# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=31

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 32

---

## [Alerting - Filter Query not working](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [November 15, 2024, 3:59pm UTC](https://discuss.elastic.co/t/alerting-filter-query-not-working/370612 "2024-11-15T15:59:55Z")

</div>

Hello, I was testing out the Metric Threshold to alert on disk usage. I want to exclude some hosts from the alert, but I seem to get this error

---

## [Line - Lens Issue](https://discuss.elastic.co/t/line-lens-issue/369301)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [November 15, 2024, 3:14pm UTC](https://discuss.elastic.co/t/line-lens-issue/369301 "2024-11-15T15:14:50Z")

</div>

Hello, we upgraded recently to 8.15.3 It looks like some line graphs changed to dots: why is that?

---

## [Self Managed - Solution View Release](https://discuss.elastic.co/t/self-managed-solution-view-release/370584)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [November 15, 2024, 3:09pm UTC](https://discuss.elastic.co/t/self-managed-solution-view-release/370584 "2024-11-15T15:09:45Z")

</div>

Hello, I understand that Solution Views are currently under Cloud-Hosted environments, but Self-Managed customers would love to use them. When can we expect to see this? Sorry, I am impatient. I just really like …

---

## [Drill Down with timestamps](https://discuss.elastic.co/t/drill-down-with-timestamps/361574)

<div class="topic-metadata">

**Author:** [@Madeline\_Nguyen](https://discuss.elastic.co/u/Madeline_Nguyen)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:29pm UTC](https://discuss.elastic.co/t/drill-down-with-timestamps/361574 "2024-11-15T14:29:46Z")

</div>

Greetings all, I'm doing some stuff with drill down topics and I have a requirement of making links from dashboard to data table that including the timestamp set on the dashboard too. Are there any possible solutions f…

---

## [Taking ratio of two series in TSVB](https://discuss.elastic.co/t/taking-ratio-of-two-series-in-tsvb/368256)

<div class="topic-metadata">

**Author:** [@smondal](https://discuss.elastic.co/u/smondal)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:17pm UTC](https://discuss.elastic.co/t/taking-ratio-of-two-series-in-tsvb/368256 "2024-11-15T14:17:37Z")

</div>

I am trying to create a line chart in TSVB which is the ratio of "Numerator" and "Denominator" defined as follows: Added a series called "Numerator" by first creating a metric with aggregation = "Cardinality" on a fiel…

---

## [Exporting visualisations' data](https://discuss.elastic.co/t/exporting-visualisations-data/366547)

<div class="topic-metadata">

**Author:** [@Nikita\_Vasyliev](https://discuss.elastic.co/u/Nikita_Vasyliev)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:16pm UTC](https://discuss.elastic.co/t/exporting-visualisations-data/366547 "2024-11-15T14:16:04Z")

</div>

Hi, I'm curious is there an automated way to get the data from the visualisation? Attaching the screenshot of what I mean My goal is to get the 'response' object of the Kibana visualisation in JSON/CSV format. I also…

---

## [Lens - Pie Legend Location](https://discuss.elastic.co/t/lens-pie-legend-location/363159)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:13pm UTC](https://discuss.elastic.co/t/lens-pie-legend-location/363159 "2024-11-15T14:13:01Z")

</div>

Hello, Wasn't there used to be an option on where you can place the legend? Seems to be gone? Kibana/Elasticsearch : 8.14.3

---

## [Styling specific elements in a Kibana dashboard](https://discuss.elastic.co/t/styling-specific-elements-in-a-kibana-dashboard/360532)

<div class="topic-metadata">

**Author:** [@Danyal\_Danish](https://discuss.elastic.co/u/Danyal_Danish)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:11pm UTC](https://discuss.elastic.co/t/styling-specific-elements-in-a-kibana-dashboard/360532 "2024-11-15T14:11:45Z")

</div>

Is there a way to change the styling of a Kibana dashboard, for example, changing the font color, size, weight, etc. of specific elements. Like we can do using CSS?

