# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=34

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 35

---

## [Alerting based on different data sources](https://discuss.elastic.co/t/alerting-based-on-different-data-sources/369187)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [October 22, 2024, 1:45pm UTC](https://discuss.elastic.co/t/alerting-based-on-different-data-sources/369187 "2024-10-22T13:45:48Z")

</div>

Hello, How can I alert based on conditions across a variety of different data sources. For example, I want to be alert if log.level: error x 3 from logs-\* AND system.filesystem.used.pct \>= 80% from metrics-\* Thanks,

---

## [Open Dashboard by Title](https://discuss.elastic.co/t/open-dashboard-by-title/369223)

<div class="topic-metadata">

**Author:** [@DrMxxxxx](https://discuss.elastic.co/u/DrMxxxxx)\
**Replies:** 0\
**Last updated:** [October 22, 2024, 12:46pm UTC](https://discuss.elastic.co/t/open-dashboard-by-title/369223 "2024-10-22T12:46:08Z")

</div>

Hey there, in my Dashboards I use links within Markdown and Runtime fields. These Links are pointing to the Dashboard IDs. However, when I now copy these Dashboards to another space, these IDs change to a new random va…

---

## [Workaround for Dashboard short Share Link on Kibana v8.15.1](https://discuss.elastic.co/t/workaround-for-dashboard-short-share-link-on-kibana-v8-15-1/368061)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 6\
**Last updated:** [October 22, 2024, 5:41am UTC](https://discuss.elastic.co/t/workaround-for-dashboard-short-share-link-on-kibana-v8-15-1/368061 "2024-10-22T05:41:42Z")

</div>

Hi everyone, Since Kibana v8.15 and of course in v8.15.1 the Dashboard short Share Link doesn't work as expected, one user opened an issue, although has been improved. Is there a workaround to get in Kibana v8.15.1 Das…

---

## [Dashboard drilldown option not showing in Kibana 7.10.1](https://discuss.elastic.co/t/dashboard-drilldown-option-not-showing-in-kibana-7-10-1/368915)

<div class="topic-metadata">

**Author:** [@audioman](https://discuss.elastic.co/u/audioman)\
**Replies:** 4\
**Last updated:** [October 22, 2024, 1:37am UTC](https://discuss.elastic.co/t/dashboard-drilldown-option-not-showing-in-kibana-7-10-1/368915 "2024-10-22T01:37:25Z")

</div>

Hi Team, I'm trying to create some dashboard drilldown from a pie chart, but unfortunately I can't find the "Create drilldown" option. Am I doing something wrong? I'm new to Kibana, so please let me know what I'm do…

---

## [Kibana Dashboard - Navigation Tips](https://discuss.elastic.co/t/kibana-dashboard-navigation-tips/367194)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [October 21, 2024, 9:32pm UTC](https://discuss.elastic.co/t/kibana-dashboard-navigation-tips/367194 "2024-10-21T21:32:00Z")

</div>

Hello, I was wondering how people navigate in elastic with custom dashboards? Do people normally rely on Dashboards UI to find their unrelated dashboards? The main reason I ask is that I find myself creating to many l…

---

## [Return distinct values of a field in an alert](https://discuss.elastic.co/t/return-distinct-values-of-a-field-in-an-alert/368945)

<div class="topic-metadata">

**Author:** [@Austin\_R](https://discuss.elastic.co/u/Austin_R)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 8:18pm UTC](https://discuss.elastic.co/t/return-distinct-values-of-a-field-in-an-alert/368945 "2024-10-16T20:18:05Z")

</div>

I've created an alert that returns the results I'm looking for, but I want to return only one event per unique id field. I've tried a couple different things, but neither of them have worked for me so far. Using Query D…

---

## [Log Alerts - Latest Events](https://discuss.elastic.co/t/log-alerts-latest-events/369173)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 21, 2024, 5:50pm UTC](https://discuss.elastic.co/t/log-alerts-latest-events/369173 "2024-10-21T17:50:15Z")

</div>

How can I create a alert that checks for the last events? For example I might collect 36 documents of the same event but the timestamp is different. I don't really care about the all the events because it might create s…

---

## [Kibana - minimum time interval](https://discuss.elastic.co/t/kibana-minimum-time-interval/369009)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [October 21, 2024, 5:18pm UTC](https://discuss.elastic.co/t/kibana-minimum-time-interval/369009 "2024-10-21T17:18:45Z")

</div>

How do I setup lens to do fixed time interval aggregation? when I do 15 min minimum interval it work for short timeframe like 24 hour window but when I select larger window it goes back to auto. is there way we can fixe…

