# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=29

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 30

---

## [Access nested fields in canvas markdown](https://discuss.elastic.co/t/access-nested-fields-in-canvas-markdown/371362)

<div class="topic-metadata">

**Author:** [@Stephen\_IAnson](https://discuss.elastic.co/u/Stephen_IAnson)\
**Replies:** 0\
**Last updated:** [December 3, 2024, 9:08am UTC](https://discuss.elastic.co/t/access-nested-fields-in-canvas-markdown/371362 "2024-12-03T09:08:47Z")

</div>

Hi, I'm able to use the text element on a canvas and use ES SQL to query to retrieve my document content. Basically I have a single 'health report' document from another source and I'd like to create a simple dashboard…

---

## [Kibana v.8.14.1 - Canvas Filters not getting applied to VEGA & VEGA panels getting refreshed back to 15mins in Canvas](https://discuss.elastic.co/t/kibana-v-8-14-1-canvas-filters-not-getting-applied-to-vega-vega-panels-getting-refreshed-back-to-15mins-in-canvas/371293)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 2\
**Last updated:** [December 3, 2024, 6:11am UTC](https://discuss.elastic.co/t/kibana-v-8-14-1-canvas-filters-not-getting-applied-to-vega-vega-panels-getting-refreshed-back-to-15mins-in-canvas/371293 "2024-12-03T06:11:47Z")

</div>

Hello Team, I am currently working on building a Canvas in Kibana (v8.14.1) and encountering the following challenges: When applying filters (Dropdown Select or Timefilter), they are not being applied to the VEGA visu…

---

## [Grouping similar fields but with different parents](https://discuss.elastic.co/t/grouping-similar-fields-but-with-different-parents/371339)

<div class="topic-metadata">

**Author:** [@CalvinHobbes](https://discuss.elastic.co/u/CalvinHobbes)\
**Replies:** 0\
**Last updated:** [December 2, 2024, 8:56pm UTC](https://discuss.elastic.co/t/grouping-similar-fields-but-with-different-parents/371339 "2024-12-02T20:56:49Z")

</div>

I am trying to group similar fields but from different parents: Is this possible in Lens? e.g. I have documents with: groupa.name groupb.name Can I group on the field name which should then include values from the pa…

---

## [Kibana Dashboard issue](https://discuss.elastic.co/t/kibana-dashboard-issue/371058)

<div class="topic-metadata">

**Author:** [@CM\_Liotta](https://discuss.elastic.co/u/CM_Liotta)\
**Replies:** 7\
**Last updated:** [December 2, 2024, 6:50pm UTC](https://discuss.elastic.co/t/kibana-dashboard-issue/371058 "2024-12-02T18:50:58Z")

</div>

Hello all, I am using a Lens to try and display the "Last value" of some data based on two included keys "processing" and "awaiting\_processing". I am using simple default formulas like last\_value(extra.processing) and …

---

## [Lens - Dotted Lines](https://discuss.elastic.co/t/lens-dotted-lines/371152)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 6\
**Last updated:** [December 2, 2024, 4:05pm UTC](https://discuss.elastic.co/t/lens-dotted-lines/371152 "2024-12-02T16:05:26Z")

</div>

Hello, I was wondering how I can create something like this: Where it just connects the points and creates like a cohesive dotted line. Is there a way I can just enable , if the data points are far apart make it a …

---

## [Combine two index in one using Kibana](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673)

<div class="topic-metadata">

**Author:** [@amity.nidhi](https://discuss.elastic.co/u/amity.nidhi)\
**Replies:** 9\
**Last updated:** [December 2, 2024, 2:46am UTC](https://discuss.elastic.co/t/combine-two-index-in-one-using-kibana/370673 "2024-12-02T02:46:15Z")

</div>

Hello, I have a requirement to combine two index in Elasticsearch on basis of below criteria - index1: Record1: {"service": "abc", "opened\_at":"2024-11-04T16:48:04.000Z","closed\_at":"2024-11-05T18:00:10.000Z") Record…

