# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=243

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 244

---

## [Create alerts for logs ingestion in kibana](https://discuss.elastic.co/t/create-alerts-for-logs-ingestion-in-kibana/295772)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 6\
**Last updated:** [February 7, 2022, 4:16am UTC](https://discuss.elastic.co/t/create-alerts-for-logs-ingestion-in-kibana/295772 "2022-02-07T04:16:07Z")

</div>

Hello, I'm trying to create an alert for log ingestion alert. ex- If we have one index pattern and logs stopped coming to the kibana for the last 5 min, Can we create an alert for this in kibana?

---

## [Filter for field contains value in Dashboard](https://discuss.elastic.co/t/filter-for-field-contains-value-in-dashboard/296398)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 5\
**Last updated:** [February 7, 2022, 3:29am UTC](https://discuss.elastic.co/t/filter-for-field-contains-value-in-dashboard/296398 "2022-02-07T03:29:29Z")

</div>

Hi All, I'm using 7.16.2 version. I want to ask if there is a possibility to filter the dashboard by field that contain certain string? Thanks, Shay

---

## [Storage size doubled after Update By Query](https://discuss.elastic.co/t/storage-size-doubled-after-update-by-query/296405)

<div class="topic-metadata">

**Author:** [@yamaga](https://discuss.elastic.co/u/yamaga)\
**Replies:** 1\
**Last updated:** [February 6, 2022, 11:58pm UTC](https://discuss.elastic.co/t/storage-size-doubled-after-update-by-query/296405 "2022-02-06T23:58:17Z")

</div>

Hi, Mi index has 17Gb of storage size But where I executed (2 times !) the "update by query" querey to copy a field in an other one the size is increased : The Docs count doesnt change. POST jp\_data\_stk\_mouv/\_updat…

---

## [Can I have two different Kibana Servers pointed at the same elasticsearch cluster?](https://discuss.elastic.co/t/can-i-have-two-different-kibana-servers-pointed-at-the-same-elasticsearch-cluster/296339)

<div class="topic-metadata">

**Author:** [@nsimi](https://discuss.elastic.co/u/nsimi)\
**Replies:** 1\
**Last updated:** [February 6, 2022, 9:44pm UTC](https://discuss.elastic.co/t/can-i-have-two-different-kibana-servers-pointed-at-the-same-elasticsearch-cluster/296339 "2022-02-06T21:44:20Z")

</div>

Good Morning All, I have an ES cluster running and an instance of Kibana (Lets call this instance A) pointed at that. And because of some involved weird "business reasons" I wanted to know if I could have a separate Kib…

---

## [How to print multiple text rows with vega](https://discuss.elastic.co/t/how-to-print-multiple-text-rows-with-vega/296085)

<div class="topic-metadata">

**Author:** [@TUKTUK](https://discuss.elastic.co/u/TUKTUK)\
**Replies:** 2\
**Last updated:** [February 6, 2022, 5:47pm UTC](https://discuss.elastic.co/t/how-to-print-multiple-text-rows-with-vega/296085 "2022-02-06T17:47:22Z")

</div>

Hi, all I am pretty new to the Vega world inside Kibana and was wondering if there is some easy way to simply print text fields in rows. I know that Vega is not designed to output text, nevertheless, someone knows maybe…

---

## [Automatically centre the map around a specified point by dropdown menu](https://discuss.elastic.co/t/automatically-centre-the-map-around-a-specified-point-by-dropdown-menu/296281)

<div class="topic-metadata">

**Author:** [@Angad\_Panesar1](https://discuss.elastic.co/u/Angad_Panesar1)\
**Replies:** 1\
**Last updated:** [February 4, 2022, 7:44pm UTC](https://discuss.elastic.co/t/automatically-centre-the-map-around-a-specified-point-by-dropdown-menu/296281 "2022-02-04T19:44:01Z")

</div>

Hi, There is a dropdown menu filter of ID's with each of them having different latitudes and longitudes on the map. Is there any way that I can centre the map around the specified point by clicking on the ID in the dropd…

