# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=242

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 243

---

## [Unique Count Aggregation filtering](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679)

<div class="topic-metadata">

**Author:** [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Replies:** 3\
**Last updated:** [February 9, 2022, 12:04pm UTC](https://discuss.elastic.co/t/unique-count-aggregation-filtering/296679 "2022-02-09T12:04:33Z")

</div>

\*\* I was wondering if the below described is possible to display on Kibana. With a sample data as below, and the unique identifier being the 'sessionId' What i'm trying to do is create any vizualization (lets say a tab…

---

## [Kibana not splitting fields by dot anymore](https://discuss.elastic.co/t/kibana-not-splitting-fields-by-dot-anymore/295826)

<div class="topic-metadata">

**Author:** [@fredsted](https://discuss.elastic.co/u/fredsted)\
**Replies:** 7\
**Last updated:** [February 9, 2022, 10:01am UTC](https://discuss.elastic.co/t/kibana-not-splitting-fields-by-dot-anymore/295826 "2022-02-09T10:01:01Z")

</div>

Hello, I'm wondering why Kibana has stopped splitting fields. For example, we used to have separate fields for "cloud.provider", "cloud.machine.type", but now it's just a single "cloud" field. It's interesting that …

---

## [Action message variable](https://discuss.elastic.co/t/action-message-variable/294908)

<div class="topic-metadata">

**Author:** [@eddieyee](https://discuss.elastic.co/u/eddieyee)\
**Replies:** 4\
**Last updated:** [February 9, 2022, 8:44am UTC](https://discuss.elastic.co/t/action-message-variable/294908 "2022-02-09T08:44:44Z")

</div>

In my Alert using Elasticsearch query, I'm building a URL pointing to Elastic Discover link in the action message and I'm able to include a time filter as seen below: time:(from:now-{{params.timeWindowSize}}{{params.tim…

---

## [How to disable saving Kibana logs to /var/log/kibana](https://discuss.elastic.co/t/how-to-disable-saving-kibana-logs-to-var-log-kibana/296447)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [February 9, 2022, 8:33am UTC](https://discuss.elastic.co/t/how-to-disable-saving-kibana-logs-to-var-log-kibana/296447 "2022-02-09T08:33:06Z")

</div>

Hello! How to totally disable saving Kibana logs to /var/log/kibana/kibana.log ? I'm using elastic stack version 7.16 and already trying to set in kibana.yml: logging.dest: "u01/data/logs/kibana.log" and logging: …

---

## [Migrating Watcher alerts for redeploy](https://discuss.elastic.co/t/migrating-watcher-alerts-for-redeploy/296677)

<div class="topic-metadata">

**Author:** [@Stud21](https://discuss.elastic.co/u/Stud21)\
**Replies:** 1\
**Last updated:** [February 9, 2022, 8:25am UTC](https://discuss.elastic.co/t/migrating-watcher-alerts-for-redeploy/296677 "2022-02-09T08:25:38Z")

</div>

I have created a watcher alert in Kibana on a test environment which I need to transfer using Ansible as a new build to another environment. I have looked at the link below which is doesn't provide information to do so. …

---

## [Multi line support to view full log message in kibana](https://discuss.elastic.co/t/multi-line-support-to-view-full-log-message-in-kibana/296586)

<div class="topic-metadata">

**Author:** [@thujitha\_p](https://discuss.elastic.co/u/thujitha_p)\
**Replies:** 3\
**Last updated:** [February 9, 2022, 7:33am UTC](https://discuss.elastic.co/t/multi-line-support-to-view-full-log-message-in-kibana/296586 "2022-02-09T07:33:53Z")

</div>

Hi there, I am new to this ELK stack. I have a problem with previewing log message in kibana. If a log message has too much characters, it is unable to view full message without expanding it. If it is large it is ended …

---

## [Kibana can't connect to elasticsearch using self signed certificates](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255)

<div class="topic-metadata">

**Author:** [@proxymoxy](https://discuss.elastic.co/u/proxymoxy)\
**Replies:** 1\
**Last updated:** [February 9, 2022, 6:31am UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-elasticsearch-using-self-signed-certificates/294255 "2022-02-09T06:31:40Z")

</div>

Hi, I have enabled TLS certificates for connection between Kibana and Elasticsearch as described here: Set up basic security for the Elastic Stack plus secured HTTPS traffic | Elasticsearch Guide \[7.16\] | Elastic I use …

---

## [How to embed existing dashboard in custom kibana plugin](https://discuss.elastic.co/t/how-to-embed-existing-dashboard-in-custom-kibana-plugin/296030)