---

## [What approach should I take to visualize next-day user retention?](https://discuss.elastic.co/t/what-approach-should-i-take-to-visualize-next-day-user-retention/371263)

<div class="topic-metadata">

**Author:** [@NealJ](https://discuss.elastic.co/u/NealJ)\
**Replies:** 0\
**Last updated:** [November 30, 2024, 3:05pm UTC](https://discuss.elastic.co/t/what-approach-should-i-take-to-visualize-next-day-user-retention/371263 "2024-11-30T15:05:51Z")

</div>

Hello everyone, I’m new to Elastic, and I’d like to ask a question. In Analytics -\> Dashboard, when creating a visualization panel, how can I view the next-day user retention rate?Assume I have the following data: \`us…

---

## [Static Pie Chart](https://discuss.elastic.co/t/static-pie-chart/371202)

<div class="topic-metadata">

**Author:** [@Hannah\_J\_Swystun](https://discuss.elastic.co/u/Hannah_J_Swystun)\
**Replies:** 10\
**Last updated:** [November 29, 2024, 3:06pm UTC](https://discuss.elastic.co/t/static-pie-chart/371202 "2024-11-29T15:06:12Z")

</div>

Hi, I am using KIBANA 7.8.0 : Index type : app-YYYY-MM-DD which means an index is created every day Visualization : Pie Chart Data from a CSV files with logstash example : TIMESTAMP;APP1;PASSED;5.6 TIMESTAMP;APP2;PA…

---

## [Compare two logstash pipeline code and highlight differences](https://discuss.elastic.co/t/compare-two-logstash-pipeline-code-and-highlight-differences/371227)

<div class="topic-metadata">

**Author:** [@navya\_k](https://discuss.elastic.co/u/navya_k)\
**Replies:** 1\
**Last updated:** [November 29, 2024, 3:04pm UTC](https://discuss.elastic.co/t/compare-two-logstash-pipeline-code-and-highlight-differences/371227 "2024-11-29T15:04:19Z")

</div>

Hello Team, As part of my work has to compare two logstash pipelines. One pipeline in UAT and other one at PROD cluster. There is no sync of logstash pipelines between clusters. In the same there were near 15 to 20 logs…

---

## [Kibana dashboard for span metrics](https://discuss.elastic.co/t/kibana-dashboard-for-span-metrics/371229)

<div class="topic-metadata">

**Author:** [@Kenzi007220](https://discuss.elastic.co/u/Kenzi007220)\
**Replies:** 0\
**Last updated:** [November 29, 2024, 11:45am UTC](https://discuss.elastic.co/t/kibana-dashboard-for-span-metrics/371229 "2024-11-29T11:45:16Z")

</div>

Good day, we have, based on apm metrics, "time spent by span type" dashboard. Can you please provide a calculation or formula for this dashboard? We would like to have it also in grafana. Thanks in advance.

---

## [Need to calculate a single value event rate and visualize it](https://discuss.elastic.co/t/need-to-calculate-a-single-value-event-rate-and-visualize-it/371076)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 7\
**Last updated:** [November 29, 2024, 10:29am UTC](https://discuss.elastic.co/t/need-to-calculate-a-single-value-event-rate-and-visualize-it/371076 "2024-11-29T10:29:52Z")

</div>

I need to calculate the event rate and show it as a single value (metric). E.g. I've the following documents: Column 1 Column 2 Timestamp Data 1.2.2024 15:30 Event 1 1.2.2024 15:45 Event 2 2.2.2024 10:30 …

---

## [Is it possible to create a graph from a non array key/par object or transform it?](https://discuss.elastic.co/t/is-it-possible-to-create-a-graph-from-a-non-array-key-par-object-or-transform-it/371125)

<div class="topic-metadata">

**Author:** [@pontual](https://discuss.elastic.co/u/pontual)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 8:56am UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-graph-from-a-non-array-key-par-object-or-transform-it/371125 "2024-11-27T08:56:48Z")

