# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=35

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 36

---

## [How to achieve one dashboard multiple index pattern where ......?](https://discuss.elastic.co/t/how-to-achieve-one-dashboard-multiple-index-pattern-where/368848)

<div class="topic-metadata">

**Author:** [@Aman\_Muleva](https://discuss.elastic.co/u/Aman_Muleva)\
**Replies:** 0\
**Last updated:** [October 15, 2024, 12:01pm UTC](https://discuss.elastic.co/t/how-to-achieve-one-dashboard-multiple-index-pattern-where/368848 "2024-10-15T12:01:51Z")

</div>

how to achieve one dashboard multiple index pattern where i want each of my user to have an unique index pattern but i am automating the part of creating the index pattern and the data view creation but idk how to link t…

---

## [Is there any way to hide the port number between kibana and auditbeat?](https://discuss.elastic.co/t/is-there-any-way-to-hide-the-port-number-between-kibana-and-auditbeat/368824)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 0\
**Last updated:** [October 15, 2024, 7:42am UTC](https://discuss.elastic.co/t/is-there-any-way-to-hide-the-port-number-between-kibana-and-auditbeat/368824 "2024-10-15T07:42:06Z")

</div>

Hello all. I'am using SIEM in kibana and auditbeat on specific system. When I watch the network traffic with wireshark, they show the port number between kibana and auditbeat (port number: 5601) I want to hide the por…

---

## [How to Use Building Block Rules in the Main Rule?](https://discuss.elastic.co/t/how-to-use-building-block-rules-in-the-main-rule/368789)

<div class="topic-metadata">

**Author:** [@karakoz](https://discuss.elastic.co/u/karakoz)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 2:52pm UTC](https://discuss.elastic.co/t/how-to-use-building-block-rules-in-the-main-rule/368789 "2024-10-14T14:52:55Z")

</div>

Hello! I am creating a rule that should trigger when a process from the Building Block Rules list is created in a temporary directory. I have successfully created a Building Block rule, but I’m not sure how to reference…

---

## [Make kibana.alert.url clickable](https://discuss.elastic.co/t/make-kibana-alert-url-clickable/368760)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 9:35am UTC](https://discuss.elastic.co/t/make-kibana-alert-url-clickable/368760 "2024-10-14T09:35:12Z")

</div>

Is it possible to make kibana.alert.url column clickable in the Alerts? Thanks in advance.

---

## [Data Frame Analytics - ML Time Field](https://discuss.elastic.co/t/data-frame-analytics-ml-time-field/368555)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [October 14, 2024, 8:52am UTC](https://discuss.elastic.co/t/data-frame-analytics-ml-time-field/368555 "2024-10-14T08:52:01Z")

</div>

Hello, I a bit confused why I am getting this Error, IF it asked for a time field : I

---

## [Integrations doesn't get populated for agent policy under fleet server](https://discuss.elastic.co/t/integrations-doesnt-get-populated-for-agent-policy-under-fleet-server/365788)

<div class="topic-metadata">

**Author:** [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Replies:** 1\
**Last updated:** [October 14, 2024, 7:46am UTC](https://discuss.elastic.co/t/integrations-doesnt-get-populated-for-agent-policy-under-fleet-server/365788 "2024-10-14T07:46:38Z")

</div>

Hello All, I am trying create a fleet policy with integration, however, when click on integration it keeps loading and throws an error at the end. I check kibana logs and it shows below error {"service":{"node":{"role…

---

## [Increase document limit/sample size in Discover?](https://discuss.elastic.co/t/increase-document-limit-sample-size-in-discover/367268)

<div class="topic-metadata">

**Author:** [@juarrow](https://discuss.elastic.co/u/juarrow)\
**Replies:** 3\
**Last updated:** [October 14, 2024, 5:52am UTC](https://discuss.elastic.co/t/increase-document-limit-sample-size-in-discover/367268 "2024-10-14T05:52:32Z")

</div>

How do I overcome the "Document count is based on smaller..."-limitation in Kibana's Discover (without Dashboard)? It seems to have a hard limit on 5000 documents taken into account. (My date range is set to max; there…

---

## [Getting issue while starting kibana](https://discuss.elastic.co/t/getting-issue-while-starting-kibana/368693)

<div class="topic-metadata">

**Author:** [@pranchalm](https://discuss.elastic.co/u/pranchalm)\
**Replies:** 9\
**Last updated:** [October 14, 2024, 12:15am UTC](https://discuss.elastic.co/t/getting-issue-while-starting-kibana/368693 "2024-10-14T00:15:40Z")

