# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=232

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 233

---

## [\[Filebeat System\] Syslog dashboard ECS](https://discuss.elastic.co/t/filebeat-system-syslog-dashboard-ecs/299065)

<div class="topic-metadata">

**Author:** [@Alphonse\_Kambo](https://discuss.elastic.co/u/Alphonse_Kambo)\
**Replies:** 4\
**Last updated:** [March 9, 2022, 10:47am UTC](https://discuss.elastic.co/t/filebeat-system-syslog-dashboard-ecs/299065 "2022-03-09T10:47:11Z")

</div>

Hello Everyone, on the Dashboard "Syslog dashboard ECS" there is the following Visualization: This Visualization is a Markdown: Can someone tell me where to find the path /dashboard/Filebeat-syslog-dashboard-ecs …

---

## [Authenticating issue when using iframe outside the kibana](https://discuss.elastic.co/t/authenticating-issue-when-using-iframe-outside-the-kibana/299196)

<div class="topic-metadata">

**Author:** [@Hashika\_Maduranga](https://discuss.elastic.co/u/Hashika_Maduranga)\
**Replies:** 3\
**Last updated:** [March 9, 2022, 10:29am UTC](https://discuss.elastic.co/t/authenticating-issue-when-using-iframe-outside-the-kibana/299196 "2022-03-09T10:29:13Z")

</div>

When I used Kibana visualization on my web page it was not working correctly. I just used Kibana configuration (kibana.yml) xpack.security.authc.providers: basic.basic1: order: 0 anonymous.anonymous1: order…

---

## [Can we have save query as a sub feature in Kibana](https://discuss.elastic.co/t/can-we-have-save-query-as-a-sub-feature-in-kibana/299061)

<div class="topic-metadata">

**Author:** [@Shashankdevaraj](https://discuss.elastic.co/u/Shashankdevaraj)\
**Replies:** 3\
**Last updated:** [March 9, 2022, 9:16am UTC](https://discuss.elastic.co/t/can-we-have-save-query-as-a-sub-feature-in-kibana/299061 "2022-03-09T09:16:24Z")

</div>

If we have a separate access/privilege in role for Kibana to save query it will be great. As without write access we can give this privilege to users.

---

## [Canvas showing couldn't update workpad errors](https://discuss.elastic.co/t/canvas-showing-couldnt-update-workpad-errors/299027)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 3\
**Last updated:** [March 9, 2022, 9:16am UTC](https://discuss.elastic.co/t/canvas-showing-couldnt-update-workpad-errors/299027 "2022-03-09T09:16:01Z")

</div>

Hi there! I'm new to Canvas and I'm trying to use the service on one of my instances where I'm running other services as well. And while I'm using Canvas I'm seeing some errors showing Couldn't update workpad / Intern…

---

## [Integration of kibana widgets in angular app](https://discuss.elastic.co/t/integration-of-kibana-widgets-in-angular-app/298929)

<div class="topic-metadata">

**Author:** [@frank3nst3in](https://discuss.elastic.co/u/frank3nst3in)\
**Replies:** 3\
**Last updated:** [March 9, 2022, 9:15am UTC](https://discuss.elastic.co/t/integration-of-kibana-widgets-in-angular-app/298929 "2022-03-09T09:15:03Z")

</div>

Hi Elastic Team, I have a working angular app, a nodejs backend and a privately hosted ELK instance. Currently, everything is going good with kibana dashboard. But, now I want to display widgets generated by the kiban…

---

## [Create kibana visualization & dashboard - templates ndjson](https://discuss.elastic.co/t/create-kibana-visualization-dashboard-templates-ndjson/298609)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 6\
**Last updated:** [March 9, 2022, 6:32am UTC](https://discuss.elastic.co/t/create-kibana-visualization-dashboard-templates-ndjson/298609 "2022-03-09T06:32:20Z")

</div>

Hi, Is there a tool/method to create a template(ndjson) for a dashboard & its visualizations; so that we can replicate the same structure with a different name for another index pattern. Thanks Chandrakanth

---

## [Scripted fields not working for nested value in Kibana 7.x](https://discuss.elastic.co/t/scripted-fields-not-working-for-nested-value-in-kibana-7-x/297647)

<div class="topic-metadata">

**Author:** [@frankfenomena](https://discuss.elastic.co/u/frankfenomena)\
**Replies:** 7\
**Last updated:** [March 9, 2022, 4:38am UTC](https://discuss.elastic.co/t/scripted-fields-not-working-for-nested-value-in-kibana-7-x/297647 "2022-03-09T04:38:50Z")

</div>

My scripted field works as intended in older version of kibana 5.x, but we use 7.x in a different environment and the same scripted field does not work. I've searched for what the syntax change would be in 7.x but could…

