat-sql-module-date-fields/297348 "2022-03-29T12:30:16Z")

</div>

I am ingesting some sql queries via the metricbeat sql module, including date/time fields. I would like to use these fields on a Lens graph, but cannot as they are ingested as a string format. Is there any way to get K…

---

## [Kibana behind apache reverse proxy](https://discuss.elastic.co/t/kibana-behind-apache-reverse-proxy/300454)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 3\
**Last updated:** [March 29, 2022, 9:37am UTC](https://discuss.elastic.co/t/kibana-behind-apache-reverse-proxy/300454 "2022-03-29T09:37:35Z")

</div>

Hi I'm trying to get kibana working behind and apache reverse proxy. I already have it working, but there's one issue (for which I already have a workaround) but I need to know if it's a configuration issue or a bug. The…

---

## [Combining Documents for test result comparison in Kibana](https://discuss.elastic.co/t/combining-documents-for-test-result-comparison-in-kibana/300829)

<div class="topic-metadata">

**Author:** [@JBufton](https://discuss.elastic.co/u/JBufton)\
**Replies:** 1\
**Last updated:** [March 29, 2022, 9:23am UTC](https://discuss.elastic.co/t/combining-documents-for-test-result-comparison-in-kibana/300829 "2022-03-29T09:23:48Z")

</div>

Hi, I'm new here so I apologise if this turns out to be a noob question. I have a large set of documents in elastic containing test result data including timestamps, runtimes, results, branch tests were ran on and test r…

---

## [Drawing a time based graph](https://discuss.elastic.co/t/drawing-a-time-based-graph/300382)

<div class="topic-metadata">

**Author:** [@George915](https://discuss.elastic.co/u/George915)\
**Replies:** 1\
**Last updated:** [March 29, 2022, 8:57am UTC](https://discuss.elastic.co/t/drawing-a-time-based-graph/300382 "2022-03-29T08:57:24Z")

</div>

Hi ELK community, newbie ELK user here. I have a time based document as shown below and I was able to insert it in my Elasticsearch. I set up the timestamps field as a date date type. Timestamps are epoch time. I want t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=225)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=227)
