# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=37

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 38

---

## [Issue with Extracting "trace\_id" from Logs in Elasticsearch Using Filebeat Pipeline](https://discuss.elastic.co/t/issue-with-extracting-trace-id-from-logs-in-elasticsearch-using-filebeat-pipeline/367185)

<div class="topic-metadata">

**Author:** [@helloworld466](https://discuss.elastic.co/u/helloworld466)\
**Replies:** 5\
**Last updated:** [September 30, 2024, 6:03am UTC](https://discuss.elastic.co/t/issue-with-extracting-trace-id-from-logs-in-elasticsearch-using-filebeat-pipeline/367185 "2024-09-30T06:03:03Z")

</div>

I am currently pushing logs to the Elasticsearch from Filebeat. I’m trying to extract the trace\_id from the message field and store the value in a separate field. The message field has the value: 2024-09-23 10:00:915 \[h…

---

## [Data Table Equivalent to Display 200,000 rows of data](https://discuss.elastic.co/t/data-table-equivalent-to-display-200-000-rows-of-data/366951)

<div class="topic-metadata">

**Author:** [@ManiS](https://discuss.elastic.co/u/ManiS)\
**Replies:** 10\
**Last updated:** [September 30, 2024, 4:24am UTC](https://discuss.elastic.co/t/data-table-equivalent-to-display-200-000-rows-of-data/366951 "2024-09-30T04:24:57Z")

</div>

Hi all, I'm trying to create a Data Table visualization based on an Index that has around 200,000 rows of data. However, when the data table index tries to display the visualization, it is failing with the following err…

---

## [Remove access to the menu on the left of the kibana 8.15 screen](https://discuss.elastic.co/t/remove-access-to-the-menu-on-the-left-of-the-kibana-8-15-screen/366215)

<div class="topic-metadata">

**Author:** [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Replies:** 3\
**Last updated:** [September 30, 2024, 12:15am UTC](https://discuss.elastic.co/t/remove-access-to-the-menu-on-the-left-of-the-kibana-8-15-screen/366215 "2024-09-30T00:15:18Z")

</div>

I have successfully limited users' access to the dashboards and set a default route to the first dashboard. The final thing I need to do is to stop them using the menu on the left and selecting Analytics\>Dashboards and …

---

## [Showing Max Value Per Unique Host](https://discuss.elastic.co/t/showing-max-value-per-unique-host/367258)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [September 27, 2024, 5:38pm UTC](https://discuss.elastic.co/t/showing-max-value-per-unique-host/367258 "2024-09-27T17:38:16Z")

</div>

I have a dataset that records the application version installed on a host. There are multiple records for each host, one for each version of the application that's been installed. Something like \[ { "hostname": …

---

## [Drilldown to dashboard, set control's value](https://discuss.elastic.co/t/drilldown-to-dashboard-set-controls-value/367246)

<div class="topic-metadata">

**Author:** [@cgame](https://discuss.elastic.co/u/cgame)\
**Replies:** 2\
**Last updated:** [September 27, 2024, 2:44pm UTC](https://discuss.elastic.co/t/drilldown-to-dashboard-set-controls-value/367246 "2024-09-27T14:44:54Z")

</div>

Hi, In Kibana is it possible when creating a drill-down to a dashboard which contains a control, to set a value for said control ? The point is to use the same source dashboard for multiple drill-down links, each displa…

---

## [If the default space is removed from the role, the elastic logo is displaying on load of dashboard and select space](https://discuss.elastic.co/t/if-the-default-space-is-removed-from-the-role-the-elastic-logo-is-displaying-on-load-of-dashboard-and-select-space/367241)

<div class="topic-metadata">

**Author:** [@tejashree](https://discuss.elastic.co/u/tejashree)\
**Replies:** 1\
**Last updated:** [September 27, 2024, 1:20pm UTC](https://discuss.elastic.co/t/if-the-default-space-is-removed-from-the-role-the-elastic-logo-is-displaying-on-load-of-dashboard-and-select-space/367241 "2024-09-27T13:20:25Z")

</div>

After login, on load of select space, the default elastic logo is getting displayed. The user is created without default space. Please let me know how to fix this issue. Version 8.14.1