---

## [Why and how to use elastic charts?](https://discuss.elastic.co/t/why-and-how-to-use-elastic-charts/298836)

<div class="topic-metadata">

**Author:** [@frank3nst3in](https://discuss.elastic.co/u/frank3nst3in)\
**Replies:** 4\
**Last updated:** [March 9, 2022, 3:26am UTC](https://discuss.elastic.co/t/why-and-how-to-use-elastic-charts/298836 "2022-03-09T03:26:05Z")

</div>

I found the @elastic/charts library on official github profile of elastic. So, can I create visualizations (ones which are displayed in a kibana dashboard) by consuming Elasticsearch rest api and @elastic/charts ? If y…

---

## [Snapshot retention policy](https://discuss.elastic.co/t/snapshot-retention-policy/299059)

<div class="topic-metadata">

**Author:** [@Nicole\_Hirshler](https://discuss.elastic.co/u/Nicole_Hirshler)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 8:57am UTC](https://discuss.elastic.co/t/snapshot-retention-policy/299059 "2022-03-08T08:57:05Z")

</div>

I'm not sure I understand how snapshots are working. I see that all snapshots are taken without errors according to the policy I have defined, but I do not see that old snapshots are ever deleted. You can see in the att…

---

## [Two Kibana instance on one single Elasticsearch cluster pointing at different Indexes](https://discuss.elastic.co/t/two-kibana-instance-on-one-single-elasticsearch-cluster-pointing-at-different-indexes/299002)

<div class="topic-metadata">

**Author:** [@siemdude](https://discuss.elastic.co/u/siemdude)\
**Replies:** 3\
**Last updated:** [March 8, 2022, 10:11pm UTC](https://discuss.elastic.co/t/two-kibana-instance-on-one-single-elasticsearch-cluster-pointing-at-different-indexes/299002 "2022-03-08T22:11:09Z")

</div>

I am trying to create two Kibana on top of a single Elasticsearch cluster. I want to separate data at Kibana level instead of Spaces. Is it possible with Kibana Cloud? Which fields to configure to separate specific indic…

---

## [Running ELK on docker, Kibana says: Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/running-elk-on-docker-kibana-says-unable-to-retrieve-version-information-from-elasticsearch-nodes/298220)

<div class="topic-metadata">

**Author:** [@Rajesh\_Singh](https://discuss.elastic.co/u/Rajesh_Singh)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 6:05pm UTC](https://discuss.elastic.co/t/running-elk-on-docker-kibana-says-unable-to-retrieve-version-information-from-elasticsearch-nodes/298220 "2022-03-08T18:05:57Z")

</div>

I was referring to example given in the Elasticsearch documentation for starting elastic stack (elastic and kibana) on docker using docker compose. It gives example of docker compose version 2.2 file. So, I tried to conv…

---

## [Get Copy Post URL via API for automatic reports](https://discuss.elastic.co/t/get-copy-post-url-via-api-for-automatic-reports/299094)

<div class="topic-metadata">

**Author:** [@Agus\_Roca](https://discuss.elastic.co/u/Agus_Roca)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 1:37pm UTC](https://discuss.elastic.co/t/get-copy-post-url-via-api-for-automatic-reports/299094 "2022-03-08T13:37:20Z")

</div>

Hi, i've been checking the docs and also the forum and seems like the only way to automate the generation of pdf is to first manually copy the Post URL and then, yes we have APIs to call. But I was wondering if it is pos…

---

## [\[Kibana\] Some plugins show yellow state in 7.16.3](https://discuss.elastic.co/t/kibana-some-plugins-show-yellow-state-in-7-16-3/297623)

<div class="topic-metadata">

**Author:** [@PEB](https://discuss.elastic.co/u/PEB)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 4:36pm UTC](https://discuss.elastic.co/t/kibana-some-plugins-show-yellow-state-in-7-16-3/297623 "2022-03-08T16:36:02Z")

</div>

Similarly to https://discuss.elastic.co/t/kibana-state-become-yellow-after-upgrade-to-version-7-16-2 , we have yellow state for kibana with the same plugin list. I wonder if this is kind of a bug or is there something f…

---

## [Create Pie Chart](https://discuss.elastic.co/t/create-pie-chart/298887)

<div class="topic-metadata">

**Author:** [@cris](https://discuss.elastic.co/u/cris)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 12:30pm UTC](https://discuss.elastic.co/t/create-pie-chart/298887 "2022-03-08T12:30:34Z")

</div>

Hi Community! I want make a pie chart with some data but I don´t know how to do it. I have a doc that looks like: { Login: passed, Country: Spain, Logout: passed } I have diferent docs with diferent countries, lik…

---

## [Problem with metricbeat to monitor one cluster with security enabled and the other one without security enabled](https://discuss.elastic.co/t/problem-with-metricbeat-to-monitor-one-cluster-with-security-enabled-and-the-other-one-without-security-enabled/297903)