---

## [elasticsearch error: /usr/local/bin/docker-entrypoint.sh: cannot create temp file for here-document: Permission denied](https://discuss.elastic.co/t/elasticsearch-error-usr-local-bin-docker-entrypoint-sh-cannot-create-temp-file-for-here-document-permission-denied/365192)

<div class="topic-metadata">

**Author:** [@gomgom](https://discuss.elastic.co/u/gomgom)\
**Replies:** 1\
**Last updated:** [October 21, 2024, 7:14am UTC](https://discuss.elastic.co/t/elasticsearch-error-usr-local-bin-docker-entrypoint-sh-cannot-create-temp-file-for-here-document-permission-denied/365192 "2024-10-21T07:14:51Z")

</div>

I am new to elasticsearch and i want to install ELK on my linux local server using docker compose method. I took the .env and docker-compose files from the following url: \[elasticsearch/docs/reference/setup/install/dock…

---

## [Self-signed certificate in certificate chain](https://discuss.elastic.co/t/self-signed-certificate-in-certificate-chain/368976)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 2\
**Last updated:** [October 21, 2024, 3:14am UTC](https://discuss.elastic.co/t/self-signed-certificate-in-certificate-chain/368976 "2024-10-21T03:14:06Z")

</div>

Im having trouble running secure kibana on linux, i keep getting the below error : \[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. self-signed certificate in certificate c…

---

## [Can I able to ignore Duplicate match it is effecting on entire relevance score](https://discuss.elastic.co/t/can-i-able-to-ignore-duplicate-match-it-is-effecting-on-entire-relevance-score/369088)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [October 19, 2024, 5:00am UTC](https://discuss.elastic.co/t/can-i-able-to-ignore-duplicate-match-it-is-effecting-on-entire-relevance-score/369088 "2024-10-19T05:00:42Z")

</div>

Hello, When I perform a querying on Elasticsearch the duplicate matches also take score by Inverse Document Frequency and come top of the results. Can I ignore the duplicate matching. top document, "highlight": { …

---

## [Bandwith Utilization - SNMP Interface](https://discuss.elastic.co/t/bandwith-utilization-snmp-interface/369080)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 18, 2024, 5:57pm UTC](https://discuss.elastic.co/t/bandwith-utilization-snmp-interface/369080 "2024-10-18T17:57:05Z")

</div>

Hello, How do I build a visualization to show the bandwith utilization of an interface. I am polling once every 1hour. My data looks like:

---

## [Localizing Kibana into Unsupported Languages](https://discuss.elastic.co/t/localizing-kibana-into-unsupported-languages/369062)

<div class="topic-metadata">

**Author:** [@avm-1](https://discuss.elastic.co/u/avm-1)\
**Replies:** 0\
**Last updated:** [October 18, 2024, 1:16pm UTC](https://discuss.elastic.co/t/localizing-kibana-into-unsupported-languages/369062 "2024-10-18T13:16:34Z")

</div>

Hello everyone! I'm running Kibana in Docker and looking for a way to fully localize it. I created a separate file ru-RU.json, added translations to it, made changes to kibana/x-pack/.i18nrc.json and kibana/node\_modules/…

---

## [Copy to dashboard dialog displays only 5 dashboards in dropdown](https://discuss.elastic.co/t/copy-to-dashboard-dialog-displays-only-5-dashboards-in-dropdown/369007)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 2\
**Last updated:** [October 18, 2024, 7:55am UTC](https://discuss.elastic.co/t/copy-to-dashboard-dialog-displays-only-5-dashboards-in-dropdown/369007 "2024-10-18T07:55:23Z")

</div>

Hello Elastic-Community, we experience a strange issue while copying a visualization panel to another existing dashboard. The dropdown list contains only 5 dashboards. And these dashboards are ones with the oldest chang…

---

## [Kibana iframe autoscroll issue](https://discuss.elastic.co/t/kibana-iframe-autoscroll-issue/369021)

<div class="topic-metadata">

**Author:** [@Ankit\_Guleria](https://discuss.elastic.co/u/Ankit_Guleria)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 5:51pm UTC](https://discuss.elastic.co/t/kibana-iframe-autoscroll-issue/369021 "2024-10-17T17:51:42Z")

</div>

Hi, I am using kibana iframe in a lengthy web page and due to some autofocus issue the page is scrolling down to kibana iframe. I have tried js query or other things to resolve it but I am back to bottom of the page. …

---

## [Problem with map visual](https://discuss.elastic.co/t/problem-with-map-visual/368849)

<div class="topic-metadata">

**Author:** [@HermannSamimi](https://discuss.elastic.co/u/HermannSamimi)\
**Replies:** 5\
**Last updated:** [October 17, 2024, 1:23pm UTC](https://discuss.elastic.co/t/problem-with-map-visual/368849 "2024-10-17T13:23:32Z")