</div>

Elasticsearch version-:8.15 Kibana version-:8.15 security is enabled(basic auth), without ssl Running Elasticsearch and kibana in local with single cluster -windows machine As we can see in the screenshot kibana i…

---

## [Search bar persistent? (or to pin search phrase as a filter to persist?)](https://discuss.elastic.co/t/search-bar-persistent-or-to-pin-search-phrase-as-a-filter-to-persist/368738)

<div class="topic-metadata">

**Author:** [@bob454522](https://discuss.elastic.co/u/bob454522)\
**Replies:** 0\
**Last updated:** [October 13, 2024, 6:46pm UTC](https://discuss.elastic.co/t/search-bar-persistent-or-to-pin-search-phrase-as-a-filter-to-persist/368738 "2024-10-13T18:46:10Z")

</div>

on Kibana (v8.15.2, but prior i was on 8.8.2) - how do you get a search phrase (ie typed into the search bar) to persist across pages? (ie either across different dashboards, or even across different pages of the same d…

---

## [Displaying a dashboard via iframe without anonymous user access enabled](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644)

<div class="topic-metadata">

**Author:** [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Replies:** 4\
**Last updated:** [October 11, 2024, 3:14pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644 "2024-10-11T15:14:21Z")

</div>

Hi, I'm trying to display a dashboard in an iframe. My Kibana instance is required to use basic auth. I've setup a user specifically for this purpose. I've tried setting up anonymous access but I don't want just anyo…

---

## [Kibana BUG](https://discuss.elastic.co/t/kibana-bug/368627)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 5\
**Last updated:** [October 11, 2024, 2:42pm UTC](https://discuss.elastic.co/t/kibana-bug/368627 "2024-10-11T14:42:59Z")

</div>

Hello, When i select space and want to go to discover i got this error. Can somebody point me what is this? i cannot find anything...

---

## [Alerts not Triggering Email Notifications Despite Anomalies Detected in ML Jobs](https://discuss.elastic.co/t/alerts-not-triggering-email-notifications-despite-anomalies-detected-in-ml-jobs/368635)

<div class="topic-metadata">

**Author:** [@catarina](https://discuss.elastic.co/u/catarina)\
**Replies:** 1\
**Last updated:** [October 11, 2024, 2:33pm UTC](https://discuss.elastic.co/t/alerts-not-triggering-email-notifications-despite-anomalies-detected-in-ml-jobs/368635 "2024-10-11T14:33:13Z")

</div>

Hi Elasticsearch Community, I’ve created several Single Metric Machine Learning (ML) jobs, each configured to monitor sum of bytes for specific IP addresses. Due to the large volume of data, I’ve fine-tuned each job, an…

---

## [Elastic Search Configuration Problem with Kibana.yml](https://discuss.elastic.co/t/elastic-search-configuration-problem-with-kibana-yml/368665)

<div class="topic-metadata">

**Author:** [@schwarz\_ravenn](https://discuss.elastic.co/u/schwarz_ravenn)\
**Replies:** 2\
**Last updated:** [October 11, 2024, 8:15am UTC](https://discuss.elastic.co/t/elastic-search-configuration-problem-with-kibana-yml/368665 "2024-10-11T08:15:09Z")

</div>

So, I'm a newbie in Elasticsearch and Kibana. I've a problem with configuration and connection of Kibana to ES, sadly I couldn't find a solution that would work out for me, so I hope someone could help me out. Steps I'v…

---

## [Tag clound in Element List](https://discuss.elastic.co/t/tag-clound-in-element-list/368648)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 7:12pm UTC](https://discuss.elastic.co/t/tag-clound-in-element-list/368648 "2024-10-10T19:12:31Z")

</div>

I have a document that contains a list formatted as a dictionary. How can I extract the first element or the value of an element by its key to create a tag cloud? { "document\_id": 1, "terms": \[ { "key": "…

---

## [Install Kibana plugin in Elastic Cloud](https://discuss.elastic.co/t/install-kibana-plugin-in-elastic-cloud/368621)

<div class="topic-metadata">

**Author:** [@sami-obvio](https://discuss.elastic.co/u/sami-obvio)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 1:52pm UTC](https://discuss.elastic.co/t/install-kibana-plugin-in-elastic-cloud/368621 "2024-10-10T13:52:58Z")

</div>

Hi I am evaluating an Elastic Cloud instance I want to make a video player plugin for Kibana - I found a guide for isntallation but it's talking about putting the plugin in a folder... and I don't have terminal access…

---

## [How to change the kibana logo? (v7.17)](https://discuss.elastic.co/t/how-to-change-the-kibana-logo-v7-17/368620)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 1:16pm UTC](https://discuss.elastic.co/t/how-to-change-the-kibana-logo-v7-17/368620 "2024-10-10T13:16:18Z")

