# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=24

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 25

---

## [Disable errors screenshotting in canvas](https://discuss.elastic.co/t/disable-errors-screenshotting-in-canvas/371763)

<div class="topic-metadata">

**Author:** [@Taras\_Mikityuk](https://discuss.elastic.co/u/Taras_Mikityuk)\
**Replies:** 1\
**Last updated:** [February 5, 2025, 6:02pm UTC](https://discuss.elastic.co/t/disable-errors-screenshotting-in-canvas/371763 "2025-02-05T18:02:18Z")

</div>

When there is an issue while generating pdf report from canvas, Elasticsearch will put screenshot of an error in pdf report, here is example i want to disable this feature but cant find how to do it, is it even possi…

---

## [Timestamp sorting in a search, is not sorting on milliseconds](https://discuss.elastic.co/t/timestamp-sorting-in-a-search-is-not-sorting-on-milliseconds/373842)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 1\
**Last updated:** [February 4, 2025, 10:12pm UTC](https://discuss.elastic.co/t/timestamp-sorting-in-a-search-is-not-sorting-on-milliseconds/373842 "2025-02-04T22:12:18Z")

</div>

Hi We have a search, which is sorted default by @timestamp. But is it not sorted correctly, on the milliseconds level. Here are the lines from the search. Jan 29, 2025 @ 16:34:36.040 dokument-lager-service-spring ERROR…

---

## [How to smoothly replace deprecated reporting\_user by Kibana Feature privileges?](https://discuss.elastic.co/t/how-to-smoothly-replace-deprecated-reporting-user-by-kibana-feature-privileges/373780)

<div class="topic-metadata">

**Author:** [@bianca\_s](https://discuss.elastic.co/u/bianca_s)\
**Replies:** 1\
**Last updated:** [February 4, 2025, 3:41pm UTC](https://discuss.elastic.co/t/how-to-smoothly-replace-deprecated-reporting-user-by-kibana-feature-privileges/373780 "2025-02-04T15:41:09Z")

</div>

Hi all, we want to get rid of the deprecated reporting\_user and wonder how to do that smoothly. We have already found out that as a replacement one can use Kibana Feature Privileges which are available in the UI when s…

---

## [How to change the policy of an existing datastream](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 4\
**Last updated:** [February 4, 2025, 3:21pm UTC](https://discuss.elastic.co/t/how-to-change-the-policy-of-an-existing-datastream/373811 "2025-02-04T15:21:55Z")

</div>

Hey all, so current situation is that we set up logging for openshift into elastic, and it has taken the standard Logs index lifecycle policy, However this has a silly retention period, and i need to change this. I hav…

---

## [All fields have the status "unknown field"](https://discuss.elastic.co/t/all-fields-have-the-status-unknown-field/371760)

<div class="topic-metadata">

**Author:** [@atbc](https://discuss.elastic.co/u/atbc)\
**Replies:** 17\
**Last updated:** [February 4, 2025, 3:17pm UTC](https://discuss.elastic.co/t/all-fields-have-the-status-unknown-field/371760 "2025-02-04T15:17:40Z")

</div>

Hello, We have a problem, all fields have the status "unknown field" on our Kibana, wich breaks most of our searches.. Do you know how to solve this ? Regards,

---

## [If math get unknown error](https://discuss.elastic.co/t/if-math-get-unknown-error/373851)

<div class="topic-metadata">

**Author:** [@MattiHatem](https://discuss.elastic.co/u/MattiHatem)\
**Replies:** 1\
**Last updated:** [February 4, 2025, 2:38pm UTC](https://discuss.elastic.co/t/if-math-get-unknown-error/373851 "2025-02-04T14:38:53Z")

</div>

Hi, when I try to pass the blow I got this error Expression failed with the message: \[if\] \> \[math\] \> Unknown variable: count filters | essql query="SELECT COUNT(\*) as count FROM \\"reservation-event\*\\" WHERE message…

---

## [Monitoring a Dataview (Watcher vs. Rule)](https://discuss.elastic.co/t/monitoring-a-dataview-watcher-vs-rule/374058)

<div class="topic-metadata">

**Author:** [@MGBSLC](https://discuss.elastic.co/u/MGBSLC)\
**Replies:** 0\
**Last updated:** [February 4, 2025, 10:19am UTC](https://discuss.elastic.co/t/monitoring-a-dataview-watcher-vs-rule/374058 "2025-02-04T10:19:44Z")

</div>

Hi Community We would like to monitor a dataview and generate an alert, if there is no data sent to it. we saw that there are several options to create monitors. we focused on "watcher" or "rule". but what is exactely …