</div>

Hi I'm using elastisearch 8.12 and I'm trying to create a graph that shows "the most used query string paramenters". I have a field in my index called "query" that has each possible value (query string paramenter) as a p…

---

## [Capturing Comprehensive Kibana Audit Logs for User Activities](https://discuss.elastic.co/t/capturing-comprehensive-kibana-audit-logs-for-user-activities/370954)

<div class="topic-metadata">

**Author:** [@Akarsh\_Shaw](https://discuss.elastic.co/u/Akarsh_Shaw)\
**Replies:** 8\
**Last updated:** [November 29, 2024, 6:09am UTC](https://discuss.elastic.co/t/capturing-comprehensive-kibana-audit-logs-for-user-activities/370954 "2024-11-29T06:09:47Z")

</div>

Hello Elastic Community, I am looking to implement comprehensive Kibana audit logging to monitor user activities effectively. Specifically, I want to capture the following events: User Login and Logout: I need to log …

---

## [Generating Reports via Watcher Issue](https://discuss.elastic.co/t/generating-reports-via-watcher-issue/371085)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [November 29, 2024, 2:09am UTC](https://discuss.elastic.co/t/generating-reports-via-watcher-issue/371085 "2024-11-29T02:09:40Z")

</div>

Hello, Not sure what's happening but I ran a watcher: { "trigger": { "schedule": { "interval": "1h" } }, "input": { "none": {} }, "condition": { "always": {} }, "actions": { "ema…

---

## [Calculation between two fields in two separate indexes](https://discuss.elastic.co/t/calculation-between-two-fields-in-two-separate-indexes/371182)

<div class="topic-metadata">

**Author:** [@ek9boy](https://discuss.elastic.co/u/ek9boy)\
**Replies:** 1\
**Last updated:** [November 29, 2024, 2:05am UTC](https://discuss.elastic.co/t/calculation-between-two-fields-in-two-separate-indexes/371182 "2024-11-29T02:05:18Z")

</div>

Hi, I have Index\_a: with an amount field I have Index\_b: with a threshold field Is there anyway to calculate the percentage of these fields within kibana itself?

---

## [Issue when trying to delete Agent Policy with Managed Package Policies](https://discuss.elastic.co/t/issue-when-trying-to-delete-agent-policy-with-managed-package-policies/371167)

<div class="topic-metadata">

**Author:** [@bradleysb](https://discuss.elastic.co/u/bradleysb)\
**Replies:** 0\
**Last updated:** [November 28, 2024, 7:36am UTC](https://discuss.elastic.co/t/issue-when-trying-to-delete-agent-policy-with-managed-package-policies/371167 "2024-11-28T07:36:00Z")

</div>

Hi community, We have a problem where we cannot delete a Agent Policy because it states that "Agent policy with managed package policies cannot be deleted". Context: We copied an existing Agent Policy with 33 integrat…

---

## [How to filter all data but the index names with jq in kibana: GET \_all/\_ilm/explain | jq](https://discuss.elastic.co/t/how-to-filter-all-data-but-the-index-names-with-jq-in-kibana-get-all-ilm-explain-jq/371092)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 5\
**Last updated:** [November 27, 2024, 7:16pm UTC](https://discuss.elastic.co/t/how-to-filter-all-data-but-the-index-names-with-jq-in-kibana-get-all-ilm-explain-jq/371092 "2024-11-27T19:16:39Z")

</div>

Hello, How to filter all data, but the index names with jq in kibana: GET \_all/\_ilm/explain | jq . Only the indexes with phase : cold.