---

## [How to organize snmp tables like in nagios](https://discuss.elastic.co/t/how-to-organize-snmp-tables-like-in-nagios/296372)

<div class="topic-metadata">

**Author:** [@Samt1](https://discuss.elastic.co/u/Samt1)\
**Replies:** 1\
**Last updated:** [February 6, 2022, 1:32am UTC](https://discuss.elastic.co/t/how-to-organize-snmp-tables-like-in-nagios/296372 "2022-02-06T01:32:23Z")

</div>

Hello. I'm trying to monitor some devices via snmp and logstash. I want to display the information in a table like this (this table is from nagios). Is it possible? I've made some tables on the visualization library, bu…

---

## [Attempt to divide two fields at the aggregate level causing infinity response](https://discuss.elastic.co/t/attempt-to-divide-two-fields-at-the-aggregate-level-causing-infinity-response/296198)

<div class="topic-metadata">

**Author:** [@LuigiGalati](https://discuss.elastic.co/u/LuigiGalati)\
**Replies:** 20\
**Last updated:** [February 5, 2022, 11:08pm UTC](https://discuss.elastic.co/t/attempt-to-divide-two-fields-at-the-aggregate-level-causing-infinity-response/296198 "2022-02-05T23:08:45Z")

</div>

I am feeding kibana with an HR dataset from peoplesoft. The data is beginning, end and termination counts by fiscal year. There is no timestamped data used. I need to calculate percent turnover which is Terminations/(Ave…

---

## [Remove Kibana message about overlapping Snapshots](https://discuss.elastic.co/t/remove-kibana-message-about-overlapping-snapshots/296350)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [February 5, 2022, 12:07am UTC](https://discuss.elastic.co/t/remove-kibana-message-about-overlapping-snapshots/296350 "2022-02-05T00:07:42Z")

</div>

Hello, While elasticsearch can now take multiple snapshots at the same time, If you configure a snapshot policy with the same time in Kibana, it will show the following message: Two or more policies have the same sche…

---

## [Kibana service account not working for v8 upgrade deprecation note](https://discuss.elastic.co/t/kibana-service-account-not-working-for-v8-upgrade-deprecation-note/296125)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 4\
**Last updated:** [February 4, 2022, 9:05pm UTC](https://discuss.elastic.co/t/kibana-service-account-not-working-for-v8-upgrade-deprecation-note/296125 "2022-02-04T21:05:19Z")

</div>

We recently moved our stack to 7.17 and are working through some of the warnings in the 8.0 upgrade assistant to be ready for the new version in the future. When changing Kibana to use Elasticsearch.serviceAccountToken i…

---

## [Namespace Option in Slack Connector](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 5\
**Last updated:** [February 4, 2022, 7:59pm UTC](https://discuss.elastic.co/t/namespace-option-in-slack-connector/295292 "2022-02-04T19:59:25Z")

</div>

Is it possible to add the namespace information in the slack connector? i.e Rule {{context.rule.name}} with severity {{context.rule.severity}} generated {{state.signals\_count}} alerts in the {{context.data\_stream.names…

---

## [Kibana errors](https://discuss.elastic.co/t/kibana-errors/296229)

<div class="topic-metadata">

**Author:** [@sukhsehaj](https://discuss.elastic.co/u/sukhsehaj)\
**Replies:** 5\
**Last updated:** [February 4, 2022, 5:21pm UTC](https://discuss.elastic.co/t/kibana-errors/296229 "2022-02-04T17:21:01Z")

</div>

Hello, can you plz help me troubleshoot these Kibana errors: Feb 03 19:49:32 prozokiba01.pinpointtech.com systemd\[1\]: Started Kibana. Feb 03 19:49:42 prozokiba01.pinpointtech.com kibana\[562\]: {"type":"log","@timestamp"…

---

## [Do I need a nested query or foreach or a create a new index?](https://discuss.elastic.co/t/do-i-need-a-nested-query-or-foreach-or-a-create-a-new-index/295968)

