# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=33

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 34

---

## [Apply Label Template in URL format for field not null](https://discuss.elastic.co/t/apply-label-template-in-url-format-for-field-not-null/369783)

<div class="topic-metadata">

**Author:** [@trungyutu](https://discuss.elastic.co/u/trungyutu)\
**Replies:** 2\
**Last updated:** [October 30, 2024, 7:17am UTC](https://discuss.elastic.co/t/apply-label-template-in-url-format-for-field-not-null/369783 "2024-10-30T07:17:35Z")

</div>

Hi, I have a field name Issue Link which contain either a url or empty. My url is quite long so i want to shorter it, i use Url format in data view and set custom label to "Bug". And the output in kibana: It also …

---

## [Rule Recovery Functionality](https://discuss.elastic.co/t/rule-recovery-functionality/369771)

<div class="topic-metadata">

**Author:** [@jeffabar](https://discuss.elastic.co/u/jeffabar)\
**Replies:** 0\
**Last updated:** [October 29, 2024, 10:55pm UTC](https://discuss.elastic.co/t/rule-recovery-functionality/369771 "2024-10-29T22:55:23Z")

</div>

I have a DSL query which finds the latest record grouped by a field Module and if that latest record has another field unexpected\_state set to true it matches. I have the rule set for "FOR THE LAST 5 minutes" and it run…

---

## [Kibana - Phone Format](https://discuss.elastic.co/t/kibana-phone-format/369734)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [October 29, 2024, 1:30pm UTC](https://discuss.elastic.co/t/kibana-phone-format/369734 "2024-10-29T13:30:48Z")

</div>

Hello is there a way to format a keyword into a phone number? For example I have: 2221110000 But I would want something like this 222-111-0000

---

## [How to use Kibana export API?](https://discuss.elastic.co/t/how-to-use-kibana-export-api/369717)

<div class="topic-metadata">

**Author:** [@nakb](https://discuss.elastic.co/u/nakb)\
**Replies:** 0\
**Last updated:** [October 29, 2024, 11:38am UTC](https://discuss.elastic.co/t/how-to-use-kibana-export-api/369717 "2024-10-29T11:38:53Z")

</div>

I am using Kibana export API to get the rule in dev tools, but it's throwing error. { "statusCode": 400, "error": "Bad Request", "message": "Trying to export object(s) with non-exportable types: rule:5f598262-6916…

---

## [Count of a particular value is different in dicover and in visulisation specially in line chart](https://discuss.elastic.co/t/count-of-a-particular-value-is-different-in-dicover-and-in-visulisation-specially-in-line-chart/369714)

<div class="topic-metadata">

**Author:** [@aman\_kumar4](https://discuss.elastic.co/u/aman_kumar4)\
**Replies:** 0\
**Last updated:** [October 29, 2024, 10:20am UTC](https://discuss.elastic.co/t/count-of-a-particular-value-is-different-in-dicover-and-in-visulisation-specially-in-line-chart/369714 "2024-10-29T10:20:29Z")

</div>

I'm using split processor that separate on the basis of "/' (light/moon) and create a new field that is a basically simple values like "sun" and arrays like \[light, bulb, sun\] type now the problem is lets suppose the fi…

---

## [Kibana not starting after upgrade to version 15.3](https://discuss.elastic.co/t/kibana-not-starting-after-upgrade-to-version-15-3/369472)

<div class="topic-metadata">

**Author:** [@alrubaa](https://discuss.elastic.co/u/alrubaa)\
**Replies:** 1\
**Last updated:** [October 28, 2024, 5:57pm UTC](https://discuss.elastic.co/t/kibana-not-starting-after-upgrade-to-version-15-3/369472 "2024-10-28T17:57:28Z")

</div>

I am running a couple of Elastic clusters, both were running 8.13.2. Then I upgraded the larger cluster to version 15.3 using a rolling upgrade, switched all kibana nodes off and then upgraded kibana and all went well. T…