---

## [Kibana Authentication attempt failed: UNEXPECTED\_SESSION\_ERROR](https://discuss.elastic.co/t/kibana-authentication-attempt-failed-unexpected-session-error/369920)

<div class="topic-metadata">

**Author:** [@seb\_l](https://discuss.elastic.co/u/seb_l)\
**Replies:** 3\
**Last updated:** [November 27, 2024, 1:51pm UTC](https://discuss.elastic.co/t/kibana-authentication-attempt-failed-unexpected-session-error/369920 "2024-11-27T13:51:39Z")

</div>

Hello! First time posting and i have been using the ELK stack for quite a while now. I've encountered an issue that i haven't found much about in the forums or elsewhere and it's related to the security when it comes t…

---

## [Problem: Kibana Dashboard Created with Terraform is Not Deleted by terraform destroy](https://discuss.elastic.co/t/problem-kibana-dashboard-created-with-terraform-is-not-deleted-by-terraform-destroy/371134)

<div class="topic-metadata">

**Author:** [@tachibana](https://discuss.elastic.co/u/tachibana)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 11:51am UTC](https://discuss.elastic.co/t/problem-kibana-dashboard-created-with-terraform-is-not-deleted-by-terraform-destroy/371134 "2024-11-27T11:51:48Z")

</div>

I have created a Kibana dashboard using Terraform, but the dashboard is not deleted when I execute terraform destroy. Could you provide guidance on how to resolve this issue or explain potential causes? I am referring t…

---

## [Kibana canvas with query and shape circle](https://discuss.elastic.co/t/kibana-canvas-with-query-and-shape-circle/371107)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 12:20am UTC](https://discuss.elastic.co/t/kibana-canvas-with-query-and-shape-circle/371107 "2024-11-27T00:20:32Z")

</div>

Hello, I would like to create a few dynamic circles based on the number of years that a user can input via filters esql for example - 2018, 2019, 2020, 2021, 2022 etc. Each of these years have values coming from elastic…

---

## [Elastick - alerting](https://discuss.elastic.co/t/elastick-alerting/364536)

<div class="topic-metadata">

**Author:** [@Martin\_Stepanik](https://discuss.elastic.co/u/Martin_Stepanik)\
**Replies:** 1\
**Last updated:** [November 26, 2024, 5:19pm UTC](https://discuss.elastic.co/t/elastick-alerting/364536 "2024-11-26T17:19:45Z")

</div>

Hello, I have an enterprise license within elastic. I have an O365 agent deployed that collects logs. I can view them using dashboards. How do I please set up the logs from O365 to go through the connector to Mail? If…

---

## [After upgrade to 8.15.2 - csv export not working](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 8\
**Last updated:** [November 26, 2024, 10:42am UTC](https://discuss.elastic.co/t/after-upgrade-to-8-15-2-csv-export-not-working/368902 "2024-11-26T10:42:09Z")

</div>

Hello All, I have saved search which i am trying to export to csv. But i got error: document\_parsing\_exception Caused by: illegal\_argument\_exception: Expected text at 1:623 but found START\_OBJECT Root causes: document…

---

## [I am trying to list all the spaces, dashboards and watchers present on the entire elasticsearch cluster](https://discuss.elastic.co/t/i-am-trying-to-list-all-the-spaces-dashboards-and-watchers-present-on-the-entire-elasticsearch-cluster/371052)

<div class="topic-metadata">

**Author:** [@Johnson\_will](https://discuss.elastic.co/u/Johnson_will)\
**Replies:** 2\
**Last updated:** [November 26, 2024, 3:28am UTC](https://discuss.elastic.co/t/i-am-trying-to-list-all-the-spaces-dashboards-and-watchers-present-on-the-entire-elasticsearch-cluster/371052 "2024-11-26T03:28:20Z")

</div>

I am using the below apis to get them GET /api/spaces/space POST /api/saved\_objects/\_bulk\_get All the above are giving 400, are they deprecated in v8.13.4 ?

