# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=25

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 26

---

## [Global search shows Index Names. How to avoid that, as they spam result?](https://discuss.elastic.co/t/global-search-shows-index-names-how-to-avoid-that-as-they-spam-result/373708)

<div class="topic-metadata">

**Author:** [@arberg](https://discuss.elastic.co/u/arberg)\
**Replies:** 0\
**Last updated:** [January 27, 2025, 10:06am UTC](https://discuss.elastic.co/t/global-search-shows-index-names-how-to-avoid-that-as-they-spam-result/373708 "2025-01-27T10:06:40Z")

</div>

In the new Kibana 8.17.1 (coming from 8.11.4) the global search now find index names when I search. This makes it difficult to use. I can see i can wrtie tag:search but that makes it slow and much less useful than just u…

---

## [Unable to create fleet server with default logstash output](https://discuss.elastic.co/t/unable-to-create-fleet-server-with-default-logstash-output/373663)

<div class="topic-metadata">

**Author:** [@Vladimir7172](https://discuss.elastic.co/u/Vladimir7172)\
**Replies:** 1\
**Last updated:** [January 25, 2025, 10:49pm UTC](https://discuss.elastic.co/t/unable-to-create-fleet-server-with-default-logstash-output/373663 "2025-01-25T22:49:31Z")

</div>

I encountered a problem that completely interferes with the normal operation of the service. I opened an issue on Git, but so far they are silent, I want to know if this is the expected behavior Details below Stack Ve…

---

## [Visualizations: Unique Count is Inaccurate](https://discuss.elastic.co/t/visualizations-unique-count-is-inaccurate/373595)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [January 24, 2025, 2:49pm UTC](https://discuss.elastic.co/t/visualizations-unique-count-is-inaccurate/373595 "2025-01-24T14:49:26Z")

</div>

Hello, As I been exploring the use of ES|QL , I found inconsistencies with metric visualizations using unique count. I have a dataset with 6,929 unique host.name values and for the sake of this it will only show up as 6…

---

## [Heatmap for test cases overview](https://discuss.elastic.co/t/heatmap-for-test-cases-overview/373604)

<div class="topic-metadata">

**Author:** [@Fabian\_Sturm](https://discuss.elastic.co/u/Fabian_Sturm)\
**Replies:** 4\
**Last updated:** [January 24, 2025, 2:21pm UTC](https://discuss.elastic.co/t/heatmap-for-test-cases-overview/373604 "2025-01-24T14:21:00Z")

</div>

Hello community, I thought I have a fairly easy problem but I somehow always struggle with the Kibana visualizations. What I have is an index with test case execution records. Where each document in the index has a fil…

---

## [Kibana user metrics](https://discuss.elastic.co/t/kibana-user-metrics/373397)

<div class="topic-metadata">

**Author:** [@ezaydler](https://discuss.elastic.co/u/ezaydler)\
**Replies:** 3\
**Last updated:** [January 24, 2025, 12:52pm UTC](https://discuss.elastic.co/t/kibana-user-metrics/373397 "2025-01-24T12:52:11Z")

</div>

Hello, our company uses Kibana, and we want to track user metrics such as the requested date range, applied filters, and other relevant data. Is there a solution to achieve this?

---

## [ES|QL Visualizations: Filtering](https://discuss.elastic.co/t/es-ql-visualizations-filtering/373590)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [January 24, 2025, 12:12pm UTC](https://discuss.elastic.co/t/es-ql-visualizations-filtering/373590 "2025-01-24T12:12:20Z")

</div>

Hello, I created a nice ES|QL visualization, nothing crazy, its just grouping by version number found in the raw data. I wanted to filter on one of the version numbers to apply to the whole dashboard but it doesn't let…

---

## [Table dashboard in Kibana is not showing every events](https://discuss.elastic.co/t/table-dashboard-in-kibana-is-not-showing-every-events/373562)