---

## [Plot time shift line from 4 previous week](https://discuss.elastic.co/t/plot-time-shift-line-from-4-previous-week/369297)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 1\
**Last updated:** [October 28, 2024, 3:15pm UTC](https://discuss.elastic.co/t/plot-time-shift-line-from-4-previous-week/369297 "2024-10-28T15:15:23Z")

</div>

Hello See my viz below: The shaded blue area is the count of 15 window time shifted 1 week ago Now I want the average count from 4 previous week. For example , the April 2 12:15pm: the green line is the cou…

---

## [How to populate each user ping directory deletion operations data in logging server](https://discuss.elastic.co/t/how-to-populate-each-user-ping-directory-deletion-operations-data-in-logging-server/369679)

<div class="topic-metadata">

**Author:** [@Subhasmita](https://discuss.elastic.co/u/Subhasmita)\
**Replies:** 0\
**Last updated:** [October 28, 2024, 2:30pm UTC](https://discuss.elastic.co/t/how-to-populate-each-user-ping-directory-deletion-operations-data-in-logging-server/369679 "2024-10-28T14:30:54Z")

</div>

How to populate each user ping directory deletion operations data in logging server.

---

## [Discover in kibana shows blank](https://discuss.elastic.co/t/discover-in-kibana-shows-blank/369457)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [October 28, 2024, 11:22am UTC](https://discuss.elastic.co/t/discover-in-kibana-shows-blank/369457 "2024-10-28T11:22:48Z")

</div>

This is how discover is showing, weird, until yesterday everything was fine. can see dshboards with visual but not doscover. When switching to different space then there its showing normal discover with data. Any su…

---

## [Importing data to Machine Learning](https://discuss.elastic.co/t/importing-data-to-machine-learning/369416)

<div class="topic-metadata">

**Author:** [@tapiojaa](https://discuss.elastic.co/u/tapiojaa)\
**Replies:** 2\
**Last updated:** [October 28, 2024, 9:58am UTC](https://discuss.elastic.co/t/importing-data-to-machine-learning/369416 "2024-10-28T09:58:23Z")

</div>

Hi, I'm studying Machine Learning and trying to import sample data to the Elasticsearch witch can be found here Machine-Learning-with-Elastic-Stack-Second-Edition/Chapter12 at main · PacktPublishing/Machine-Learning-wi…

---

## [Accessing Kibana using hostname](https://discuss.elastic.co/t/accessing-kibana-using-hostname/369520)

<div class="topic-metadata">

**Author:** [@jayjayy](https://discuss.elastic.co/u/jayjayy)\
**Replies:** 0\
**Last updated:** [October 28, 2024, 8:24am UTC](https://discuss.elastic.co/t/accessing-kibana-using-hostname/369520 "2024-10-28T08:24:35Z")

</div>

I have an ELK setup on Ubuntu and I am trying to access the Kibana Web through hostname. I can access Kibana with my IP address but not hostname despite setting the server.publicBaseUrl: "https://:5601". I am enable to…

---

## [Defender - Kibana Incidents Count](https://discuss.elastic.co/t/defender-kibana-incidents-count/369504)

<div class="topic-metadata">

**Author:** [@Sunny\_Sunny](https://discuss.elastic.co/u/Sunny_Sunny)\
**Replies:** 0\
**Last updated:** [October 28, 2024, 1:24am UTC](https://discuss.elastic.co/t/defender-kibana-incidents-count/369504 "2024-10-28T01:24:09Z")

</div>

I'm working on creating a visualization in Kibana that counts incidents by their m365\_defender.incident.alert.status. The statuses can be "new", "inProgress", or "resolved". However, I am encountering an issue where Kiba…

---

## [Alert Rules - doesn't seem to process query](https://discuss.elastic.co/t/alert-rules-doesnt-seem-to-process-query/369433)

<div class="topic-metadata">

**Author:** [@PhilA](https://discuss.elastic.co/u/PhilA)\
**Replies:** 2\
**Last updated:** [October 26, 2024, 5:45am UTC](https://discuss.elastic.co/t/alert-rules-doesnt-seem-to-process-query/369433 "2024-10-26T05:45:19Z")