</div>

Hello. I want to change the kibana logo to company logo. Navbar logo (sidebar top left logo) I searched a lot and tried to change the logo by changing the script or using third party plugin. I think this post is us…

---

## [Thousands of predefined fields visible in "Default fields" in discover](https://discuss.elastic.co/t/thousands-of-predefined-fields-visible-in-default-fields-in-discover/368534)

<div class="topic-metadata">

**Author:** [@rkrzewski](https://discuss.elastic.co/u/rkrzewski)\
**Replies:** 2\
**Last updated:** [October 10, 2024, 9:20am UTC](https://discuss.elastic.co/t/thousands-of-predefined-fields-visible-in-default-fields-in-discover/368534 "2024-10-10T09:20:40Z")

</div>

I'm running Kibana/Elasticsearch/FileBeat 8.12.0 on Kubernetes, deployed using ECK operator. I'm only collecting logs from selected workloads in the kubernetes cluster. My filebeat configuration looks like this: f…

---

## [Pattern matching with Kibana](https://discuss.elastic.co/t/pattern-matching-with-kibana/367089)

<div class="topic-metadata">

**Author:** [@scrouet](https://discuss.elastic.co/u/scrouet)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 8:46am UTC](https://discuss.elastic.co/t/pattern-matching-with-kibana/367089 "2024-10-10T08:46:29Z")

</div>

Hello, In Kibana I want to filter out messages when the field "EntryMessage" contains "Contact with Id {{numeric\_id}} has an incorrect login name or password." I tried this filter, but it does not work: { "regexp": …

---

## [How can I use a boolean query with a filter that checks for strings that "do not end with", "does not start with" and "does not contain" a certain string,](https://discuss.elastic.co/t/how-can-i-use-a-boolean-query-with-a-filter-that-checks-for-strings-that-do-not-end-with-does-not-start-with-and-does-not-contain-a-certain-string/368577)

<div class="topic-metadata">

**Author:** [@sebbpp](https://discuss.elastic.co/u/sebbpp)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 11:35pm UTC](https://discuss.elastic.co/t/how-can-i-use-a-boolean-query-with-a-filter-that-checks-for-strings-that-do-not-end-with-does-not-start-with-and-does-not-contain-a-certain-string/368577 "2024-10-09T23:35:11Z")

</div>

I am trying to get a query that help me out to get the records where tsv3message.connection.helo does not contain "dm3" string tsv3message.connection.host does not start with "qak" string tsv3message.connection.host do…

---

## [Does Kibana have a video player widget?](https://discuss.elastic.co/t/does-kibana-have-a-video-player-widget/368545)

<div class="topic-metadata">

**Author:** [@sami-obvio](https://discuss.elastic.co/u/sami-obvio)\
**Replies:** 1\
**Last updated:** [October 9, 2024, 4:07pm UTC](https://discuss.elastic.co/t/does-kibana-have-a-video-player-widget/368545 "2024-10-09T16:07:19Z")

</div>

I want to read a DB which has a video URL field - I want to render and play that video in a Kibana dashboard Is there a Kibana widget to play videos via loading them with a URL? I couldn't find one Thanks

---

## [CCR KSPM Data](https://discuss.elastic.co/t/ccr-kspm-data/368541)

<div class="topic-metadata">

**Author:** [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 2:53pm UTC](https://discuss.elastic.co/t/ccr-kspm-data/368541 "2024-10-09T14:53:11Z")

</div>

As suggested in the past, for using the KSPM on the SIEM Module, we need to use the Elastic Agent integration for our k8s clusters. Now if in case this data is read over CCR, what changes needs to be done other than map…

---

## [Possible to access sibling aggregation value within sibling child aggregation?](https://discuss.elastic.co/t/possible-to-access-sibling-aggregation-value-within-sibling-child-aggregation/368537)

<div class="topic-metadata">

**Author:** [@jlrivera81](https://discuss.elastic.co/u/jlrivera81)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 1:54pm UTC](https://discuss.elastic.co/t/possible-to-access-sibling-aggregation-value-within-sibling-child-aggregation/368537 "2024-10-09T13:54:51Z")

</div>

Hello, I have a test pipeline that is triggered for every code commit. The code commit has a unique "revision" and you can determine commit-order based on the revision's associated "revision\_order". Additionally, each…

---

## [Extraxt data from a strin in a shown in a data table](https://discuss.elastic.co/t/extraxt-data-from-a-strin-in-a-shown-in-a-data-table/368439)