<div class="topic-metadata">

**Author:** [@clearbluelou](https://discuss.elastic.co/u/clearbluelou)\
**Replies:** 5\
**Last updated:** [February 3, 2022, 8:52pm UTC](https://discuss.elastic.co/t/do-i-need-a-nested-query-or-foreach-or-a-create-a-new-index/295968 "2022-02-03T20:52:06Z")

</div>

I'm new to Elasticsearch and Kibana. I haven't really gotten to a point of understanding of the JSON-like syntax. I've just been using the filters and some Lucene queries. Please be gentle. :blush: This is hard to e…

---

## [No results with larger time range](https://discuss.elastic.co/t/no-results-with-larger-time-range/296035)

<div class="topic-metadata">

**Author:** [@jukow](https://discuss.elastic.co/u/jukow)\
**Replies:** 1\
**Last updated:** [February 4, 2022, 2:22pm UTC](https://discuss.elastic.co/t/no-results-with-larger-time-range/296035 "2022-02-04T14:22:28Z")

</div>

When i do a terms aggregation with a count metric Kibana shows "No results found" for a time range of e.g. 3 days. When i lower the range to e.g. 1 day results are showing up. What kind of strange behavior is this?

---

## [Configure Proxy Settings in Kibana to access Webhook](https://discuss.elastic.co/t/configure-proxy-settings-in-kibana-to-access-webhook/294604)

<div class="topic-metadata">

**Author:** [@mralladin](https://discuss.elastic.co/u/mralladin)\
**Replies:** 7\
**Last updated:** [February 4, 2022, 1:56pm UTC](https://discuss.elastic.co/t/configure-proxy-settings-in-kibana-to-access-webhook/294604 "2022-02-04T13:56:24Z")

</div>

Hello I want to send Alerts via Webhook to the Webex Api but the Kibana/Elastic Application ist behind our Company Proxy. I tried already with xpack.actions.proxyUrl: "http://TechnicalUser:Password@Proxy:Port" But it…

---

## [Unable to set "defaultRoute" in kibana configuration file in kibana 7.10.2](https://discuss.elastic.co/t/unable-to-set-defaultroute-in-kibana-configuration-file-in-kibana-7-10-2/296231)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 1\
**Last updated:** [February 4, 2022, 1:15pm UTC](https://discuss.elastic.co/t/unable-to-set-defaultroute-in-kibana-configuration-file-in-kibana-7-10-2/296231 "2022-02-04T13:15:43Z")

</div>

I want to remove all deprecation warnings from the kibana. In the logs, I have seen that kibana.defaultAppId has been deprecated and it has been suggested that defaultRoute should be used. But when i set this option in k…

---

## [Date Histogram Visualization](https://discuss.elastic.co/t/date-histogram-visualization/296199)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 3\
**Last updated:** [February 4, 2022, 11:40am UTC](https://discuss.elastic.co/t/date-histogram-visualization/296199 "2022-02-04T11:40:41Z")

</div>

I have a Datetime field in my index and I want to show a visualization where I will be able to see in which hours my records are the most frequent. But when I use the Date Histogram and choose to show "per 2 hours" for e…

---

## [Unable see document fields in "Add Field" selector in Kibana / Graph](https://discuss.elastic.co/t/unable-see-document-fields-in-add-field-selector-in-kibana-graph/295601)

<div class="topic-metadata">

**Author:** [@blackge](https://discuss.elastic.co/u/blackge)\
**Replies:** 2\
**Last updated:** [February 4, 2022, 10:48am UTC](https://discuss.elastic.co/t/unable-see-document-fields-in-add-field-selector-in-kibana-graph/295601 "2022-02-04T10:48:55Z")

</div>

Hi, I've just started experimenting with Graphs in Kibana and I'm only seeing a subset of the fields in my documents available to select for the graph. When I click on the add fields, I see 9 fields in the "Add Fields"…

---

## [Converting Null values to Zero](https://discuss.elastic.co/t/converting-null-values-to-zero/295707)

<div class="topic-metadata">

**Author:** [@AmyMCollins](https://discuss.elastic.co/u/AmyMCollins)\
**Replies:** 1\
**Last updated:** [February 4, 2022, 10:30am UTC](https://discuss.elastic.co/t/converting-null-values-to-zero/295707 "2022-02-04T10:30:49Z")

