# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=23

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 24

---

## [Error using time in Vega](https://discuss.elastic.co/t/error-using-time-in-vega/374169)

<div class="topic-metadata">

**Author:** [@MattiHatem](https://discuss.elastic.co/u/MattiHatem)\
**Replies:** 1\
**Last updated:** [February 14, 2025, 10:22am UTC](https://discuss.elastic.co/t/error-using-time-in-vega/374169 "2025-02-14T10:22:34Z")

</div>

When I use below I got the following error, and I am just trying to use the time range from the dashboard, anyone can help ? (EsError: failed to parse date field \[1738832413539\] with format \[strict\_date\_optional\_time\]: …

---

## [Alert based on a condition](https://discuss.elastic.co/t/alert-based-on-a-condition/374525)

<div class="topic-metadata">

**Author:** [@wmulobole1](https://discuss.elastic.co/u/wmulobole1)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 6:37pm UTC](https://discuss.elastic.co/t/alert-based-on-a-condition/374525 "2025-02-13T18:37:57Z")

</div>

Hello. I am trying to set up an alert on the Kibana UI. Its is an elasticsearch query alert where I am matching an error message string. However, I would like only documents with unique device IDS so I have an aggregati…

---

## [Aggregation over array](https://discuss.elastic.co/t/aggregation-over-array/374511)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 6\
**Last updated:** [February 13, 2025, 4:36pm UTC](https://discuss.elastic.co/t/aggregation-over-array/374511 "2025-02-13T16:36:32Z")

</div>

Hi, I have a document like this { "ip": \[ "192.168.1.1", "192.168.1.2" \] } Is it possible to make aggregation over value at zero position in the array? Something like this? { "aggs": { "my\_aggregati…

---

## [Still unable to install Kibana since "E: Repository 'https://artifacts.elastic.co/packages/8.x/apt stable InRelease' changed its 'Origin' value from 'Artifactory' to 'elastic'"](https://discuss.elastic.co/t/still-unable-to-install-kibana-since-e-repository-https-artifacts-elastic-co-packages-8-x-apt-stable-inrelease-changed-its-origin-value-from-artifactory-to-elastic/374520)

<div class="topic-metadata">

**Author:** [@n89n](https://discuss.elastic.co/u/n89n)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 4:14pm UTC](https://discuss.elastic.co/t/still-unable-to-install-kibana-since-e-repository-https-artifacts-elastic-co-packages-8-x-apt-stable-inrelease-changed-its-origin-value-from-artifactory-to-elastic/374520 "2025-02-13T16:14:21Z")

</div>

So I've been trying to install Kibana on Ubuntu: I imported the Elastic PGP key, installed the apt-transport-https package, Saved the repository definition to /etc/apt/sources.list.d/elastic-8.x.list and tried to install…

---

## [Visualization Help - Methods to Show Status](https://discuss.elastic.co/t/visualization-help-methods-to-show-status/366689)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [February 13, 2025, 2:29pm UTC](https://discuss.elastic.co/t/visualization-help-methods-to-show-status/366689 "2025-02-13T14:29:20Z")

</div>

Hello, I was wondering what others are doing to visualize status health? I know this depends on the data but was wondering what others are doing? For example these are what I can do:

---

## [Unable to visualize histogram data](https://discuss.elastic.co/t/unable-to-visualize-histogram-data/372300)

<div class="topic-metadata">

**Author:** [@Mudboyzh](https://discuss.elastic.co/u/Mudboyzh)\
**Replies:** 1\
**Last updated:** [February 13, 2025, 2:26pm UTC](https://discuss.elastic.co/t/unable-to-visualize-histogram-data/372300 "2025-02-13T14:26:13Z")

</div>

Hi guys, I tried to visualize the histogram data from Prometheus I checked a few topics or GitHub issues, kibana seems to support histogram data. My Elastic Stack version is 8.15.3. Here is the simplified data. # S…