---

## [Purpose of Time filter in Kibana](https://discuss.elastic.co/t/purpose-of-time-filter-in-kibana/370986)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [November 25, 2024, 9:16pm UTC](https://discuss.elastic.co/t/purpose-of-time-filter-in-kibana/370986 "2024-11-25T21:16:49Z")

</div>

Hi All, What is the significance of "Time filter" when setting up an index pattern or Data view? When setting it up it says Select a primary time field for use with the global time filter Thanks

---

## [Networkerror: error when attempting to fetch resource Kibana](https://discuss.elastic.co/t/networkerror-error-when-attempting-to-fetch-resource-kibana/370964)

<div class="topic-metadata">

**Author:** [@Darksin248](https://discuss.elastic.co/u/Darksin248)\
**Replies:** 7\
**Last updated:** [November 25, 2024, 5:32pm UTC](https://discuss.elastic.co/t/networkerror-error-when-attempting-to-fetch-resource-kibana/370964 "2024-11-25T17:32:01Z")

</div>

It’s to do with Kibana, I am trying to import three NDJSON files for dashboard visualisation as this is for network intrusion task. But it comes up with a network error, it’s having issues fetching the resources, I’ve ch…

---

## [How to include specific fields (columns) in Kibana Discover links in alert emails?](https://discuss.elastic.co/t/how-to-include-specific-fields-columns-in-kibana-discover-links-in-alert-emails/370958)

<div class="topic-metadata">

**Author:** [@Lapo](https://discuss.elastic.co/u/Lapo)\
**Replies:** 4\
**Last updated:** [November 25, 2024, 1:26pm UTC](https://discuss.elastic.co/t/how-to-include-specific-fields-columns-in-kibana-discover-links-in-alert-emails/370958 "2024-11-25T13:26:59Z")

</div>

Hi everyone, I'm using Kibana to set up alerts, and in my alert email templates, I include the {{context.link}} variable to provide a link to the Discover page. However, when clicking this link, I want specific fields l…

---

## [Share dashboards between Spaces issue](https://discuss.elastic.co/t/share-dashboards-between-spaces-issue/371026)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 1:16pm UTC](https://discuss.elastic.co/t/share-dashboards-between-spaces-issue/371026 "2024-11-25T13:16:51Z")

</div>

Hey there, I have updated my cluster to latest ES 8.16.1 and I was quite confident to be able to share a Dashboard or anything else between different Spaces. Currently, it seems I can share only Data View saved objects …

---

## [Autodiscover categorizes field as long but discover says it's unknown](https://discuss.elastic.co/t/autodiscover-categorizes-field-as-long-but-discover-says-its-unknown/370948)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 1\
**Last updated:** [November 25, 2024, 12:40pm UTC](https://discuss.elastic.co/t/autodiscover-categorizes-field-as-long-but-discover-says-its-unknown/370948 "2024-11-25T12:40:24Z")

</div>

Hi, I'm trying to ingest data and use auto discovery. When I look at the mappings my field is discovered as long. I guess that this is ok as it's an integer. "ResolveTime": { "type": "long" }, But w…

---

## [How to create visualization of field values](https://discuss.elastic.co/t/how-to-create-visualization-of-field-values/370899)

<div class="topic-metadata">

**Author:** [@i.k](https://discuss.elastic.co/u/i.k)\
**Replies:** 2\
**Last updated:** [November 24, 2024, 4:20pm UTC](https://discuss.elastic.co/t/how-to-create-visualization-of-field-values/370899 "2024-11-24T16:20:55Z")

</div>

Hi there, I’m new to the platform, and I’m already pulling my hair out over what should be a ridiculously simple task—yet I can’t figure it out. Something as basic as visualizing field values seems completely elusive. H…

---

## [How to View In Context using Logs Explorer?](https://discuss.elastic.co/t/how-to-view-in-context-using-logs-explorer/370993)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 0\
**Last updated:** [November 24, 2024, 10:59am UTC](https://discuss.elastic.co/t/how-to-view-in-context-using-logs-explorer/370993 "2024-11-24T10:59:26Z")

</div>

Hi, it seems like Logs Stream is disabled by default in Kibana 8.16. If it is going away in future release, how can we View In Context using Logs Explorer? Thanks.

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=28)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=30)