---

## [Alerts issue](https://discuss.elastic.co/t/alerts-issue/367182)

<div class="topic-metadata">

**Author:** [@tapiojaa](https://discuss.elastic.co/u/tapiojaa)\
**Replies:** 2\
**Last updated:** [September 27, 2024, 11:55am UTC](https://discuss.elastic.co/t/alerts-issue/367182 "2024-09-27T11:55:28Z")

</div>

I'm trying to configure an alert that when certain word is found, email is sent. Email connector is configured and test email works. My rule looks like this: { "query":{ "match" : { "message": "client …

---

## [\[ERROR\]\[o.e.x.m.e.l.LocalExporter\] \[my-cluster\] failed to delete indices org.elasticsearch.index.IndexNotFoundException: no such index \[.monitoring-kibana-7-YYYY.MM.DD\]](https://discuss.elastic.co/t/error-o-e-x-m-e-l-localexporter-my-cluster-failed-to-delete-indices-org-elasticsearch-index-indexnotfoundexception-no-such-index-monitoring-kibana-7-yyyy-mm-dd/367239)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 0\
**Last updated:** [September 27, 2024, 10:58am UTC](https://discuss.elastic.co/t/error-o-e-x-m-e-l-localexporter-my-cluster-failed-to-delete-indices-org-elasticsearch-index-indexnotfoundexception-no-such-index-monitoring-kibana-7-yyyy-mm-dd/367239 "2024-09-27T10:58:29Z")

</div>

My cluster is raising the following error every day - this is a single node cluster using all default settings. I have enabled stack monitoring in Kibana. Looking to understand the cause an stop this error from being ra…

---

## [Issue with labels in MSSQL Curated Dashboards](https://discuss.elastic.co/t/issue-with-labels-in-mssql-curated-dashboards/367235)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [September 27, 2024, 10:47am UTC](https://discuss.elastic.co/t/issue-with-labels-in-mssql-curated-dashboards/367235 "2024-09-27T10:47:09Z")

</div>

Hi Team, We are using Elastic MSSQL integration (ELK Version 8.13.4) to pull error logs. The elastic agent is installed on the Windows node running the MSSQL service and is managed by fleet. The curated log dashboard do…

---

## [Kibana error after upgrade to 8.13.2](https://discuss.elastic.co/t/kibana-error-after-upgrade-to-8-13-2/359016)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 4\
**Last updated:** [September 27, 2024, 6:45am UTC](https://discuss.elastic.co/t/kibana-error-after-upgrade-to-8-13-2/359016 "2024-09-27T06:45:26Z")

</div>

Hello Team, i recently upgraded by kibana instance to 8.13.2 using zip bundle after upgrades i am seeking a pop-up error alerts in UI just after logging in kibana dashboard. is anyone can help to let me know this cause…

---

## [Kibana and Logstash are stopped automatically after some time](https://discuss.elastic.co/t/kibana-and-logstash-are-stopped-automatically-after-some-time/367210)

<div class="topic-metadata">

**Author:** [@Chinna\_Venkata\_Reddy](https://discuss.elastic.co/u/Chinna_Venkata_Reddy)\
**Replies:** 0\
**Last updated:** [September 27, 2024, 5:43am UTC](https://discuss.elastic.co/t/kibana-and-logstash-are-stopped-automatically-after-some-time/367210 "2024-09-27T05:43:36Z")

</div>

I have installed the Elastic search, Kibana and Logstash to integrate with my application. I installed Kibana and Logstash as windows services by using winsw as mentioned below Kibana : Logstash: With this I can…

---

## [Kibana log in, Is this behavior in line with expectations?](https://discuss.elastic.co/t/kibana-log-in-is-this-behavior-in-line-with-expectations/367173)

<div class="topic-metadata">

**Author:** [@rangerforce007](https://discuss.elastic.co/u/rangerforce007)\
**Replies:** 2\
**Last updated:** [September 27, 2024, 1:46am UTC](https://discuss.elastic.co/t/kibana-log-in-is-this-behavior-in-line-with-expectations/367173 "2024-09-27T01:46:46Z")

</div>

Two different elasticsearch instances use the elastic account to log in to the kibana page of each instance in the same browser. After the second login succeeds, the previous one will be automatically logged out. Is th…