---

## [Invalid Literal Value](https://discuss.elastic.co/t/invalid-literal-value/374502)

<div class="topic-metadata">

**Author:** [@furkanuznr](https://discuss.elastic.co/u/furkanuznr)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 12:35pm UTC](https://discuss.elastic.co/t/invalid-literal-value/374502 "2025-02-13T12:35:20Z")

</div>

Inventory \> hosts \> agent host I get this error directly when I enter this section: \[ { "code": "invalid\_union", "unionErrors": \[ { "issues": \[ { "received": null, "code": "invalid\_literal", "expected": "metrics", "pat…

---

## [Error in Entity Analytics](https://discuss.elastic.co/t/error-in-entity-analytics/374500)

<div class="topic-metadata">

**Author:** [@pcglr](https://discuss.elastic.co/u/pcglr)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 12:27pm UTC](https://discuss.elastic.co/t/error-in-entity-analytics/374500 "2025-02-13T12:27:52Z")

</div>

Hello, I get this error on the Entity Analytics screen. Could you please help me? I could not find a document about this on the web. "An error occurred during entity store resource initialization Failed to authenticat…

---

## [Role reporting user is showing deprecated](https://discuss.elastic.co/t/role-reporting-user-is-showing-deprecated/372830)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 4\
**Last updated:** [February 13, 2025, 10:05am UTC](https://discuss.elastic.co/t/role-reporting-user-is-showing-deprecated/372830 "2025-02-13T10:05:53Z")

</div>

Hi OS - 22.04 ES - 7.17.0 kibana - 7.17.23 we are working on one requirement for user management so one user it is require to use reporting\_user role for download CSV report. but this role is showing deprecated so w…

---

## [Journald integration timestamp field](https://discuss.elastic.co/t/journald-integration-timestamp-field/374477)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 7:39am UTC](https://discuss.elastic.co/t/journald-integration-timestamp-field/374477 "2025-02-13T07:39:00Z")

</div>

Currently I am getting errors like the following quite often: This cluster had issues returning data and results might be incomplete. error fetching \[journald.custom.syslog\_timestamp\]: Field \[journald.custom.syslog\_ti…

---

## [HOW TO PARSE OPTIONAL FIELDS ON LOGSTASH?](https://discuss.elastic.co/t/how-to-parse-optional-fields-on-logstash/374476)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 6:34am UTC](https://discuss.elastic.co/t/how-to-parse-optional-fields-on-logstash/374476 "2025-02-13T06:34:14Z")

</div>

Unable to parse optional fields in dhcp lease logs. Following is the sample of logs:- lease 1.1.1.1 { starts 4 2025/02/13 06:14:46; ends 6 2025/03/15 06:14:46; cltt 4 2025/02/13 06:14:46; binding state active; next bin…

---

## [Kibana cannot connect to the Elastic Package Registry](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry/374239)

<div class="topic-metadata">

**Author:** [@EkilErif](https://discuss.elastic.co/u/EkilErif)\
**Replies:** 1\
**Last updated:** [February 13, 2025, 2:15am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry/374239 "2025-02-13T02:15:05Z")

</div>

I am very new to ELK and after configuring x-pack security to true I am getting the message: Kibana cannot connect to the Elastic Package Registry When I searched this community I found the following post: Is this s…

---

## [File Upload - Kibana](https://discuss.elastic.co/t/file-upload-kibana/374459)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [February 12, 2025, 10:33pm UTC](https://discuss.elastic.co/t/file-upload-kibana/374459 "2025-02-12T22:33:23Z")

</div>

Hello, I was wondering if its possible to upload more than one file in the File Upload. For example., I added a file upload and did some custom parsing via ingest pipelines. Instead of trying to find a different way to…

---

## [How to configure Daily Average Sum Calculation in Lens? ](https://discuss.elastic.co/t/how-to-configure-daily-average-sum-calculation-in-lens/374387)