<div class="topic-metadata">

**Author:** [@vaibhav\_dahmival](https://discuss.elastic.co/u/vaibhav_dahmival)\
**Replies:** 1\
**Last updated:** [October 9, 2024, 7:46am UTC](https://discuss.elastic.co/t/extraxt-data-from-a-strin-in-a-shown-in-a-data-table/368439 "2024-10-09T07:46:58Z")

</div>

I was creating a dashboard, when i tried creating a data table selected the field i want to add. But i only wanted the first 3 digits from that string. Could you guys help me with it on how to do it. there were some solu…

---

## [Elastic Fleet API Permissions](https://discuss.elastic.co/t/elastic-fleet-api-permissions/368474)

<div class="topic-metadata">

**Author:** [@elasticfantastik](https://discuss.elastic.co/u/elasticfantastik)\
**Replies:** 2\
**Last updated:** [October 8, 2024, 8:16pm UTC](https://discuss.elastic.co/t/elastic-fleet-api-permissions/368474 "2024-10-08T20:16:44Z")

</div>

We have an elastic stack setup, along with fleet to manage our elastic agents. However, due to a number of technical reasons: We have to manually deploy updates to certain agents. We are limited to accessing Kibana onl…

---

## [Not able to log on](https://discuss.elastic.co/t/not-able-to-log-on/368377)

<div class="topic-metadata">

**Author:** [@jleroux1](https://discuss.elastic.co/u/jleroux1)\
**Replies:** 4\
**Last updated:** [October 8, 2024, 4:09pm UTC](https://discuss.elastic.co/t/not-able-to-log-on/368377 "2024-10-08T16:09:26Z")

</div>

Hi, I'm new to elastic cloud. I created a superuser in kibana. Not able to logon...bad user name or password. I've checked the documentation. What do I mist ? Thank in advance :slight\_smile:

---

## [Watcher feature not available after upgrading Elasticsearch to version 8.15.2](https://discuss.elastic.co/t/watcher-feature-not-available-after-upgrading-elasticsearch-to-version-8-15-2/368437)

<div class="topic-metadata">

**Author:** [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Replies:** 0\
**Last updated:** [October 8, 2024, 11:17am UTC](https://discuss.elastic.co/t/watcher-feature-not-available-after-upgrading-elasticsearch-to-version-8-15-2/368437 "2024-10-08T11:17:41Z")

</div>

Hi All, We recently upgraded Elasticsearch from version 7.17.9 to version 8.15.2. Earlier , we had set up watchers in the Management tab inside alerts. But after the upgrade we are unable to see the Watcher option . Is …

---

## [Unable to login to Elastic Cloud using Microsoft login](https://discuss.elastic.co/t/unable-to-login-to-elastic-cloud-using-microsoft-login/368393)

<div class="topic-metadata">

**Author:** [@cpua](https://discuss.elastic.co/u/cpua)\
**Replies:** 7\
**Last updated:** [October 8, 2024, 10:10am UTC](https://discuss.elastic.co/t/unable-to-login-to-elastic-cloud-using-microsoft-login/368393 "2024-10-08T10:10:51Z")

</div>

For the past weeks I am able to login to Elastic cloud to configure the server and indices. But today I am unable to login to my Elastic cloud. I have provision it using Azure Elasticsearch. Is there any changes or maint…

---

## [Disable Kibana Help button](https://discuss.elastic.co/t/disable-kibana-help-button/368429)

<div class="topic-metadata">

**Author:** [@arT1](https://discuss.elastic.co/u/arT1)\
**Replies:** 0\
**Last updated:** [October 8, 2024, 10:06am UTC](https://discuss.elastic.co/t/disable-kibana-help-button/368429 "2024-10-08T10:06:01Z")

</div>

is there any way to remove or hide the help button?

---

## [Unable to check permissions in Fleet](https://discuss.elastic.co/t/unable-to-check-permissions-in-fleet/368324)

<div class="topic-metadata">

**Author:** [@Muni](https://discuss.elastic.co/u/Muni)\
**Replies:** 2\
**Last updated:** [October 8, 2024, 10:03am UTC](https://discuss.elastic.co/t/unable-to-check-permissions-in-fleet/368324 "2024-10-08T10:03:16Z")

</div>

Hi , We are unable to access the fleet and we are getting the error unable to check permission.

---

## [Kibana Upgrade Failed](https://discuss.elastic.co/t/kibana-upgrade-failed/368352)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [October 8, 2024, 8:27am UTC](https://discuss.elastic.co/t/kibana-upgrade-failed/368352 "2024-10-08T08:27:31Z")

</div>

I have a single kibana instance. I just upgraded from 8.12 to 8.15 by stopping kibana with systemctl, dnf installed kibana, and then restarted kibana. Kibana is failing to start and is printing this error message: Task …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=34)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=36)