</div>

Hi I have some basic alerts configured to alert when log sources stop sending. One example is monitoring logs from a number of firewalls; I simply want an alert if one fails to generate logs. I have created the follow…

---

## [Elasticsearch logs coming slow in index from file beat to logstash](https://discuss.elastic.co/t/elasticsearch-logs-coming-slow-in-index-from-file-beat-to-logstash/369420)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [October 25, 2024, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-logs-coming-slow-in-index-from-file-beat-to-logstash/369420 "2024-10-25T11:22:25Z")

</div>

Whenever I am doing Get \_cat/nodes from kibana getting this: stausCode:502, Error:”bad gateway”, “Message”: client request timeout” Also logs are coming in elastic index slow and in elastic logs it’s showing continuo…

---

## [ignoreFilterIfFieldNotInIndex does not work?](https://discuss.elastic.co/t/ignorefilteriffieldnotinindex-does-not-work/369382)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 2\
**Last updated:** [October 25, 2024, 7:06pm UTC](https://discuss.elastic.co/t/ignorefilteriffieldnotinindex-does-not-work/369382 "2024-10-25T19:06:44Z")

</div>

Hi there! I enabled "ignoreFilterIfFieldNotInIndex" option in Kibana Advanced Settings, since I am using 2 data views and I would like to avoid filtering out documents if some field does not exist in the data view Howe…

---

## [Is it possible to hide the header and top menu on the reporting page in embedded mode?](https://discuss.elastic.co/t/is-it-possible-to-hide-the-header-and-top-menu-on-the-reporting-page-in-embedded-mode/369431)

<div class="topic-metadata">

**Author:** [@Serhii\_samoilenko](https://discuss.elastic.co/u/Serhii_samoilenko)\
**Replies:** 0\
**Last updated:** [October 25, 2024, 2:19pm UTC](https://discuss.elastic.co/t/is-it-possible-to-hide-the-header-and-top-menu-on-the-reporting-page-in-embedded-mode/369431 "2024-10-25T14:19:08Z")

</div>

Hi, I have shared a dashboard in embedded mode. This dashboard contains a saved search with the option to download a CSV report. After generating the CSV report, Kibana provides a link to the reporting page for downlo…

---

## [Kibana read-only role (8.15)](https://discuss.elastic.co/t/kibana-read-only-role-8-15/369377)

<div class="topic-metadata">

**Author:** [@jleroux1](https://discuss.elastic.co/u/jleroux1)\
**Replies:** 0\
**Last updated:** [October 24, 2024, 5:53pm UTC](https://discuss.elastic.co/t/kibana-read-only-role-8-15/369377 "2024-10-24T17:53:35Z")

</div>

I'm trying to to create a read-only role in kibana (8.15), and since the kibana\_user role is deprecated, and not really replaced with a new one. At the end In the documentation ' Required roles and privileges | Fleet an…

---

## [Adding Secure Remote Clusters (OpenSearch Security and X-Pack Enabled Elasticsearch) in Kibana](https://discuss.elastic.co/t/adding-secure-remote-clusters-opensearch-security-and-x-pack-enabled-elasticsearch-in-kibana/369319)

<div class="topic-metadata">

**Author:** [@ejox](https://discuss.elastic.co/u/ejox)\
**Replies:** 4\
**Last updated:** [October 24, 2024, 1:39pm UTC](https://discuss.elastic.co/t/adding-secure-remote-clusters-opensearch-security-and-x-pack-enabled-elasticsearch-in-kibana/369319 "2024-10-24T13:39:31Z")

</div>

Hey, We are reaching out to seek guidance and support for integrating secure remote clusters (e.g., OpenSearch Security and X-Pack enabled Elasticsearch) within Kibana Our goal is to seamlessly connect and visualize dat…