<div class="topic-metadata">

**Author:** [@Rafael\_Mendonca](https://discuss.elastic.co/u/Rafael_Mendonca)\
**Replies:** 2\
**Last updated:** [February 12, 2025, 4:41pm UTC](https://discuss.elastic.co/t/how-to-configure-daily-average-sum-calculation-in-lens/374387 "2025-02-12T16:41:53Z")

</div>

I have a "Data Table" visualization configured, where I sum the daily average of a specific value, as shown in the image below. Now, I'm trying to recreate this view in Lens, but I can't achieve the same calculation,…

---

## [Rank functions not showing](https://discuss.elastic.co/t/rank-functions-not-showing/374407)

<div class="topic-metadata">

**Author:** [@3isenHeiM](https://discuss.elastic.co/u/3isenHeiM)\
**Replies:** 3\
**Last updated:** [February 12, 2025, 1:13pm UTC](https://discuss.elastic.co/t/rank-functions-not-showing/374407 "2025-02-12T13:13:29Z")

</div>

Hi, Between 2 ELK instances of the same version (8.12.2), and the same data type (keyword), the ranking functions proposed are not the same. On the first one, I can ran the vertical axis of my bar graph percentage by A…

---

## [Rank customers by counter\_rate](https://discuss.elastic.co/t/rank-customers-by-counter-rate/374227)

<div class="topic-metadata">

**Author:** [@Annxii](https://discuss.elastic.co/u/Annxii)\
**Replies:** 1\
**Last updated:** [February 12, 2025, 11:36am UTC](https://discuss.elastic.co/t/rank-customers-by-counter-rate/374227 "2025-02-12T11:36:06Z")

</div>

Hi, I'm trying to make a tabular visualization of the top 10 customers measure on req/sec. I have a monotonically increasing counter with the customer as an attribute. My counter\_rate is working fine, my issue is that …

---

## [Visualize flattened fields in Kibana dashboard](https://discuss.elastic.co/t/visualize-flattened-fields-in-kibana-dashboard/368112)

<div class="topic-metadata">

**Author:** [@HermannSamimi](https://discuss.elastic.co/u/HermannSamimi)\
**Replies:** 3\
**Last updated:** [February 12, 2025, 8:35am UTC](https://discuss.elastic.co/t/visualize-flattened-fields-in-kibana-dashboard/368112 "2025-02-12T08:35:03Z")

</div>

Hello, I was wondering if there is a possibility to visualize flattened fields in a simple table in Lens.

---

## [Kibana Alerts to index is giving me a JSON with key/value instead of just the value](https://discuss.elastic.co/t/kibana-alerts-to-index-is-giving-me-a-json-with-key-value-instead-of-just-the-value/374385)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [February 11, 2025, 8:49pm UTC](https://discuss.elastic.co/t/kibana-alerts-to-index-is-giving-me-a-json-with-key-value-instead-of-just-the-value/374385 "2025-02-11T20:49:16Z")

</div>

Kibana version 8.17.0 Hi, I set up an index to store the alerts, Im using metric threshold and when I use the variable {{context.metric}} y get a JSON instead of just the value of the metric: {"condition0":"gcp.compute…

---

## [MetricBeat Elastic Stack on Kubernetes no Working](https://discuss.elastic.co/t/metricbeat-elastic-stack-on-kubernetes-no-working/374381)

<div class="topic-metadata">

**Author:** [@Bruno\_Macedo](https://discuss.elastic.co/u/Bruno_Macedo)\
**Replies:** 0\
**Last updated:** [February 11, 2025, 7:33pm UTC](https://discuss.elastic.co/t/metricbeat-elastic-stack-on-kubernetes-no-working/374381 "2025-02-11T19:33:05Z")

</div>

I'm trying to get metrics in my elastic running in kubernetes, but metrics doesn't seem to appear in Kibana, it shows that it doesn't have metric beat configured, but I see the sidecar: apiVersion: elasticsearch.k8s.ela…