---

## [Elasticsearch:9200 rest api tunneled through kibana:5601](https://discuss.elastic.co/t/elasticsearch-9200-rest-api-tunneled-through-kibana-5601/371587)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 2\
**Last updated:** [February 4, 2025, 10:07am UTC](https://discuss.elastic.co/t/elasticsearch-9200-rest-api-tunneled-through-kibana-5601/371587 "2025-02-04T10:07:16Z")

</div>

Is it possible to tunnel elasticsearch:9200 queries via kibana:5601

---

## [Kibana Elastic Cloud default snapshot policy and searchable snapshots](https://discuss.elastic.co/t/kibana-elastic-cloud-default-snapshot-policy-and-searchable-snapshots/373981)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [February 2, 2025, 1:24pm UTC](https://discuss.elastic.co/t/kibana-elastic-cloud-default-snapshot-policy-and-searchable-snapshots/373981 "2025-02-02T13:24:03Z")

</div>

On Elastic Cloud there is a default snapshot policy that takes a snapshot fo the entire cluster, per default this policy runs every 30 minutes and cannot be disabeld, just tricked into not running (by setting a distant f…

---

## [Shape issue in Canvas](https://discuss.elastic.co/t/shape-issue-in-canvas/374013)

<div class="topic-metadata">

**Author:** [@MattiHatem](https://discuss.elastic.co/u/MattiHatem)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 3:19pm UTC](https://discuss.elastic.co/t/shape-issue-in-canvas/374013 "2025-02-03T15:19:30Z")

</div>

the below is giving me the following error (\[if\] \> \[gte\] \> Can not cast 'shape' to any of 'number, string'), I have tried the switch case but also didn't work, can anyone help me please filters | essql query="SELECT…

---

## [Kibana Dashboard report Printable version](https://discuss.elastic.co/t/kibana-dashboard-report-printable-version/374009)

<div class="topic-metadata">

**Author:** [@amarasinghe.kaluarac](https://discuss.elastic.co/u/amarasinghe.kaluarac)\
**Replies:** 0\
**Last updated:** [February 3, 2025, 10:40am UTC](https://discuss.elastic.co/t/kibana-dashboard-report-printable-version/374009 "2025-02-03T10:40:13Z")

</div>

Hi all, So I tried to take a report using kibana but when I tried to take the printable option of PDF it failed with no error So I am at a lost now , I have tried with increasing the jvm heap and kibana ram KIBAN…

---

## [Issue with embedded dashboard Anonymous authentication](https://discuss.elastic.co/t/issue-with-embedded-dashboard-anonymous-authentication/373972)

<div class="topic-metadata">

**Author:** [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 10:03am UTC](https://discuss.elastic.co/t/issue-with-embedded-dashboard-anonymous-authentication/373972 "2025-02-03T10:03:28Z")

</div>

Hi We have configured the Anonymous authentication for Kibana so that we can share the embedded dashboard link to the users. The problem we face is, this embedded dashboard link will open only one time (who ever opens …

---

## [Upgrade elasticsearch from version 7.16 to 7.17](https://discuss.elastic.co/t/upgrade-elasticsearch-from-version-7-16-to-7-17/373837)

<div class="topic-metadata">

**Author:** [@p\_alavi](https://discuss.elastic.co/u/p_alavi)\
**Replies:** 12\
**Last updated:** [February 2, 2025, 12:56pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-from-version-7-16-to-7-17/373837 "2025-02-02T12:56:16Z")

</div>

Hi all, I recently upgraded my Elasticsearch cluster from version 7.16 to 7.17 and encountered several issues. Kibana is not loading properly, and I am receiving license-related errors and missing authentication credent…

---

## [Why is TSVB being depricated](https://discuss.elastic.co/t/why-is-tsvb-being-depricated/373678)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 8\
**Last updated:** [January 31, 2025, 7:30pm UTC](https://discuss.elastic.co/t/why-is-tsvb-being-depricated/373678 "2025-01-31T19:30:43Z")

</div>

well the main question what is the main reason behind deprecation of TSVB and what will be going to be the alternative solution? TSVB is such a nice feature, it would give the opportunity to search on your data in one…

---

## [How to filter the visualization on unique values of a field?](https://discuss.elastic.co/t/how-to-filter-the-visualization-on-unique-values-of-a-field/373714)

<div class="topic-metadata">

**Author:** [@Priyanka\_Rajpal](https://discuss.elastic.co/u/Priyanka_Rajpal)\
**Replies:** 6\
**Last updated:** [January 31, 2025, 3:06pm UTC](https://discuss.elastic.co/t/how-to-filter-the-visualization-on-unique-values-of-a-field/373714 "2025-01-31T15:06:26Z")

</div>

I have a visualization to plot the sum of item quantity's over the span of a period. I need to add a filter to only sum item's having unique item id. How can I do that? I tried using the below query, but it gives me th…

---

## [Dashboard API](https://discuss.elastic.co/t/dashboard-api/373834)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [January 30, 2025, 7:32pm UTC](https://discuss.elastic.co/t/dashboard-api/373834 "2025-01-30T19:32:20Z")

</div>

Hello, Is there a way to automate or programmatically create dashboards/visualizations using an API?