<div class="topic-metadata">

**Author:** [@AitorGomezSanz](https://discuss.elastic.co/u/AitorGomezSanz)\
**Replies:** 0\
**Last updated:** [February 22, 2022, 1:38pm UTC](https://discuss.elastic.co/t/problem-with-metricbeat-to-monitor-one-cluster-with-security-enabled-and-the-other-one-without-security-enabled/297903 "2022-02-22T13:38:35Z")

</div>

Hi, I have a problem, because I have two clusters, one of these clusters (cluster1) has xpack security enabled, and the other one doesn't have security enabled (cluster2). The problem is that I want to monitor cluster1 …

---

## [The aggregation series\_agg is not supported in entire\_time\_range mode](https://discuss.elastic.co/t/the-aggregation-series-agg-is-not-supported-in-entire-time-range-mode/298846)

<div class="topic-metadata">

**Author:** [@d71247](https://discuss.elastic.co/u/d71247)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 12:25pm UTC](https://discuss.elastic.co/t/the-aggregation-series-agg-is-not-supported-in-entire-time-range-mode/298846 "2022-03-08T12:25:29Z")

</div>

After upgrading our kibana instance from 7.4 to 7.16.3 , we saw errors in our Visualizes tsvb "The aggregation series\_agg is not supported in entire\_time\_range mode"

---

## [Hide "-" valued entries in predefined metricbeat dashboard](https://discuss.elastic.co/t/hide-valued-entries-in-predefined-metricbeat-dashboard/297524)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 12:13pm UTC](https://discuss.elastic.co/t/hide-valued-entries-in-predefined-metricbeat-dashboard/297524 "2022-03-08T12:13:31Z")

</div>

Hello, i just set up metricbeat with the predefined kibana dashboards. Is it possible to hide all entries with a "-" value, that are on top and look like they have 100%? I tried a filter on the field with 0% to 100…

---

## [Document table with duplicate records](https://discuss.elastic.co/t/document-table-with-duplicate-records/298066)

<div class="topic-metadata">

**Author:** [@rituzza](https://discuss.elastic.co/u/rituzza)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 11:18am UTC](https://discuss.elastic.co/t/document-table-with-duplicate-records/298066 "2022-03-08T11:18:22Z")

</div>

I have a problem: when importing a document table created on kibana v7.7.1 on a kibana v7.14.1, I have duplicate records that determine me wrong totals on the metrics. Opening the visualization in edit, as if I wanted to…

---

## [Need for syntax and semantix - GROK filter](https://discuss.elastic.co/t/need-for-syntax-and-semantix-grok-filter/298404)

<div class="topic-metadata">

**Author:** [@Clyton](https://discuss.elastic.co/u/Clyton)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 8:27am UTC](https://discuss.elastic.co/t/need-for-syntax-and-semantix-grok-filter/298404 "2022-03-08T08:27:32Z")

</div>

Hi All, I would like to grep the below numeric value before the keyword "DEBUG" from the message field and map it to a new field called OrderID. Kindly let us know the pattern we can apply in order to achieve this conte…

---

## [Convert a dashboard from 7.16 to 7.14](https://discuss.elastic.co/t/convert-a-dashboard-from-7-16-to-7-14/298946)

<div class="topic-metadata">

**Author:** [@khouloud1](https://discuss.elastic.co/u/khouloud1)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 8:05am UTC](https://discuss.elastic.co/t/convert-a-dashboard-from-7-16-to-7-14/298946 "2022-03-08T08:05:35Z")

</div>

Hello , i did import a dashboard 7.16 to my kibana 7.14 but it doesn't work because it isn't compatible. Can you help me please to convert this dashboard to be compatible with my EK 7.14 https://raw.githubusercon…

---

## [Some indices do not show datetime filter](https://discuss.elastic.co/t/some-indices-do-not-show-datetime-filter/299018)

<div class="topic-metadata">

**Author:** [@markand.bhatt](https://discuss.elastic.co/u/markand.bhatt)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 7:59am UTC](https://discuss.elastic.co/t/some-indices-do-not-show-datetime-filter/299018 "2022-03-08T07:59:21Z")

</div>

I wonder some of my indices show datetime filter in KQL kibana, some not. Could someone please guide me, any setting in kibana or elastic to show datetime filter?