<div class="topic-metadata">

**Author:** [@Shreeya\_Rajguru](https://discuss.elastic.co/u/Shreeya_Rajguru)\
**Replies:** 6\
**Last updated:** [February 9, 2022, 6:34am UTC](https://discuss.elastic.co/t/how-to-embed-existing-dashboard-in-custom-kibana-plugin/296030 "2022-02-09T06:34:07Z")

</div>

Hi, Is there a way to embed the existing kibana dashboards in custom plugin? I have referred the dashboard embeddable example plugin code - Embeddables plugin | Kibana Guide \[master\] | Elastic but this doesn't seem to…

---

## [How to print matches in Elasticsearch and Kibana or Elasticsearch-py?](https://discuss.elastic.co/t/how-to-print-matches-in-elasticsearch-and-kibana-or-elasticsearch-py/296329)

<div class="topic-metadata">

**Author:** [@Travel\_Time](https://discuss.elastic.co/u/Travel_Time)\
**Replies:** 2\
**Last updated:** [February 9, 2022, 5:43am UTC](https://discuss.elastic.co/t/how-to-print-matches-in-elasticsearch-and-kibana-or-elasticsearch-py/296329 "2022-02-09T05:43:54Z")

</div>

I have 2 example patterns, with the same column names. pattern1\* (index-1,index-2,index-3) col1 col2 col3 col4 pattern2\* (index-5, index-6, index-7, index-8) col1 col2 col5 I want to automatically compare pattern1\* an…

---

## [Date Histogram - Date Format Change](https://discuss.elastic.co/t/date-histogram-date-format-change/296228)

<div class="topic-metadata">

**Author:** [@Surya\_Raviraj](https://discuss.elastic.co/u/Surya_Raviraj)\
**Replies:** 2\
**Last updated:** [February 9, 2022, 1:06am UTC](https://discuss.elastic.co/t/date-histogram-date-format-change/296228 "2022-02-09T01:06:00Z")

</div>

I am currently using a date histogram for my visualization. Unfortunately, the date format seems to default to "yyyy-MM-dd". I would like to Modify it to "MMM-yyyy". I've applied that change on the field but I think whil…

---

## [Unable to change the INTERVAL part of the monitor using update monitor API](https://discuss.elastic.co/t/unable-to-change-the-interval-part-of-the-monitor-using-update-monitor-api/296665)

<div class="topic-metadata">

**Author:** [@N\_Pusapati](https://discuss.elastic.co/u/N_Pusapati)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 11:13pm UTC](https://discuss.elastic.co/t/unable-to-change-the-interval-part-of-the-monitor-using-update-monitor-api/296665 "2022-02-08T23:13:23Z")

</div>

Hi I am pretty new to Elasticsearch, trying to setup monitors on certain indexes based on the Extraction Query response. I am trying to achieve this using Create/Update monitor APIs. Everything works as expected except o…

---

## [Kibana Anonymous access - how do you prevent listing all dashboards?](https://discuss.elastic.co/t/kibana-anonymous-access-how-do-you-prevent-listing-all-dashboards/296214)

<div class="topic-metadata">

**Author:** [@maverick1](https://discuss.elastic.co/u/maverick1)\
**Replies:** 5\
**Last updated:** [February 8, 2022, 9:23pm UTC](https://discuss.elastic.co/t/kibana-anonymous-access-how-do-you-prevent-listing-all-dashboards/296214 "2022-02-08T21:23:13Z")

</div>

We are using Elastic cloud, and have setup Kibana for Anonymous access so that users can share dashboard links publicly. The anonymous role is configured to only allow Kibana -\> Dashboard Read permissions. This set…

---

## [Union two fields within Vega](https://discuss.elastic.co/t/union-two-fields-within-vega/296613)

<div class="topic-metadata">

**Author:** [@TUKTUK](https://discuss.elastic.co/u/TUKTUK)\
**Replies:** 3\
**Last updated:** [February 8, 2022, 8:00pm UTC](https://discuss.elastic.co/t/union-two-fields-within-vega/296613 "2022-02-08T20:00:44Z")

</div>

Hello together, I am looking for a way to union the elements of two different fields into one (new) array in Vega (If this is already possible in an Elastic Query that's also fine). It should be similar to a SQL-Statem…

---

## [Chart data disappears or shows up very differently when setting smaller timeframe](https://discuss.elastic.co/t/chart-data-disappears-or-shows-up-very-differently-when-setting-smaller-timeframe/296412)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 22\
**Last updated:** [February 8, 2022, 3:12pm UTC](https://discuss.elastic.co/t/chart-data-disappears-or-shows-up-very-differently-when-setting-smaller-timeframe/296412 "2022-02-08T15:12:09Z")