---

## [Error running kibana 8.14 in AL 2023 ARM](https://discuss.elastic.co/t/error-running-kibana-8-14-in-al-2023-arm/374336)

<div class="topic-metadata">

**Author:** [@Tara\_John](https://discuss.elastic.co/u/Tara_John)\
**Replies:** 9\
**Last updated:** [February 11, 2025, 5:20pm UTC](https://discuss.elastic.co/t/error-running-kibana-8-14-in-al-2023-arm/374336 "2025-02-11T17:20:35Z")

</div>

Seeing an error during the install: /usr/share/kibana/bin/kibana-keystore: line 29: 374498 Illegal instruction (core dumped) NODE\_OPTIONS="$KBN\_NODE\_OPTS $NODE\_OPTIONS" NODE\_ENV=production "${NODE}" "${DIR}/src/cli\_…

---

## [Kibana - create field using painless (doc doesn't have a value for a field)](https://discuss.elastic.co/t/kibana-create-field-using-painless-doc-doesnt-have-a-value-for-a-field/374376)

<div class="topic-metadata">

**Author:** [@Pavel\_Duda](https://discuss.elastic.co/u/Pavel_Duda)\
**Replies:** 0\
**Last updated:** [February 11, 2025, 4:26pm UTC](https://discuss.elastic.co/t/kibana-create-field-using-painless-doc-doesnt-have-a-value-for-a-field/374376 "2025-02-11T16:26:02Z")

</div>

I'm trying to add field for the data view in Kibana UI and I'm (trying) using painless script to do that (set value). The document in the index has "start\_time" and "close\_time" fields (date format) and I'm trying to ca…

---

## [ESQL to compare data in two indexes based on a unique key](https://discuss.elastic.co/t/esql-to-compare-data-in-two-indexes-based-on-a-unique-key/369211)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [February 11, 2025, 2:38pm UTC](https://discuss.elastic.co/t/esql-to-compare-data-in-two-indexes-based-on-a-unique-key/369211 "2025-02-11T14:38:30Z")

</div>

Hi Team, I am having two indexes in elasticsearch/kibana and wanted to write a ESQL query which will fetch the documents based on a unique field where the documents are there in index1 but not in index2. Could you pleas…

---

## [Kibana metricbeat iis and postgres default dashboards](https://discuss.elastic.co/t/kibana-metricbeat-iis-and-postgres-default-dashboards/374180)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 1\
**Last updated:** [February 11, 2025, 7:46am UTC](https://discuss.elastic.co/t/kibana-metricbeat-iis-and-postgres-default-dashboards/374180 "2025-02-11T07:46:12Z")

</div>

Hi Teams! Please tell me where you can download default metricbeat dashboards for iis and postgres. Since I can't download them manually because they are in json format and I need ndjson. I would like to get as a result…

---

## [Run from source Elasticsearch and connect Kibana](https://discuss.elastic.co/t/run-from-source-elasticsearch-and-connect-kibana/374279)

<div class="topic-metadata">

**Author:** [@Egor\_Krylovich](https://discuss.elastic.co/u/Egor_Krylovich)\
**Replies:** 7\
**Last updated:** [February 10, 2025, 7:21pm UTC](https://discuss.elastic.co/t/run-from-source-elasticsearch-and-connect-kibana/374279 "2025-02-10T19:21:03Z")

</div>

Hello, I'm trying to setup environment for contribution into the project. I was able to run Elasticsearch from sources by running: ./gradlew run I verified that the server is up and running by: curl -u elastic:passwo…

---

## [How to Add a Filter Bar to a Data Table in Kibana?](https://discuss.elastic.co/t/how-to-add-a-filter-bar-to-a-data-table-in-kibana/374321)