<div class="topic-metadata">

**Author:** [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Replies:** 1\
**Last updated:** [January 24, 2025, 11:32am UTC](https://discuss.elastic.co/t/table-dashboard-in-kibana-is-not-showing-every-events/373562 "2025-01-24T11:32:26Z")

</div>

Hi, Some how we are able to create a basic TABLE dashboard to visualize the list of alerts events in table format. But what its missing is, Its not showing every alert events, for example at 13:35 there are multiple ale…

---

## [Kibana Update field on dashboard](https://discuss.elastic.co/t/kibana-update-field-on-dashboard/373516)

<div class="topic-metadata">

**Author:** [@modnakapsula](https://discuss.elastic.co/u/modnakapsula)\
**Replies:** 1\
**Last updated:** [January 24, 2025, 10:28am UTC](https://discuss.elastic.co/t/kibana-update-field-on-dashboard/373516 "2025-01-24T10:28:53Z")

</div>

Hi, I am showing a list of the top 10 documents in kibana table visualisation and I need the end user to be able to "mark" if the document/row is relevant or not for him. Is it possible to do it on the dashboard?

---

## [Field sorting in discover](https://discuss.elastic.co/t/field-sorting-in-discover/373530)

<div class="topic-metadata">

**Author:** [@venxxx](https://discuss.elastic.co/u/venxxx)\
**Replies:** 7\
**Last updated:** [January 24, 2025, 9:25am UTC](https://discuss.elastic.co/t/field-sorting-in-discover/373530 "2025-01-24T09:25:02Z")

</div>

i am trying to sort on the 'field' column but the sorting is disabled somehow. i checked the dataview and it shows 38 fields available, but in discover there are only 18 fields.

---

## [How does Kibana's timestamp-based filtering work?](https://discuss.elastic.co/t/how-does-kibanas-timestamp-based-filtering-work/373224)

<div class="topic-metadata">

**Author:** [@Harshali\_Zode](https://discuss.elastic.co/u/Harshali_Zode)\
**Replies:** 4\
**Last updated:** [January 24, 2025, 6:07am UTC](https://discuss.elastic.co/t/how-does-kibanas-timestamp-based-filtering-work/373224 "2025-01-24T06:07:34Z")

</div>

Hello, everyone. I have a question about filtering data from Elasticsearch based on the UTC timestamp. The requirement is to display the date and time details in the local time zone after retrieving the data from elast…

---

## [Displaying values on Kibana images](https://discuss.elastic.co/t/displaying-values-on-kibana-images/373429)

<div class="topic-metadata">

**Author:** [@SaraAlshamsi](https://discuss.elastic.co/u/SaraAlshamsi)\
**Replies:** 4\
**Last updated:** [January 24, 2025, 3:53am UTC](https://discuss.elastic.co/t/displaying-values-on-kibana-images/373429 "2025-01-24T03:53:12Z")

</div>

Hello everyone, I would like to display data on Kibana images in my dashboard. I know how to insert images by adding the image panel: But, there is no option to display data on top of the images. For example, I wa…

---

## [Changing the session time for non cloud version loging out](https://discuss.elastic.co/t/changing-the-session-time-for-non-cloud-version-loging-out/371496)

<div class="topic-metadata">

**Author:** [@nash3650](https://discuss.elastic.co/u/nash3650)\
**Replies:** 1\
**Last updated:** [January 24, 2025, 2:07am UTC](https://discuss.elastic.co/t/changing-the-session-time-for-non-cloud-version-loging-out/371496 "2025-01-24T02:07:24Z")

</div>

Hi, Does anyone know how I can change the logout time session to an 1hr?