</div>

Hi, I'm using Kibana 7.17.0. it seems like the chart area in Kibana disappears when setting timeframe around 5 minutes (2nd screenshot). When I set it slightly longer than that (3rd screenshot), it doesn't seem to show t…

---

## [Index Frequency & Rollover](https://discuss.elastic.co/t/index-frequency-rollover/296598)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [February 8, 2022, 1:17pm UTC](https://discuss.elastic.co/t/index-frequency-rollover/296598 "2022-02-08T13:17:33Z")

</div>

If you have an ILM policy set to the default rollover settings (30 days or 50 GB), how should you configure your indexing in the LogStash output to align with that? Here's what I mean... if you have the following output …

---

## [Kibana - maximum amount of values in the DSL terms search](https://discuss.elastic.co/t/kibana-maximum-amount-of-values-in-the-dsl-terms-search/296585)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 12:45pm UTC](https://discuss.elastic.co/t/kibana-maximum-amount-of-values-in-the-dsl-terms-search/296585 "2022-02-08T12:45:55Z")

</div>

Hi! I'm trying to do a DSL filter in Kibana, in order to filter by a large amount of values on a specific field. For this, I'm using this syntax: { "query": { "bool": { "filter": { "terms": { …

---

## [Kibana is now available (was degraded)](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded/296553)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 9:05am UTC](https://discuss.elastic.co/t/kibana-is-now-available-was-degraded/296553 "2022-02-08T09:05:07Z")

</div>

Hi, I have installed a new 7.17.0 cluster and noticed that kibana is connecting to Elasticsearch. However it is not publishing on 5601. Noticed kibana is now available (was degraded) at the end. can some one tell me w…

---

## [\[Maps\] Apply global time to style metadata requests](https://discuss.elastic.co/t/maps-apply-global-time-to-style-metadata-requests/296497)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 1\
**Last updated:** [February 7, 2022, 4:58pm UTC](https://discuss.elastic.co/t/maps-apply-global-time-to-style-metadata-requests/296497 "2022-02-07T16:58:24Z")

</div>

What does flag "Apply global time to style metadata requests" means in Kibana Maps

---

## [Sum of count of record](https://discuss.elastic.co/t/sum-of-count-of-record/296481)

<div class="topic-metadata">

**Author:** [@meyer1](https://discuss.elastic.co/u/meyer1)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 4:08pm UTC](https://discuss.elastic.co/t/sum-of-count-of-record/296481 "2022-02-07T16:08:51Z")

</div>

Hello everyone, I need help with a little thing. In a table graph, I would also like to display a "total" line with the sum of the numbers on the far right. On this image for example I would like to have this line a…

---

## [404 on PDF Report](https://discuss.elastic.co/t/404-on-pdf-report/295606)

<div class="topic-metadata">

**Author:** [@BalajiTechs](https://discuss.elastic.co/u/BalajiTechs)\
**Replies:** 6\
**Last updated:** [February 7, 2022, 4:08pm UTC](https://discuss.elastic.co/t/404-on-pdf-report/295606 "2022-02-07T16:08:34Z")

</div>

I am on 7.16.2 version of elastic cloud. I am trying to generate a PDF report from a dashboard with ~25 visualizations. The generated PDF contains only error string(as shown in below image). The last successful repor…

---

## [TLS Error Calling Webhook Connector from Kibana](https://discuss.elastic.co/t/tls-error-calling-webhook-connector-from-kibana/295498)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 3:42pm UTC](https://discuss.elastic.co/t/tls-error-calling-webhook-connector-from-kibana/295498 "2022-02-07T15:42:41Z")

</div>

Hello - I'm running Elastic/Kibana version 7.16.2 on Linux with SSL enabled and CA signed certs. My TLS related Kibana settings are: server.ssl.enabled: true server.ssl.certificate: /path/to/server.crt server.ssl.key:…

---

## [Wildcard search based on a field like Splunk?](https://discuss.elastic.co/t/wildcard-search-based-on-a-field-like-splunk/295250)

<div class="topic-metadata">

**Author:** [@jlrMantu](https://discuss.elastic.co/u/jlrMantu)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 3:04pm UTC](https://discuss.elastic.co/t/wildcard-search-based-on-a-field-like-splunk/295250 "2022-02-07T15:04:13Z")

</div>

Hello, Sorry if this has been posted before, I couldn't find. We are currently using Splunk but moving to Elastic / Kibana. On Splunk, we have some Fields in the dashboard, and when we search for a value, the search su…

---

## [Role account permissions](https://discuss.elastic.co/t/role-account-permissions/296471)

<div class="topic-metadata">

**Author:** [@stuwee](https://discuss.elastic.co/u/stuwee)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 2:23pm UTC](https://discuss.elastic.co/t/role-account-permissions/296471 "2022-02-07T14:23:36Z")

</div>

Hi, is it possible to allow a role account to create new user accounts? I don't see it in the permissions. Right now I can only create new accounts from the built in elastic user.