</div>

Hello, I have a problem with map visual while i create some points in the map in Kibana, After a refreshment, The map went failed to show the points.\[Error message: Unable to create layer\]

---

## [(Video)-Tutorials of old Kibana-Versions](https://discuss.elastic.co/t/video-tutorials-of-old-kibana-versions/368993)

<div class="topic-metadata">

**Author:** [@firen](https://discuss.elastic.co/u/firen)\
**Replies:** 1\
**Last updated:** [October 17, 2024, 12:48pm UTC](https://discuss.elastic.co/t/video-tutorials-of-old-kibana-versions/368993 "2024-10-17T12:48:07Z")

</div>

Hello, are there any (video-)tutorials for very old Kibana versions? We have 6.8. Regards

---

## [Is it possible to hide “Open in Discover” for a saved search in the embedded view of a Kibana dashboard?](https://discuss.elastic.co/t/is-it-possible-to-hide-open-in-discover-for-a-saved-search-in-the-embedded-view-of-a-kibana-dashboard/368925)

<div class="topic-metadata">

**Author:** [@Serhii\_samoilenko](https://discuss.elastic.co/u/Serhii_samoilenko)\
**Replies:** 2\
**Last updated:** [October 17, 2024, 10:40am UTC](https://discuss.elastic.co/t/is-it-possible-to-hide-open-in-discover-for-a-saved-search-in-the-embedded-view-of-a-kibana-dashboard/368925 "2024-10-17T10:40:18Z")

</div>

Hi, I’m embedding a Kibana dashboard that contains a saved search, but I’d like to hide or remove the “Open in Discover” link when the dashboard is viewed in embedded mode. Is there a way to achieve this through Kib…

---

## [How to apply range using calculated metric field](https://discuss.elastic.co/t/how-to-apply-range-using-calculated-metric-field/368846)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 6\
**Last updated:** [October 17, 2024, 9:27am UTC](https://discuss.elastic.co/t/how-to-apply-range-using-calculated-metric-field/368846 "2024-10-17T09:27:09Z")

</div>

I wanted to create the buckets for the total sales on the basis of the calculated value form metric aggs in lens i have total field in doc so if use agg of avg in lens then i want to create the range built on top of th…

---

## [Cant see option Grant read privileges to specific documents in kibana v 7.17.1](https://discuss.elastic.co/t/cant-see-option-grant-read-privileges-to-specific-documents-in-kibana-v-7-17-1/368982)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 8:25am UTC](https://discuss.elastic.co/t/cant-see-option-grant-read-privileges-to-specific-documents-in-kibana-v-7-17-1/368982 "2024-10-17T08:25:07Z")

</div>

hi all, i cant see option Grant read privileges to specific documents in kibana v 7.17.1. inside apm services.. i want a specific user to see specific service, not all. And if this not then any other solution? i am us…

---

## [Nested object logstash not parsing correctlly](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 6\
**Last updated:** [October 17, 2024, 8:11am UTC](https://discuss.elastic.co/t/nested-object-logstash-not-parsing-correctlly/366762 "2024-10-17T08:11:59Z")

</div>

Hello , can u help me solve the issue. I have nested object "host" =\> { "name" =\> "myserver" } like below "cluster" =\> "xxx-logs", "name" =\> "xxx2", "component" =\> "xxx", \*\*"host" =\> {\*\* \*\* "n…

---

## [Multiple Aggregations/UI Filters are not applied in ES|QL Visualizations](https://discuss.elastic.co/t/multiple-aggregations-ui-filters-are-not-applied-in-es-ql-visualizations/368952)

<div class="topic-metadata">

**Author:** [@KibanaUser2247](https://discuss.elastic.co/u/KibanaUser2247)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 10:16pm UTC](https://discuss.elastic.co/t/multiple-aggregations-ui-filters-are-not-applied-in-es-ql-visualizations/368952 "2024-10-16T22:16:55Z")

</div>

I have an index that is of the form: | event | hall | date | average\_attendees | |---------|----------|------------|-------------------| | Event A | visitors | 2022-01-01 | 150 | | Event A | ma…

---

## [Integration field map error, how to fix temporarily](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [October 16, 2024, 3:53pm UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807 "2024-10-16T15:53:21Z")

</div>

In the Microsoft Exchange integration, message tracking, field relatedrecipeinetaddress is mapped as an IP, but it is really an email address. I've reported a bug, but until it's fixed, what is the best way to fix this? …