<div class="topic-metadata">

**Author:** [@se101](https://discuss.elastic.co/u/se101)\
**Replies:** 0\
**Last updated:** [February 10, 2025, 3:26pm UTC](https://discuss.elastic.co/t/how-to-add-a-filter-bar-to-a-data-table-in-kibana/374321 "2025-02-10T15:26:57Z")

</div>

Hi, I'm using Kibana 8.15 and I want to add a filter bar specifically to a data table visualization within a dashboard. The goal is to allow users to input text and filter the data table rows without affecting other vis…

---

## [Hide Anonymous login from login page](https://discuss.elastic.co/t/hide-anonymous-login-from-login-page/374275)

<div class="topic-metadata">

**Author:** [@hamedov](https://discuss.elastic.co/u/hamedov)\
**Replies:** 1\
**Last updated:** [February 9, 2025, 3:22pm UTC](https://discuss.elastic.co/t/hide-anonymous-login-from-login-page/374275 "2025-02-09T15:22:58Z")

</div>

We have a scenario where we embed Kibana dashboards in our admin portal using saved object URL iframe embed. We use anonymous login provider in the url query to skip the login page. Is there a way to accomplish this wit…

---

## [Using Observability Alerts for Slack: Why am I unable to post both the context.value and the aggregation A value that's used to calculate context.value?](https://discuss.elastic.co/t/using-observability-alerts-for-slack-why-am-i-unable-to-post-both-the-context-value-and-the-aggregation-a-value-thats-used-to-calculate-context-value/374194)

<div class="topic-metadata">

**Author:** [@walk](https://discuss.elastic.co/u/walk)\
**Replies:** 2\
**Last updated:** [February 9, 2025, 2:10am UTC](https://discuss.elastic.co/t/using-observability-alerts-for-slack-why-am-i-unable-to-post-both-the-context-value-and-the-aggregation-a-value-thats-used-to-calculate-context-value/374194 "2025-02-09T02:10:19Z")

</div>

Hello, I've set up observability alerts with Elastic/Kibana, but have run into such a simple issue: When an alert triggers, it only shows the value that triggered the alert (e.g. the error rate above a certain threshold…

---

## [Fluid layout for Kibana panel?](https://discuss.elastic.co/t/fluid-layout-for-kibana-panel/374241)

<div class="topic-metadata">

**Author:** [@hardcodet](https://discuss.elastic.co/u/hardcodet)\
**Replies:** 1\
**Last updated:** [February 7, 2025, 8:42pm UTC](https://discuss.elastic.co/t/fluid-layout-for-kibana-panel/374241 "2025-02-07T20:42:01Z")

</div>

Hi all Beginner's question here :slight\_smile: I created a dashboard that's very similar to the discovery view: a chart on top, and then the results of the search below. When I set up the dashboard, I moved the panel …

---

## [Transforms - IP Ranges](https://discuss.elastic.co/t/transforms-ip-ranges/374237)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [February 7, 2025, 7:40pm UTC](https://discuss.elastic.co/t/transforms-ip-ranges/374237 "2025-02-07T19:40:00Z")

</div>

Hello I was attempting to use range aggregation with Transforms and noticed that it doesn't seem to allow IP address as an input: Is this a bug?

---

## [Not being able to receive the verification key to login to Kibana for ElasticSearch](https://discuss.elastic.co/t/not-being-able-to-receive-the-verification-key-to-login-to-kibana-for-elasticsearch/374091)

<div class="topic-metadata">

**Author:** [@remoteconn-7891](https://discuss.elastic.co/u/remoteconn-7891)\
**Replies:** 7\
**Last updated:** [February 5, 2025, 11:41pm UTC](https://discuss.elastic.co/t/not-being-able-to-receive-the-verification-key-to-login-to-kibana-for-elasticsearch/374091 "2025-02-05T23:41:35Z")

</div>

Hello guys, I'm relatively new to Elasticsearch and I'm trying to login to the Kibana dashboard, but on the login page, it's asking me to provide the verification code, which I'm not able to find. For some context, I'm …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=22)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=24)