---

## [Query for IP External IP Addresses Only](https://discuss.elastic.co/t/query-for-ip-external-ip-addresses-only/299024)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 7:55am UTC](https://discuss.elastic.co/t/query-for-ip-external-ip-addresses-only/299024 "2022-03-08T07:55:43Z")

</div>

Hi, I am trying to use a KQL query to search for non private (rfc1918) addresses. I am using the following query AND NOT destination.ip:10.0.0.0/8 OR NOT destination.ip:192.168.0.0/16 OR NOT destination.ip :172.16.0.0…

---

## [Filter Ratio in Maps](https://discuss.elastic.co/t/filter-ratio-in-maps/299004)

<div class="topic-metadata">

**Author:** [@sushmamagesh](https://discuss.elastic.co/u/sushmamagesh)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 7:46pm UTC](https://discuss.elastic.co/t/filter-ratio-in-maps/299004 "2022-03-07T19:46:13Z")

</div>

Is it possible to use filter ratio with a numerator/value in maps (similar to average) Something similar to Filter Ratio within Kibana TSVB.

---

## [Find all the saved objects for a given tag](https://discuss.elastic.co/t/find-all-the-saved-objects-for-a-given-tag/298486)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 6:47pm UTC](https://discuss.elastic.co/t/find-all-the-saved-objects-for-a-given-tag/298486 "2022-03-07T18:47:38Z")

</div>

Hello, I try to call a REST request to get all the saved objects tagged with a given tag FS. I'd like to call something like GET api/kibana/management/saved\_objects/\_find?type=dashboard&search\_fields=tag&search=FS It …

---

## [Compare two time periods for same timeseries](https://discuss.elastic.co/t/compare-two-time-periods-for-same-timeseries/297196)

<div class="topic-metadata">

**Author:** [@achint](https://discuss.elastic.co/u/achint)\
**Replies:** 2\
**Last updated:** [March 7, 2022, 5:50pm UTC](https://discuss.elastic.co/t/compare-two-time-periods-for-same-timeseries/297196 "2022-03-07T17:50:35Z")

</div>

Hi, I run performance tests on different time periods and i get the application response time in ELK. I want to compare these time intervals so that i can compare the response time for different build. Response time dat…

---

## [Metricbeat sql module fields query - change to date/time](https://discuss.elastic.co/t/metricbeat-sql-module-fields-query-change-to-date-time/296723)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 5:17pm UTC](https://discuss.elastic.co/t/metricbeat-sql-module-fields-query-change-to-date-time/296723 "2022-03-07T17:17:28Z")

</div>

When I ingest metricbeat sql module fields they are stored as a string. How can I change some of the date/time fields returned from the sql query from string to date/time to be used in Kibana?

---

## [Is it possible to filter by agent policy?](https://discuss.elastic.co/t/is-it-possible-to-filter-by-agent-policy/297392)

<div class="topic-metadata">

**Author:** [@Teckinfor](https://discuss.elastic.co/u/Teckinfor)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 5:12pm UTC](https://discuss.elastic.co/t/is-it-possible-to-filter-by-agent-policy/297392 "2022-03-07T17:12:56Z")

</div>

Hello, I would like to be able to monitor 2 infrastructures at the same time, I have created a space for each infrastructure as well as 2 agent policies linked to the agents of their own infrastructure. I was wondering…

---

## [Graph in Kibana is empty](https://discuss.elastic.co/t/graph-in-kibana-is-empty/298204)

<div class="topic-metadata">

**Author:** [@Soumanou\_Karimou](https://discuss.elastic.co/u/Soumanou_Karimou)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 4:20pm UTC](https://discuss.elastic.co/t/graph-in-kibana-is-empty/298204 "2022-03-07T16:20:54Z")

</div>

Hello, I've ingested two columns data in an elastic index. The values are related: spi,ip spi1,ip1 spi2,ip1 spi3,ip1 spi4,ip2 spi5,ip2 spi6,ip2 Nothing appears in the Kibana graph when choosing ip,sip as columns…

---

## [\[Vega\] Function setMapView not recognized anymore](https://discuss.elastic.co/t/vega-function-setmapview-not-recognized-anymore/296983)

<div class="topic-metadata">

**Author:** [@Kayak007](https://discuss.elastic.co/u/Kayak007)\
**Replies:** 5\
**Last updated:** [March 7, 2022, 9:01am UTC](https://discuss.elastic.co/t/vega-function-setmapview-not-recognized-anymore/296983 "2022-03-07T09:01:29Z")

</div>

Hi, Some time ago, when using 7.10.x, I used to use (...) the function setMapView in Vega visualizations in order to modify signals latitude, longitude and zoom simultaneously. I hadn't looked at these in quite some ti…

---

## [Alerts in kibana](https://discuss.elastic.co/t/alerts-in-kibana/298696)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 4\
**Last updated:** [March 7, 2022, 6:19am UTC](https://discuss.elastic.co/t/alerts-in-kibana/298696 "2022-03-07T06:19:14Z")

</div>

log \[10:06:16.242\] \[error\]\[alerting\]\[alerts\]\[plugins\]\[plugins\] Executing Alert "34af2110-24f6-11ec-8071-63a4b456f636" has resulted in Error: Unable to create alerts client because the Encrypted Saved Objects plugin is …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=231)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=233)