</div>

Hi, I am trying to get the cumulative sum of the columns 'Loaded' and 'Worked' in Canvas. I can do it with the below query but when I remove the limit statement it fails. I believe this is because the pivot creates null…

---

## [Lens visualisation doesn't sort on formula result](https://discuss.elastic.co/t/lens-visualisation-doesnt-sort-on-formula-result/296258)

<div class="topic-metadata">

**Author:** [@Dominik11](https://discuss.elastic.co/u/Dominik11)\
**Replies:** 3\
**Last updated:** [February 4, 2022, 10:25am UTC](https://discuss.elastic.co/t/lens-visualisation-doesnt-sort-on-formula-result/296258 "2022-02-04T10:25:19Z")

</div>

Hi all, I have been recreating some of my dashboards using Lens visualisations but I stumbled on a seemingly illogical limitation. The concept of one visualisation is like this : I have 50+ API's running and I want to …

---

## [Kibana KQL search common value on single column](https://discuss.elastic.co/t/kibana-kql-search-common-value-on-single-column/296077)

<div class="topic-metadata">

**Author:** [@Mercurochrome](https://discuss.elastic.co/u/Mercurochrome)\
**Replies:** 7\
**Last updated:** [February 4, 2022, 8:50am UTC](https://discuss.elastic.co/t/kibana-kql-search-common-value-on-single-column/296077 "2022-02-04T08:50:48Z")

</div>

Hello, I'm new on Kibana and I can't find answers to my problem, hopefully someone can help :slight\_smile: . Here is my problem : I have a table with some value like (Column A = Port number, Column B = IP Address, Colu…

---

## [Copying Dashboard from kibana](https://discuss.elastic.co/t/copying-dashboard-from-kibana/296142)

<div class="topic-metadata">

**Author:** [@Aniketvk008](https://discuss.elastic.co/u/Aniketvk008)\
**Replies:** 7\
**Last updated:** [February 4, 2022, 8:08am UTC](https://discuss.elastic.co/t/copying-dashboard-from-kibana/296142 "2022-02-04T08:08:15Z")

</div>

Hi how to copy dashboard from kibana without overwriting the existing object(dashboard) in same machine

---

## [Custom sort sequence is not working when using in vega-lite](https://discuss.elastic.co/t/custom-sort-sequence-is-not-working-when-using-in-vega-lite/296165)

<div class="topic-metadata">

**Author:** [@Supriya1](https://discuss.elastic.co/u/Supriya1)\
**Replies:** 0\
**Last updated:** [February 3, 2022, 9:36am UTC](https://discuss.elastic.co/t/custom-sort-sequence-is-not-working-when-using-in-vega-lite/296165 "2022-02-03T09:36:56Z")

</div>

Hi Team , If any body can guide what could be the issue Case-We are trying to extract data from kibana index and plotting a vega-lite bar chart. When we try to apply sort as ascending or descending, the sort works. How…

---

## [Elastic user works for ES API but not Kibana](https://discuss.elastic.co/t/elastic-user-works-for-es-api-but-not-kibana/295792)

<div class="topic-metadata">

**Author:** [@shlant](https://discuss.elastic.co/u/shlant)\
**Replies:** 5\
**Last updated:** [February 4, 2022, 5:18am UTC](https://discuss.elastic.co/t/elastic-user-works-for-es-api-but-not-kibana/295792 "2022-02-04T05:18:39Z")

</div>

I have set up ES and Kibana as per Secure Elasticsearch with TLS encryption and role-based access control | Elastic Blog I can hit /\_cluster/health with both elastic and kibana users. When I try and log in on the kiban…

---

## [Elastic ML job errors](https://discuss.elastic.co/t/elastic-ml-job-errors/295244)

<div class="topic-metadata">

**Author:** [@stefan.elser](https://discuss.elastic.co/u/stefan.elser)\
**Replies:** 9\
**Last updated:** [February 3, 2022, 11:10pm UTC](https://discuss.elastic.co/t/elastic-ml-job-errors/295244 "2022-02-03T23:10:38Z")