---

## [Trying to connect Kibana to Elasticsearch](https://discuss.elastic.co/t/trying-to-connect-kibana-to-elasticsearch/369273)

<div class="topic-metadata">

**Author:** [@summoner](https://discuss.elastic.co/u/summoner)\
**Replies:** 5\
**Last updated:** [October 24, 2024, 1:15pm UTC](https://discuss.elastic.co/t/trying-to-connect-kibana-to-elasticsearch/369273 "2024-10-24T13:15:27Z")

</div>

Hello again, I'm trying to connect my locally installed Kibana to a port-forwarded elastic instance (K8s pod), both are versions 7.7.0. I've already port forwarded the pod to port 9200, am met with this error: FATAL …

---

## [Apm logs (transactions) not showing in kibana](https://discuss.elastic.co/t/apm-logs-transactions-not-showing-in-kibana/369336)

<div class="topic-metadata">

**Author:** [@Karan-J\_g](https://discuss.elastic.co/u/Karan-J_g)\
**Replies:** 0\
**Last updated:** [October 24, 2024, 8:48am UTC](https://discuss.elastic.co/t/apm-logs-transactions-not-showing-in-kibana/369336 "2024-10-24T08:48:04Z")

</div>

Hi everyone, I'm encountering an issue with APM logs (transactions) not showing up in Kibana after upgrading from elastic-apm==6.10.1. My current setup includes: FastAPI Using \[elasticapm.capture\_span(...)\] to capture…

---

## [How to add textbox in data table for user comments](https://discuss.elastic.co/t/how-to-add-textbox-in-data-table-for-user-comments/369334)

<div class="topic-metadata">

**Author:** [@Sudheer\_Kumar](https://discuss.elastic.co/u/Sudheer_Kumar)\
**Replies:** 0\
**Last updated:** [October 24, 2024, 8:41am UTC](https://discuss.elastic.co/t/how-to-add-textbox-in-data-table-for-user-comments/369334 "2024-10-24T08:41:10Z")

</div>

Hi, I’m currently integrating ELK with our tools. For any reported issues, I need to add a textbox in each row of the data table in the Kibana dashboard for users to comment, acknowledge, or share the status. Could you …

---

## [Unable to add two or more Elasticsearch index for each layer in Kibana Vega-lite visualization](https://discuss.elastic.co/t/unable-to-add-two-or-more-elasticsearch-index-for-each-layer-in-kibana-vega-lite-visualization/369322)

<div class="topic-metadata">

**Author:** [@Anandhu\_R\_K](https://discuss.elastic.co/u/Anandhu_R_K)\
**Replies:** 0\
**Last updated:** [October 24, 2024, 6:20am UTC](https://discuss.elastic.co/t/unable-to-add-two-or-more-elasticsearch-index-for-each-layer-in-kibana-vega-lite-visualization/369322 "2024-10-24T06:20:50Z")

</div>

Hi, I am trying to create a custom ,multi-layered visualization in Kibana using Vega-lite. I was able to create the spec for my first two layers sharing the same data source( My 1st Elasticsearch Index). While I was t…

---

## [Yarn kbn bootstrap fails， A few "Permission denied" errors occurred！](https://discuss.elastic.co/t/yarn-kbn-bootstrap-fails-a-few-permission-denied-errors-occurred/366866)

<div class="topic-metadata">

**Author:** [@hash-yang](https://discuss.elastic.co/u/hash-yang)\
**Replies:** 2\
**Last updated:** [October 23, 2024, 9:53pm UTC](https://discuss.elastic.co/t/yarn-kbn-bootstrap-fails-a-few-permission-denied-errors-occurred/366866 "2024-10-23T21:53:15Z")

</div>

hi, i fork the kibana respository and pull it from GitHub,and then try to build kibana on windows10 with WSL2. I referred to the document : Kibana Guide.(8.15). My environment： Linux WIN-20230627BHI 5.15.153.1-microso…