---

## [Problem creating a custom color ramp for a layer](https://discuss.elastic.co/t/problem-creating-a-custom-color-ramp-for-a-layer/373890)

<div class="topic-metadata">

**Author:** [@juandres117](https://discuss.elastic.co/u/juandres117)\
**Replies:** 2\
**Last updated:** [January 30, 2025, 4:34pm UTC](https://discuss.elastic.co/t/problem-creating-a-custom-color-ramp-for-a-layer/373890 "2025-01-30T16:34:47Z")

</div>

Hey there! I am uploading different economics indicators to Kibana. However, I am having troubles with the definition of the values of the ramp. As you can see I have negative values in some countries. I have to cha…

---

## [Kibana Semaphore - no logs in 5min, 10min, 30min](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 2\
**Last updated:** [January 30, 2025, 4:17pm UTC](https://discuss.elastic.co/t/kibana-semaphore-no-logs-in-5min-10min-30min/373892 "2025-01-30T16:17:14Z")

</div>

How to create any kind of vizualisation in Kibana, which change the color according to amount of logs in time. Let's say, it should be green if there is any amount of logs within 5minutes, if no log is present in 5 mins,…

---

## [See aggregation value in a custom threshold (using webhook)](https://discuss.elastic.co/t/see-aggregation-value-in-a-custom-threshold-using-webhook/373805)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 2\
**Last updated:** [January 30, 2025, 9:41am UTC](https://discuss.elastic.co/t/see-aggregation-value-in-a-custom-threshold-using-webhook/373805 "2025-01-30T09:41:15Z")

</div>

Hello all, I have created a custom threshold rule in Kibana 8.15.3 where I have defined two aggregations: Aggregation A --\> count (all documents) Aggregation B --\> count (eventType: F\*) I have also created a webhook …

---

## [Suricata Integration Delay](https://discuss.elastic.co/t/suricata-integration-delay/373847)

<div class="topic-metadata">

**Author:** [@elastic\_c](https://discuss.elastic.co/u/elastic_c)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 4:16pm UTC](https://discuss.elastic.co/t/suricata-integration-delay/373847 "2025-01-29T16:16:32Z")

</div>

Hello Everyone, Been stuck on this issue for a while and wondering if anyone can provide me some more information on what could be going on here. I set up the Suricata integration using fleet server, elastic agent, Kib…

---

## [Controls drag drop position feature missing in elasticsearch version 8.16.1](https://discuss.elastic.co/t/controls-drag-drop-position-feature-missing-in-elasticsearch-version-8-16-1/373759)

<div class="topic-metadata">

**Author:** [@mittal\_rawal1](https://discuss.elastic.co/u/mittal_rawal1)\
**Replies:** 1\
**Last updated:** [January 29, 2025, 12:39pm UTC](https://discuss.elastic.co/t/controls-drag-drop-position-feature-missing-in-elasticsearch-version-8-16-1/373759 "2025-01-29T12:39:52Z")

</div>

I have migrated my dashboard from 8.1.0 version to 8.16.1 and in this i was using controls which is deprecated, and now new controls are there but i am not able to move controls below the dashboard header. here i wan…

---

## [Backup and Restore](https://discuss.elastic.co/t/backup-and-restore/373796)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 5:09am UTC](https://discuss.elastic.co/t/backup-and-restore/373796 "2025-01-29T05:09:10Z")

</div>

Hi Team, We have 2 variants of Elasticsearch clusters in our organisation. We have the ES cloud platinum license for some use cases while for others we have our own self-hosted ES clusters for some valid reasons. For …

---

## [Controls - Adding Links?](https://discuss.elastic.co/t/controls-adding-links/373785)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [January 28, 2025, 5:25pm UTC](https://discuss.elastic.co/t/controls-adding-links/373785 "2025-01-28T17:25:44Z")

</div>

Hello, With the use of Controls, we can have the user select an option from a list (granted you have a data view). Is it possible to have hyperlinks or links to other dashboard using Controls (drop down)? I have al…