</div>

Hi! I'm new here - working with my team to explore the ML offerings in a trial license and I'm running into some errors and questions. Can Anomaly Detection model output be viewed and used in Kibana visualizations? I …

---

## [Kibana 7.16.3 Pie Chart Hole Size](https://discuss.elastic.co/t/kibana-7-16-3-pie-chart-hole-size/296232)

<div class="topic-metadata">

**Author:** [@John\_Collins](https://discuss.elastic.co/u/John_Collins)\
**Replies:** 2\
**Last updated:** [February 3, 2022, 10:57pm UTC](https://discuss.elastic.co/t/kibana-7-16-3-pie-chart-hole-size/296232 "2022-02-03T22:57:18Z")

</div>

I just upgraded from Kibana 7.11 to 7.16.3 and something just doesn't look right to me when I look at my dashboards. The size of the hole in the middle of my pie charts are causing me a ridiculous amount of unnatural st…

---

## [Kibana 7.16.2 - fields array empty for saved\_object api call](https://discuss.elastic.co/t/kibana-7-16-2-fields-array-empty-for-saved-object-api-call/295768)

<div class="topic-metadata">

**Author:** [@ssimmons](https://discuss.elastic.co/u/ssimmons)\
**Replies:** 3\
**Last updated:** [February 3, 2022, 9:56pm UTC](https://discuss.elastic.co/t/kibana-7-16-2-fields-array-empty-for-saved-object-api-call/295768 "2022-02-03T21:56:48Z")

</div>

I've used the saved\_objects api in previous versions of Kibana to retrieve the array of fields associated with each index pattern. I use the following api call: /api/saved\_objects/\_find?type=index-pattern. This returns a…

---

## [Kibana Plugin Development in Offline Environment v7.14.0](https://discuss.elastic.co/t/kibana-plugin-development-in-offline-environment-v7-14-0/295483)

<div class="topic-metadata">

**Author:** [@alexram72](https://discuss.elastic.co/u/alexram72)\
**Replies:** 1\
**Last updated:** [February 3, 2022, 8:59pm UTC](https://discuss.elastic.co/t/kibana-plugin-development-in-offline-environment-v7-14-0/295483 "2022-02-03T20:59:09Z")

</div>

I am trying to develop a Kibana plugin in my environment that is completely offline and am running into issues in getting the helper scripts to run and the development instance of Kibana to come up. I do have access to …

---

## [500 error: "Could not create index for rollup job"](https://discuss.elastic.co/t/500-error-could-not-create-index-for-rollup-job/295946)

<div class="topic-metadata">

**Author:** [@dicko](https://discuss.elastic.co/u/dicko)\
**Replies:** 1\
**Last updated:** [February 3, 2022, 8:37pm UTC](https://discuss.elastic.co/t/500-error-could-not-create-index-for-rollup-job/295946 "2022-02-03T20:37:09Z")

</div>

v 7.14.1 I'm trying to create a roll-up job on v 7.14.1 Whatever I try, like: PUT \_rollup/job/logs\_job\_test { "id": "logs\_job\_test", "index\_pattern": "clientname\*-webaccess-\*", "rollup\_index": "rollup\_clientname…

---

## [Getting error while creating scripted field](https://discuss.elastic.co/t/getting-error-while-creating-scripted-field/296221)

<div class="topic-metadata">

**Author:** [@Surya\_Raviraj](https://discuss.elastic.co/u/Surya_Raviraj)\
**Replies:** 2\
**Last updated:** [February 3, 2022, 6:54pm UTC](https://discuss.elastic.co/t/getting-error-while-creating-scripted-field/296221 "2022-02-03T18:54:40Z")

</div>

Hi all, I am creating a scripted field on an index that already has a bunch of scripted fields. After creating the scripted field I preview the results and see my desired results. For some reason, when I go back to the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=242)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=244)