---

## [Convert string field to json](https://discuss.elastic.co/t/convert-string-field-to-json/296478)

<div class="topic-metadata">

**Author:** [@rcts](https://discuss.elastic.co/u/rcts)\
**Replies:** 1\
**Last updated:** [February 7, 2022, 2:04pm UTC](https://discuss.elastic.co/t/convert-string-field-to-json/296478 "2022-02-07T14:04:01Z")

</div>

Hi! I need to convert this "message" field to json, how?

---

## [Kibana Dashboard display no content without filtering](https://discuss.elastic.co/t/kibana-dashboard-display-no-content-without-filtering/296256)

<div class="topic-metadata">

**Author:** [@fionachan](https://discuss.elastic.co/u/fionachan)\
**Replies:** 17\
**Last updated:** [February 7, 2022, 11:28am UTC](https://discuss.elastic.co/t/kibana-dashboard-display-no-content-without-filtering/296256 "2022-02-07T11:28:46Z")

</div>

Hi, is there a way to make the table in the dashboard shows a sentence like "please select", after filtering show the data?

---

## [How to set a custom logo in kibana 7.16](https://discuss.elastic.co/t/how-to-set-a-custom-logo-in-kibana-7-16/296422)

<div class="topic-metadata">

**Author:** [@Sunil\_Bhakar](https://discuss.elastic.co/u/Sunil_Bhakar)\
**Replies:** 1\
**Last updated:** [February 7, 2022, 9:34am UTC](https://discuss.elastic.co/t/how-to-set-a-custom-logo-in-kibana-7-16/296422 "2022-02-07T09:34:21Z")

</div>

Hello, I want to set a custom logo in kibana 7.16. Thanks in Advance for the help.

---

## [Customize chart fields](https://discuss.elastic.co/t/customize-chart-fields/296071)

<div class="topic-metadata">

**Author:** [@meyer1](https://discuss.elastic.co/u/meyer1)\
**Replies:** 5\
**Last updated:** [February 7, 2022, 9:18am UTC](https://discuss.elastic.co/t/customize-chart-fields/296071 "2022-02-07T09:18:56Z")

</div>

Hello everybody I have a small problem that I encounter on most of my graphs. I would like to display the field name + its value in the captions. There is currently only the value and it is not too telling. Is it pos…

---

## [I got "Limited to 500 results. Refine your search. 256 documents" in save search displayed in dashboard](https://discuss.elastic.co/t/i-got-limited-to-500-results-refine-your-search-256-documents-in-save-search-displayed-in-dashboard/296420)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 1\
**Last updated:** [February 7, 2022, 6:57am UTC](https://discuss.elastic.co/t/i-got-limited-to-500-results-refine-your-search-256-documents-in-save-search-displayed-in-dashboard/296420 "2022-02-07T06:57:25Z")

</div>

Hi All, I'm using 7.16.2 version. I have a saved search that I'm displaying in dashboard. When I add a filter for a text field which contains certain text I get: "Limited to 500 results. Refine your search. 256 documen…

---

## [Scripted field using painless - creating new field based on multiple fields](https://discuss.elastic.co/t/scripted-field-using-painless-creating-new-field-based-on-multiple-fields/296402)

<div class="topic-metadata">

**Author:** [@iraidalavrovaa](https://discuss.elastic.co/u/iraidalavrovaa)\
**Replies:** 3\
**Last updated:** [February 7, 2022, 5:19am UTC](https://discuss.elastic.co/t/scripted-field-using-painless-creating-new-field-based-on-multiple-fields/296402 "2022-02-07T05:19:30Z")

</div>

Hi all, I have multiple fields containing the values of the same type (strings). The underlying structure of the division into these fields has changed. So I want to reorganize these fields for better filtering and vis…

---

## [Kibana Sizing Guide?](https://discuss.elastic.co/t/kibana-sizing-guide/296395)

<div class="topic-metadata">

**Author:** [@crpj](https://discuss.elastic.co/u/crpj)\
**Replies:** 4\
**Last updated:** [February 7, 2022, 4:44am UTC](https://discuss.elastic.co/t/kibana-sizing-guide/296395 "2022-02-07T04:44:51Z")

</div>

Hello, I am attempting to create a sizing estimate and did not find specific guidance for Kibana, could anyone clarify if there is an official guide? As of now, I am considering this setup to be a single machine: 4 CPU…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=241)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=243)