---

## [Moving average count based if greater than upper threshold then red color if moving avg count if lower threshold then blue color in kibana formula or vertical bar chart](https://discuss.elastic.co/t/moving-average-count-based-if-greater-than-upper-threshold-then-red-color-if-moving-avg-count-if-lower-threshold-then-blue-color-in-kibana-formula-or-vertical-bar-chart/359938)

<div class="topic-metadata">

**Author:** [@Ravisankar123](https://discuss.elastic.co/u/Ravisankar123)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:10pm UTC](https://discuss.elastic.co/t/moving-average-count-based-if-greater-than-upper-threshold-then-red-color-if-moving-avg-count-if-lower-threshold-then-blue-color-in-kibana-formula-or-vertical-bar-chart/359938 "2024-11-15T14:10:04Z")

</div>

Moving average count based if greater than upper threshold then red color if moving avg count if lower threshold then blue color in kibana formula or vertical bar chart in kibana

---

## [Kibana Visualization: average of the 99th percentile](https://discuss.elastic.co/t/kibana-visualization-average-of-the-99th-percentile/364663)

<div class="topic-metadata">

**Author:** [@Ehab\_Arman](https://discuss.elastic.co/u/Ehab_Arman)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:06pm UTC](https://discuss.elastic.co/t/kibana-visualization-average-of-the-99th-percentile/364663 "2024-11-15T14:06:49Z")

</div>

Hello Kibana experts, I am new to Elastic and been playing around with Kibana dashboard visualization. One thing I am trying to do is to create a dashboard to display the 99th percentile of total latency. What I expect…

---

## [Create new filters on an index](https://discuss.elastic.co/t/create-new-filters-on-an-index/364804)

<div class="topic-metadata">

**Author:** [@jaime\_solas](https://discuss.elastic.co/u/jaime_solas)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:05pm UTC](https://discuss.elastic.co/t/create-new-filters-on-an-index/364804 "2024-11-15T14:05:53Z")

</div>

I have done the ingestion from logstash for elastic, but I try to filter and I don't know how to do it, the ingestion has been based on an xml file like the following \<?xml version="1.0" encoding="UTF-8"?\>\<html xmlns="h…

---

## [Table aggregation](https://discuss.elastic.co/t/table-aggregation/370577)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 2:04pm UTC](https://discuss.elastic.co/t/table-aggregation/370577 "2024-11-15T14:04:53Z")

</div>

Hello! Here is the initial data: POST someindex/\_doc { "name": "Amsterdam", "documents": { "locations": \[ { "category": "aaa", "url": "https://aaa1.com" }, { "category"…

---

## [Visualisation challenge - not able to include documents without field](https://discuss.elastic.co/t/visualisation-challenge-not-able-to-include-documents-without-field/367156)

<div class="topic-metadata">

**Author:** [@Damir\_Ciganovic-Jank](https://discuss.elastic.co/u/Damir_Ciganovic-Jank)\
**Replies:** 1\
**Last updated:** [November 15, 2024, 1:13pm UTC](https://discuss.elastic.co/t/visualisation-challenge-not-able-to-include-documents-without-field/367156 "2024-11-15T13:13:44Z")

</div>

Hello, first time poster here so be gentle with me :slight\_smile: When creating a Visualisation (for example: Lens - Top Values), there is an option to pick a field and in "Advanced" section to check "Include documents …

---

## [Cannot connect to Kibana(no response)](https://discuss.elastic.co/t/cannot-connect-to-kibana-no-response/370585)

<div class="topic-metadata">

**Author:** [@chung](https://discuss.elastic.co/u/chung)\
**Replies:** 4\
**Last updated:** [November 15, 2024, 5:08am UTC](https://discuss.elastic.co/t/cannot-connect-to-kibana-no-response/370585 "2024-11-15T05:08:52Z")

</div>

I installed Elasticsearch 8.16 successfully ❯ curl localhost:9200 { "name" : "debian", "cluster\_name" : "elasticsearch", "cluster\_uuid" : "8bKtWy\_zTImqaRYnzC453g", "version" : { "number" : "8.16.0", "bui…

---

## [Error when accessing watcher execution results in ELK 8.15.0](https://discuss.elastic.co/t/error-when-accessing-watcher-execution-results-in-elk-8-15-0/370488)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [November 14, 2024, 6:15pm UTC](https://discuss.elastic.co/t/error-when-accessing-watcher-execution-results-in-elk-8-15-0/370488 "2024-11-14T18:15:00Z")

</div>

We are releasing to a customer soon and would like to know if there is a patch or workaround for this issue. In Kibana 18.15.0 and 8.15.3 Navigate to Stack Management -\> Watcher Under Watcher click Create and then "Cr…

---

## [Kibana dashboards not loading](https://discuss.elastic.co/t/kibana-dashboards-not-loading/370462)

<div class="topic-metadata">

**Author:** [@shay\_abergil](https://discuss.elastic.co/u/shay_abergil)\
**Replies:** 3\
**Last updated:** [November 14, 2024, 6:11pm UTC](https://discuss.elastic.co/t/kibana-dashboards-not-loading/370462 "2024-11-14T18:11:02Z")

</div>

Hey there, 2 of my dashboards stopped loading in the last few days without notable reason. The page layout and controllers do not load/respond and I can't edit the page or add new visualizations. The data view works w…