---

## [Metric or legacy lens does not apply dashboard context filter](https://discuss.elastic.co/t/metric-or-legacy-lens-does-not-apply-dashboard-context-filter/373707)

<div class="topic-metadata">

**Author:** [@j-nash](https://discuss.elastic.co/u/j-nash)\
**Replies:** 4\
**Last updated:** [January 28, 2025, 2:36pm UTC](https://discuss.elastic.co/t/metric-or-legacy-lens-does-not-apply-dashboard-context-filter/373707 "2025-01-28T14:36:28Z")

</div>

Hello, I'm creating a dashboard in Kibana to visualize some metrics, and I'm encountering an issue with the date selector. The date selector works perfectly for most visualizations, but when I use either the "legacy" l…

---

## [How to Filter and Group Values by Type in an Array Nested Field in Kibana](https://discuss.elastic.co/t/how-to-filter-and-group-values-by-type-in-an-array-nested-field-in-kibana/373643)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 1\
**Last updated:** [January 28, 2025, 8:35am UTC](https://discuss.elastic.co/t/how-to-filter-and-group-values-by-type-in-an-array-nested-field-in-kibana/373643 "2025-01-28T08:35:00Z")

</div>

How can I filter and group a field from a document? Inside the document, I have a field with an array of type and values. I would like to filter by type X and group only the values related to it in Kibana.

---

## [How to configure elastic stack, i want to migrate from Prometheus to elastic](https://discuss.elastic.co/t/how-to-configure-elastic-stack-i-want-to-migrate-from-prometheus-to-elastic/373395)

<div class="topic-metadata">

**Author:** [@vagharsh](https://discuss.elastic.co/u/vagharsh)\
**Replies:** 7\
**Last updated:** [January 27, 2025, 9:50pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-stack-i-want-to-migrate-from-prometheus-to-elastic/373395 "2025-01-27T21:50:52Z")

</div>

hi everyone, i am using elastic/eck-stack helm chart, my helm values are posted below, i want to migrate away from my current prometheus monitoring solution but since my environment is using servicemonitors and pod mon…

---

## [Docker-compose.yml & corporate man in the middle ca](https://discuss.elastic.co/t/docker-compose-yml-corporate-man-in-the-middle-ca/373745)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 0\
**Last updated:** [January 27, 2025, 6:34pm UTC](https://discuss.elastic.co/t/docker-compose-yml-corporate-man-in-the-middle-ca/373745 "2025-01-27T18:34:40Z")

</div>

Hi, In our company we have a man in the middle firewall/proxy for deep packet inspection with self signed certificates. For local experiments I want to run the docker-compose.yml with Elasticsearch and Kibana. When t…

---

## [M3 16" macbookpro trackpad scrolling issue with kibana console?](https://discuss.elastic.co/t/m3-16-macbookpro-trackpad-scrolling-issue-with-kibana-console/373480)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 5\
**Last updated:** [January 27, 2025, 4:50pm UTC](https://discuss.elastic.co/t/m3-16-macbookpro-trackpad-scrolling-issue-with-kibana-console/373480 "2025-01-27T16:50:38Z")

</div>

Has anybody encountered issue with scrolling? Whenever I reverse 2 finger scrolling, the screen would stutter or stops the scrolling action. It only happens with kibana console page. Both on firefox and safari. I hav…

---

## [Kibana 8.12.2 load image local](https://discuss.elastic.co/t/kibana-8-12-2-load-image-local/373593)

<div class="topic-metadata">

**Author:** [@ferchovi90](https://discuss.elastic.co/u/ferchovi90)\
**Replies:** 3\
**Last updated:** [January 27, 2025, 4:45pm UTC](https://discuss.elastic.co/t/kibana-8-12-2-load-image-local/373593 "2025-01-27T16:45:37Z")

</div>

Hello! I want to display in my kibana visualization my local image. I placed the images in this path "/usr/share/kibana/src/plugins/index\_pattern\_management/public/assets/icons/topologias/Portales" but they do not load…

---

## [Identifying number of logs per 5 minutes, over a week?](https://discuss.elastic.co/t/identifying-number-of-logs-per-5-minutes-over-a-week/373586)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 3\
**Last updated:** [January 27, 2025, 12:42pm UTC](https://discuss.elastic.co/t/identifying-number-of-logs-per-5-minutes-over-a-week/373586 "2025-01-27T12:42:01Z")

</div>

We ship AWS ALB logs to Kibana. Each log has a lot of key value fields but the two we are interested in are client\_ip and timestamp. For example: timestamp: Jan 23, 2025 @ 14:40:00.268 client\_ip: 8.8.8.8 I am trying…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=23)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=25)