---

## [Where are logs for monitors (heartbeat?)](https://discuss.elastic.co/t/where-are-logs-for-monitors-heartbeat/368909)

<div class="topic-metadata">

**Author:** [@Dani\_Perez](https://discuss.elastic.co/u/Dani_Perez)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 12:59pm UTC](https://discuss.elastic.co/t/where-are-logs-for-monitors-heartbeat/368909 "2024-10-16T12:59:04Z")

</div>

Hi, I'm using the latest version of Elastic Cloud and despite having about 50 monitors configured I'm not able to find the index or datastream where the requests are saved, I think it is not there, shouldn't it be recre…

---

## [How to make now to be dynamic in the date \> now-1M](https://discuss.elastic.co/t/how-to-make-now-to-be-dynamic-in-the-date-now-1m/368847)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 7:29am UTC](https://discuss.elastic.co/t/how-to-make-now-to-be-dynamic-in-the-date-now-1m/368847 "2024-10-16T07:29:53Z")

</div>

i am trying to create last month sales lens where i have added the filter of the date \>= now-1M/M AND date \< now/M so lets i am in oct then i want to see sep sales. and if i change the end from above globla time filte…

---

## [Signals export failing frequently as more than 20 services are exporting signals to elk at the same time](https://discuss.elastic.co/t/signals-export-failing-frequently-as-more-than-20-services-are-exporting-signals-to-elk-at-the-same-time/365610)

<div class="topic-metadata">

**Author:** [@Harshul](https://discuss.elastic.co/u/Harshul)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 7:19am UTC](https://discuss.elastic.co/t/signals-export-failing-frequently-as-more-than-20-services-are-exporting-signals-to-elk-at-the-same-time/365610 "2024-10-16T07:19:36Z")

</div>

I'm currently working on a test project that involves multiple services implemented in Python, Java, React, and Node.js. These services utilize OpenTelemetry for observability. The architecture is designed such that: A…

---

## [Tagging - Correlating Between Datasets](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [October 15, 2024, 9:14pm UTC](https://discuss.elastic.co/t/tagging-correlating-between-datasets/368873 "2024-10-15T21:14:15Z")

</div>

Hello, I want to do something like add tags but to datasets. I know I can use an ingest pipeline and then apply it all ingest pipelines but this isn't practical as updates to tags can't be retroactive. Is it possible …

---

## [BUG: Wrong visualizations rendered when using buttons/links](https://discuss.elastic.co/t/bug-wrong-visualizations-rendered-when-using-buttons-links/368850)

<div class="topic-metadata">

**Author:** [@sacalata](https://discuss.elastic.co/u/sacalata)\
**Replies:** 1\
**Last updated:** [October 15, 2024, 1:44pm UTC](https://discuss.elastic.co/t/bug-wrong-visualizations-rendered-when-using-buttons-links/368850 "2024-10-15T13:44:02Z")

</div>

When using markdown buttons to other dashboards, like this: '\[Button Text\] (/s/project/app/dashboards#/view/dashboardId)' The wrong visualizations get loaded when you click the button, if it's dashboard X with a button…

---

## [I am trying to setup elk on docker, but it is not pulling data from my log file which already has data](https://discuss.elastic.co/t/i-am-trying-to-setup-elk-on-docker-but-it-is-not-pulling-data-from-my-log-file-which-already-has-data/368833)

<div class="topic-metadata">

**Author:** [@Manak\_Wadhwa](https://discuss.elastic.co/u/Manak_Wadhwa)\
**Replies:** 2\
**Last updated:** [October 15, 2024, 12:51pm UTC](https://discuss.elastic.co/t/i-am-trying-to-setup-elk-on-docker-but-it-is-not-pulling-data-from-my-log-file-which-already-has-data/368833 "2024-10-15T12:51:04Z")

</div>

This is my logstash config: input { file { path =\> \["/Users/newlap/Desktop/newap/Logs/service-logs.log"\] } } filter {} output { elasticsearch { index =\> "logs-%{+YYYY.MM.dd}" hosts =\> \["https://e…

---

## [Create CSV from (Lens) Table via API / URL](https://discuss.elastic.co/t/create-csv-from-lens-table-via-api-url/368754)

<div class="topic-metadata">

**Author:** [@bianca\_s](https://discuss.elastic.co/u/bianca_s)\
**Replies:** 4\
**Last updated:** [October 15, 2024, 12:38pm UTC](https://discuss.elastic.co/t/create-csv-from-lens-table-via-api-url/368754 "2024-10-15T12:38:48Z")

</div>

Hi all, I wonder if it is possible to create CSV reports from (Lens) tables via an API / URL? I couldn't find anything on that in the documentation. Some background on our use case: We would like to automatically send…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=33)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=35)