---

## [Kibana getting hanged, and getting Wait response or Kill page](https://discuss.elastic.co/t/kibana-getting-hanged-and-getting-wait-response-or-kill-page/369194)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 4\
**Last updated:** [October 23, 2024, 6:27pm UTC](https://discuss.elastic.co/t/kibana-getting-hanged-and-getting-wait-response-or-kill-page/369194 "2024-10-23T18:27:25Z")

</div>

Hi Team, I am using 8.14 version of Kibana, and when I am trying to do changes in a LENS tabular dashboard, my dashboard is becoming too slow. Sometimes it even take 2-3 mins to load even loading data for last 4 hours …

---

## [Elasticsearch / Kibana tar.gz not available to download](https://discuss.elastic.co/t/elasticsearch-kibana-tar-gz-not-available-to-download/369268)

<div class="topic-metadata">

**Author:** [@ax-va](https://discuss.elastic.co/u/ax-va)\
**Replies:** 2\
**Last updated:** [October 23, 2024, 6:20pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-tar-gz-not-available-to-download/369268 "2024-10-23T18:20:25Z")

</div>

See pictures I come to these links from the pages Install Elasticsearch from archive on Linux or MacOS | Elasticsearch Guide \[8.15\] | Elastic -\> Download Elasticsearch Install Kibana from archive on Linux or mac…

---

## [URL visualizations](https://discuss.elastic.co/t/url-visualizations/369186)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [October 23, 2024, 2:39pm UTC](https://discuss.elastic.co/t/url-visualizations/369186 "2024-10-23T14:39:33Z")

</div>

Hello, I have created HTTP monitors in Synthetics. I want to add a way to monitor and visualize this on a custom dashboard. How would I go about it? I have several URLs and I don't want to drilldown based on url, I jus…

---

## [Delete Fleet Agent Policies via Dev Tools?](https://discuss.elastic.co/t/delete-fleet-agent-policies-via-dev-tools/369175)

<div class="topic-metadata">

**Author:** [@RedneckHutch](https://discuss.elastic.co/u/RedneckHutch)\
**Replies:** 2\
**Last updated:** [October 22, 2024, 5:34pm UTC](https://discuss.elastic.co/t/delete-fleet-agent-policies-via-dev-tools/369175 "2024-10-22T17:34:52Z")

</div>

Hey everyone! We are in the process of deploying a large number of agent policies, but recently decided to change multiple configurations about them. Since we are early on in our deployment, we would like to out right de…

---

## [Is there a way to create a dashboard and visualization via Kibana REST API in version 8.15.3?](https://discuss.elastic.co/t/is-there-a-way-to-create-a-dashboard-and-visualization-via-kibana-rest-api-in-version-8-15-3/369231)

<div class="topic-metadata">

**Author:** [@\_vk2](https://discuss.elastic.co/u/_vk2)\
**Replies:** 4\
**Last updated:** [October 22, 2024, 5:10pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-create-a-dashboard-and-visualization-via-kibana-rest-api-in-version-8-15-3/369231 "2024-10-22T17:10:23Z")

</div>

Is there a direct way to create a dashboard and visualization in Kibana using REST API? If not, why is that? If there is, could you give me an example please? Also, is there a way to fetch dashboard ids from Kibana using…

---

## [Scheduled Email Reports - No Watcher](https://discuss.elastic.co/t/scheduled-email-reports-no-watcher/369234)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 22, 2024, 2:32pm UTC](https://discuss.elastic.co/t/scheduled-email-reports-no-watcher/369234 "2024-10-22T14:32:24Z")

</div>

Hello, I know you can currently create a scheduled CSV report by using watcher. Is there any kind of update to create a scheduled report outside of watcher? Or perhaps move out of CSV's and have business reports?

---

## [Watcher - Actions](https://discuss.elastic.co/t/watcher-actions/369169)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [October 22, 2024, 1:50pm UTC](https://discuss.elastic.co/t/watcher-actions/369169 "2024-10-22T13:50:35Z")

</div>

Hello, If I have an ITSM ServiceNow Connector, can I use it in Watcher?

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=32)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=34)