---

## [Help Needed: Converting Numeric Aggregation Output to Boolean ("Up"/"Down") in Watcher Email Template](https://discuss.elastic.co/t/help-needed-converting-numeric-aggregation-output-to-boolean-up-down-in-watcher-email-template/370512)

<div class="topic-metadata">

**Author:** [@Sathishkumar\_Kanda](https://discuss.elastic.co/u/Sathishkumar_Kanda)\
**Replies:** 1\
**Last updated:** [November 14, 2024, 2:34pm UTC](https://discuss.elastic.co/t/help-needed-converting-numeric-aggregation-output-to-boolean-up-down-in-watcher-email-template/370512 "2024-11-14T14:34:03Z")

</div>

I’m configuring a watcher and email action in Elasticsearch to monitor the health status of multiple services and send email notifications with the status. Specifically, I need the status to display as either "Up" or "Do…

---

## [How to set multi\_match default to phrase instead of best\_fields in Kibana?](https://discuss.elastic.co/t/how-to-set-multi-match-default-to-phrase-instead-of-best-fields-in-kibana/370555)

<div class="topic-metadata">

**Author:** [@Leonardo\_Santos](https://discuss.elastic.co/u/Leonardo_Santos)\
**Replies:** 0\
**Last updated:** [November 14, 2024, 1:24pm UTC](https://discuss.elastic.co/t/how-to-set-multi-match-default-to-phrase-instead-of-best-fields-in-kibana/370555 "2024-11-14T13:24:56Z")

</div>

Hi there, I've observed that most of my users are searching in Kibana with queries like my nice query, which expands to a multi\_match search with type: best\_fields, triggering separate searches for each token in the phr…

---

## [Elastic Dashboard](https://discuss.elastic.co/t/elastic-dashboard/370316)

<div class="topic-metadata">

**Author:** [@Rafael\_Vitor](https://discuss.elastic.co/u/Rafael_Vitor)\
**Replies:** 11\
**Last updated:** [November 14, 2024, 11:07am UTC](https://discuss.elastic.co/t/elastic-dashboard/370316 "2024-11-14T11:07:40Z")

</div>

I need to create a custom dashboard, I would like to do something within ELK like the image below.

---

## [Watcher Email CSV Issue](https://discuss.elastic.co/t/watcher-email-csv-issue/370174)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [November 13, 2024, 4:47pm UTC](https://discuss.elastic.co/t/watcher-email-csv-issue/370174 "2024-11-13T16:47:15Z")

</div>

Hello, I am on ES/Kibana 8.15.3 I attempted to create a watcher using the POST URL for saved searches. The issue is that its not working, its saying its an SSL Handshake exception: This is very confusing because K…

---

## [Disabled filter on a panel](https://discuss.elastic.co/t/disabled-filter-on-a-panel/370168)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 3\
**Last updated:** [November 13, 2024, 3:32pm UTC](https://discuss.elastic.co/t/disabled-filter-on-a-panel/370168 "2024-11-13T15:32:02Z")

</div>

This is related to a question I asked last year. I have a dashboard panel showing GC count (jvm.gc.count.) I have it broken down by labels.name, which is how I get separate counts for young and old GCs. However the le…

---

## [How to create a visualization based on a unique count of an IP field but excluding port number?](https://discuss.elastic.co/t/how-to-create-a-visualization-based-on-a-unique-count-of-an-ip-field-but-excluding-port-number/370470)

<div class="topic-metadata">

**Author:** [@Silvy20](https://discuss.elastic.co/u/Silvy20)\
**Replies:** 1\
**Last updated:** [November 13, 2024, 1:05pm UTC](https://discuss.elastic.co/t/how-to-create-a-visualization-based-on-a-unique-count-of-an-ip-field-but-excluding-port-number/370470 "2024-11-13T13:05:25Z")

</div>

Hello, I need to create a visualization based on unique count of IPs, however the field available in kibana is in the following format: xx.xx.xx.xx:xxxx I would like to know if through formulas (fe) I have a way to ca…

---

## [Unable to get incident types IBM Resilient Connector](https://discuss.elastic.co/t/unable-to-get-incident-types-ibm-resilient-connector/370469)

<div class="topic-metadata">

**Author:** [@Aliya\_Khalel](https://discuss.elastic.co/u/Aliya_Khalel)\
**Replies:** 0\
**Last updated:** [November 13, 2024, 10:20am UTC](https://discuss.elastic.co/t/unable-to-get-incident-types-ibm-resilient-connector/370469 "2024-11-13T10:20:44Z")

</div>

I/m trying to add action for alerting to IBM Resilient and getting error

---

## [How to create links using the values in visualization tooltips?](https://discuss.elastic.co/t/how-to-create-links-using-the-values-in-visualization-tooltips/370088)