---

## [Latest value in ESQL Elasticsearch piped query language on kibana](https://discuss.elastic.co/t/latest-value-in-esql-elasticsearch-piped-query-language-on-kibana/373427)

<div class="topic-metadata">

**Author:** [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Replies:** 2\
**Last updated:** [January 23, 2025, 12:11pm UTC](https://discuss.elastic.co/t/latest-value-in-esql-elasticsearch-piped-query-language-on-kibana/373427 "2025-01-23T12:11:07Z")

</div>

Hi Guys We are running below ES|QL query on Kibana to make a table of list of alerts triggered from a external Monitoring tool. FROM winlogbeat-\* | WHERE event.code == "3003" | stats Alert\_Time = VALUES(@timestamp), Se…

---

## [Having trouble connecting to Kibana. New user](https://discuss.elastic.co/t/having-trouble-connecting-to-kibana-new-user/373476)

<div class="topic-metadata">

**Author:** [@CarlosDanger142](https://discuss.elastic.co/u/CarlosDanger142)\
**Replies:** 19\
**Last updated:** [January 22, 2025, 10:59pm UTC](https://discuss.elastic.co/t/having-trouble-connecting-to-kibana-new-user/373476 "2025-01-22T22:59:44Z")

</div>

Can't get the server to listen on port 5601. netstat -ant shows nothing on port 5601. Getting connection refused on port 5601 with Curl. telemetry.enabled: false telemetry.optIn: false newsfeed.enabled: false se…

---

## [Kibana - Client request timeout](https://discuss.elastic.co/t/kibana-client-request-timeout/373520)

<div class="topic-metadata">

**Author:** [@Shahram](https://discuss.elastic.co/u/Shahram)\
**Replies:** 0\
**Last updated:** [January 22, 2025, 3:02pm UTC](https://discuss.elastic.co/t/kibana-client-request-timeout/373520 "2025-01-22T15:02:11Z")

</div>

I am using dev consule of kibana to modify elasticsearch index. My request reads the data of a field and writes it in another field of the same index. The size of the index is 20 milion documents. This is my script: P…

---

## [How to choose different saved search in a single panel based on drop down selection type in kibana dashboard](https://discuss.elastic.co/t/how-to-choose-different-saved-search-in-a-single-panel-based-on-drop-down-selection-type-in-kibana-dashboard/373483)

<div class="topic-metadata">

**Author:** [@halex](https://discuss.elastic.co/u/halex)\
**Replies:** 2\
**Last updated:** [January 22, 2025, 3:07pm UTC](https://discuss.elastic.co/t/how-to-choose-different-saved-search-in-a-single-panel-based-on-drop-down-selection-type-in-kibana-dashboard/373483 "2025-01-22T15:07:51Z")

</div>

I have use case where based on TransactionType(dropdown), I need to execute different searches in the visualisation dashboard. Example: PO - I have created a search where i have to group the events by OrderNumber A…

---

## [ES|QL Visualization: Metric Format Title](https://discuss.elastic.co/t/es-ql-visualization-metric-format-title/373470)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [January 21, 2025, 7:17pm UTC](https://discuss.elastic.co/t/es-ql-visualization-metric-format-title/373470 "2025-01-21T19:17:39Z")

</div>

Hello, I created a metric visualization using ES|QL. I was wondering if I am doing it wrong but I can't seem to format the name with spaces. FROM logs-\* | WHERE host.name IS NOT NULL | STATS count = COUNT(\*) BY host.na…

---

## [Is there a way to return to the Kibana 8.16 interface?](https://discuss.elastic.co/t/is-there-a-way-to-return-to-the-kibana-8-16-interface/373420)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 3\
**Last updated:** [January 20, 2025, 11:51pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-return-to-the-kibana-8-16-interface/373420 "2025-01-20T23:51:12Z")

</div>

Team, I have a question. Is there a way to return to the Kibana 8.16 interface? I updated my kibana to 8.17 and it has been somewhat cumbersome to locate us, elastic promises to be easy navigation but it has been a prob…

---

## [Snapshot restore -- How to check how long the restore took?](https://discuss.elastic.co/t/snapshot-restore-how-to-check-how-long-the-restore-took/367071)

<div class="topic-metadata">

**Author:** [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Replies:** 6\
**Last updated:** [January 20, 2025, 4:05pm UTC](https://discuss.elastic.co/t/snapshot-restore-how-to-check-how-long-the-restore-took/367071 "2025-01-20T16:05:31Z")