<div class="topic-metadata">

**Author:** [@Santiago\_Carnicero](https://discuss.elastic.co/u/Santiago_Carnicero)\
**Replies:** 1\
**Last updated:** [November 13, 2024, 10:15am UTC](https://discuss.elastic.co/t/how-to-create-links-using-the-values-in-visualization-tooltips/370088 "2024-11-13T10:15:50Z")

</div>

Dear Elastic Team, In our data analytics setup using Elasticsearch, we utilize visualizations to analyze and present data insights. We’d like to know if it’s possible to format the fields displayed in tooltips within vi…

---

## [User,Roles and Role\_mapping import to new elastic version](https://discuss.elastic.co/t/user-roles-and-role-mapping-import-to-new-elastic-version/370134)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 12, 2024, 7:42pm UTC](https://discuss.elastic.co/t/user-roles-and-role-mapping-import-to-new-elastic-version/370134 "2024-11-12T19:42:04Z")

</div>

I am trying to upgrade elasticsearch 8.8.2 version to 8.14.3 and I would like to know how can I import user, role and role mapping in latest kibana 8.14.3 version from old one. Let me know some way other than snapshot. …

---

## [Same control for two data views](https://discuss.elastic.co/t/same-control-for-two-data-views/370430)

<div class="topic-metadata">

**Author:** [@juandres117](https://discuss.elastic.co/u/juandres117)\
**Replies:** 0\
**Last updated:** [November 12, 2024, 7:03pm UTC](https://discuss.elastic.co/t/same-control-for-two-data-views/370430 "2024-11-12T19:03:46Z")

</div>

Hi everyone! I am willing to create a control button like the ones that exist in Kibana but for 2 data views at the same time. For example, I have two different data views with the same variable called categories. I wan…

---

## [Kibana 7.17.25 on new aws r8g family instances](https://discuss.elastic.co/t/kibana-7-17-25-on-new-aws-r8g-family-instances/370382)

<div class="topic-metadata">

**Author:** [@Alisher\_Nabiev](https://discuss.elastic.co/u/Alisher_Nabiev)\
**Replies:** 1\
**Last updated:** [November 12, 2024, 6:53pm UTC](https://discuss.elastic.co/t/kibana-7-17-25-on-new-aws-r8g-family-instances/370382 "2024-11-12T18:53:19Z")

</div>

hi all, i am trying to install Kibana 7.17.25 on the r8g.2xlarge instance and I get a "core dump" error. " kibana.service: Start request repeated too quickly. kibana.service: Failed with result 'core-dump'. Failed t…

---

## [Regexp is not working](https://discuss.elastic.co/t/regexp-is-not-working/369971)

<div class="topic-metadata">

**Author:** [@GopalaKrishnan\_Rathi](https://discuss.elastic.co/u/GopalaKrishnan_Rathi)\
**Replies:** 4\
**Last updated:** [November 12, 2024, 6:03am UTC](https://discuss.elastic.co/t/regexp-is-not-working/369971 "2024-11-12T06:03:16Z")

</div>

Hello, I am trying filter the data from kibana elastic using below query. I need output - hain \[ like below mentioned, localhost:3000 10.42.10.112 - hain \[01/Nov/2024:18:20:05 +0000\] Kindly help me out. Below quer…

---

## [What is the headers.content\_length filed in kibans](https://discuss.elastic.co/t/what-is-the-headers-content-length-filed-in-kibans/369357)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 2\
**Last updated:** [November 12, 2024, 5:36am UTC](https://discuss.elastic.co/t/what-is-the-headers-content-length-filed-in-kibans/369357 "2024-11-12T05:36:55Z")

</div>

Hi, I am using logstash http input plugin to get the logs from application team. In kibana i am getting "headers.content\_length" field with numaric value. I did not get what is the exact meaning of "headers.content\_leng…

---

## [How to install heartbeat on Elastic cloud](https://discuss.elastic.co/t/how-to-install-heartbeat-on-elastic-cloud/370349)

<div class="topic-metadata">

**Author:** [@pdorcas](https://discuss.elastic.co/u/pdorcas)\
**Replies:** 1\
**Last updated:** [November 11, 2024, 8:55pm UTC](https://discuss.elastic.co/t/how-to-install-heartbeat-on-elastic-cloud/370349 "2024-11-11T20:55:37Z")

</div>

We are using the Elastic cloud and wish to install Heartbeat to monitor uptime. When we go to the Uptime app, it provides a button Add monitors with Heartbeat. Then when we click on it, it takes us to the installation …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=30)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=32)