</div>

I was able to restore a snapshot recently. Is there a way for Elastic / Kibana to show how long the restore took (Full time)? There does not appear to be a definitive way. I seemed to find two ways to find this data: …

---

## [Kibana Dashboard: Create line graph from a list of floats](https://discuss.elastic.co/t/kibana-dashboard-create-line-graph-from-a-list-of-floats/373131)

<div class="topic-metadata">

**Author:** [@Pasjonsfrukt](https://discuss.elastic.co/u/Pasjonsfrukt)\
**Replies:** 17\
**Last updated:** [January 20, 2025, 3:48pm UTC](https://discuss.elastic.co/t/kibana-dashboard-create-line-graph-from-a-list-of-floats/373131 "2025-01-20T15:48:06Z")

</div>

Hi, I have a list of floats that I am passing to ES/Kibana through the Python API. I am able to see the document in Discover, and the list is visible there as expected. Now, I want to create a graph that iterates over …

---

## [How to Make Vega Visualization Scrollable in Kibana Dashboard for All Data?](https://discuss.elastic.co/t/how-to-make-vega-visualization-scrollable-in-kibana-dashboard-for-all-data/373408)

<div class="topic-metadata">

**Author:** [@Yokesh\_GK](https://discuss.elastic.co/u/Yokesh_GK)\
**Replies:** 2\
**Last updated:** [January 20, 2025, 3:13pm UTC](https://discuss.elastic.co/t/how-to-make-vega-visualization-scrollable-in-kibana-dashboard-for-all-data/373408 "2025-01-20T15:13:04Z")

</div>

Hi everyone, I'm using Vega to create a table visualization in Kibana. The issue I'm facing is that the table only shows data up to the height of the visualization. If I expand the visualization panel, more rows become …

---

## [Kibana security must be enabled to use Fleet](https://discuss.elastic.co/t/kibana-security-must-be-enabled-to-use-fleet/372628)

<div class="topic-metadata">

**Author:** [@aalaskapedh](https://discuss.elastic.co/u/aalaskapedh)\
**Replies:** 1\
**Last updated:** [January 20, 2025, 3:11pm UTC](https://discuss.elastic.co/t/kibana-security-must-be-enabled-to-use-fleet/372628 "2025-01-20T15:11:38Z")

</div>

Dec 30 22:33:17 master kibana\[2375\]: \[2024-12-30T22:33:17.627+05:45\]\[INFO \] \[plugins.fleet.fleet\_authz\_router\] Kibana security must be enabled to use Fleet This is the error that I have been getting When I attempt t…

---

## [Fleet server cannot display offline elastic agent](https://discuss.elastic.co/t/fleet-server-cannot-display-offline-elastic-agent/373390)

<div class="topic-metadata">

**Author:** [@ym2011](https://discuss.elastic.co/u/ym2011)\
**Replies:** 2\
**Last updated:** [January 20, 2025, 3:02pm UTC](https://discuss.elastic.co/t/fleet-server-cannot-display-offline-elastic-agent/373390 "2025-01-20T15:02:43Z")

</div>

The versions both of elasticsearch, kibana, elastic -agent and fleet server are 8.16.1. The fleet server in kibana warn：\_hit$\_source4.components.map is not a function when i check the offline agent. what is the prob…

---

## [New Kibana install but "urlForwarding" error after login](https://discuss.elastic.co/t/new-kibana-install-but-urlforwarding-error-after-login/365310)

<div class="topic-metadata">

**Author:** [@ivanlawrence](https://discuss.elastic.co/u/ivanlawrence)\
**Replies:** 3\
**Last updated:** [January 18, 2025, 10:29am UTC](https://discuss.elastic.co/t/new-kibana-install-but-urlforwarding-error-after-login/365310 "2025-01-18T10:29:48Z")

</div>

After following the ELK demo install I can login but get a page with an error Version: 8.15.0 Build: 76360 Error: Definition of plugin "urlForwarding" not found and may have failed to load. at https://\<mydomain\>/kib…

---

## [No doc count in destination index of transform](https://discuss.elastic.co/t/no-doc-count-in-destination-index-of-transform/373284)

<div class="topic-metadata">

**Author:** [@sintim](https://discuss.elastic.co/u/sintim)\
**Replies:** 3\
**Last updated:** [January 17, 2025, 2:00pm UTC](https://discuss.elastic.co/t/no-doc-count-in-destination-index-of-transform/373284 "2025-01-17T14:00:27Z")

</div>

I created a transform on ELK and it is up and HEALTHY but till now there's still no documents in the destination index for a data view. It's been about 6 hours. Is that supposed to be normal? or if not how can I check if…

---

## [Kibana Lens Table: Filter Table Rows](https://discuss.elastic.co/t/kibana-lens-table-filter-table-rows/373286)

<div class="topic-metadata">

**Author:** [@lavaplanet](https://discuss.elastic.co/u/lavaplanet)\
**Replies:** 3\
**Last updated:** [January 17, 2025, 8:44am UTC](https://discuss.elastic.co/t/kibana-lens-table-filter-table-rows/373286 "2025-01-17T08:44:02Z")

</div>

Hi there, I want to create a Kibana lens table where the rows are divided based on field values. However, I want to filter the individual rows by specific values. I only want to see all rows starting with Keyword\_Aor…

---

## [ES|QL : Adding Days to a Date](https://discuss.elastic.co/t/es-ql-adding-days-to-a-date/373288)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [January 16, 2025, 9:02pm UTC](https://discuss.elastic.co/t/es-ql-adding-days-to-a-date/373288 "2025-01-16T21:02:29Z")

</div>

Hello, I was wondering if its possible with ES|QL to use a date field and add x amount of days to create a new date field. Or would a runtime field work for this? Or would an ingest pipeline be the only solution. Tha…

---

## [Kibana Anomaly Alerts by PartitionField](https://discuss.elastic.co/t/kibana-anomaly-alerts-by-partitionfield/373133)

<div class="topic-metadata">

**Author:** [@jlrivera81](https://discuss.elastic.co/u/jlrivera81)\
**Replies:** 3\
**Last updated:** [January 16, 2025, 6:09pm UTC](https://discuss.elastic.co/t/kibana-anomaly-alerts-by-partitionfield/373133 "2025-01-16T18:09:21Z")

</div>

I currently have a working anomaly detection job for which i have configured my detector as: high\_count over Supervisor.routine.name partitionfield=Supervisor.resource.type For my alerts, I'd like to get an alert for t…

---

## [How to push old missing logs using filebeat so that it is reflecting in kibana](https://discuss.elastic.co/t/how-to-push-old-missing-logs-using-filebeat-so-that-it-is-reflecting-in-kibana/373289)

<div class="topic-metadata">

**Author:** [@jhankar\_jhankar](https://discuss.elastic.co/u/jhankar_jhankar)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 5:51pm UTC](https://discuss.elastic.co/t/how-to-push-old-missing-logs-using-filebeat-so-that-it-is-reflecting-in-kibana/373289 "2025-01-16T17:51:19Z")

</div>

Hello everyone, I’ve been using Elasticsearch, Kibana, and Filebeat to monitor application logs. However, for the past couple of weeks, my Elasticsearch instance was down, so application logs were not being pushed to Ki…

---

## [Elasticsearch query - subject line for email](https://discuss.elastic.co/t/elasticsearch-query-subject-line-for-email/373237)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [January 16, 2025, 3:27pm UTC](https://discuss.elastic.co/t/elasticsearch-query-subject-line-for-email/373237 "2025-01-16T15:27:37Z")

</div>

Hello, I used to be able to add the grouped by field in the subject line under {{context.group}}. Did something change? Is there another field I can use? Kibana/ES: 8.16.1

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=24)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=26)