---

## [Epoch time fractional number](https://discuss.elastic.co/t/epoch-time-fractional-number/366719)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 4\
**Last updated:** [September 26, 2024, 1:15pm UTC](https://discuss.elastic.co/t/epoch-time-fractional-number/366719 "2024-09-26T13:15:36Z")

</div>

Hello guys, I have following epoch timestamp : @timestamp":1726149789.77797 And i am using ruby { code =\> ' t = Time.at(event.get("@timestamp").to\_f \* 1000) event.set("@timestamp", t.st…

---

## [How to Restrict User Access to Specific Dashboards Only (Not All) in Kibana](https://discuss.elastic.co/t/how-to-restrict-user-access-to-specific-dashboards-only-not-all-in-kibana/367101)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 5\
**Last updated:** [September 26, 2024, 1:02pm UTC](https://discuss.elastic.co/t/how-to-restrict-user-access-to-specific-dashboards-only-not-all-in-kibana/367101 "2024-09-26T13:02:01Z")

</div>

Hello Team Version - 8.14 I have created 10 dashboards under my admin account in Kibana. Recently, I added a new user with admin rights for a different team member. However, I want to restrict this user’s access to onl…

---

## [Reshuffling of columns is not resolved as per the ticket #164413](https://discuss.elastic.co/t/reshuffling-of-columns-is-not-resolved-as-per-the-ticket-164413/366977)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 3\
**Last updated:** [September 26, 2024, 12:12pm UTC](https://discuss.elastic.co/t/reshuffling-of-columns-is-not-resolved-as-per-the-ticket-164413/366977 "2024-09-26T12:12:39Z")

</div>

Hello Team, As per the below two pull and github the issue is marked resolved. However when I checked the same in v8.14 of Kibana. the issue is still there... Can you please explain what needs to be done, to avoid colum…

---

## [Kibana pivot table with expandable rows](https://discuss.elastic.co/t/kibana-pivot-table-with-expandable-rows/359345)

<div class="topic-metadata">

**Author:** [@Stefano\_Sorgente](https://discuss.elastic.co/u/Stefano_Sorgente)\
**Replies:** 2\
**Last updated:** [September 26, 2024, 8:48am UTC](https://discuss.elastic.co/t/kibana-pivot-table-with-expandable-rows/359345 "2024-09-26T08:48:07Z")

</div>

Hello, I'm using Kibana and the enhanced table plugin but I'm not able to get what I want from it. I upload this screen to help me explain. I would love to get something similar, with all the data aggregated. For exa…

---

## [Add status field for kibana alerts in elastic index](https://discuss.elastic.co/t/add-status-field-for-kibana-alerts-in-elastic-index/367155)

<div class="topic-metadata">

**Author:** [@Tural\_Mirzayev](https://discuss.elastic.co/u/Tural_Mirzayev)\
**Replies:** 0\
**Last updated:** [September 26, 2024, 7:19am UTC](https://discuss.elastic.co/t/add-status-field-for-kibana-alerts-in-elastic-index/367155 "2024-09-26T07:19:20Z")

</div>

Hello, i want to send kibana alerts to the index in elasticsearch. For this purpose i created rule and select index type connector. But i need also alerts status,but when i tried some variables for visible alerts status…

---

## [Calculate Daily Log Ingestion](https://discuss.elastic.co/t/calculate-daily-log-ingestion/367148)

<div class="topic-metadata">

**Author:** [@amalkrish](https://discuss.elastic.co/u/amalkrish)\
**Replies:** 0\
**Last updated:** [September 26, 2024, 4:51am UTC](https://discuss.elastic.co/t/calculate-daily-log-ingestion/367148 "2024-09-26T04:51:29Z")

</div>

Hi Team, I am currently working on calculating the daily ingested data into hot storage and displaying it on the dashboard. While we have successfully captured the storage variations in hot storage, we're encountering a…

---

## [How can i get the interval and used it into formula](https://discuss.elastic.co/t/how-can-i-get-the-interval-and-used-it-into-formula/367141)

<div class="topic-metadata">

**Author:** [@dreamage](https://discuss.elastic.co/u/dreamage)\
**Replies:** 2\
**Last updated:** [September 26, 2024, 1:51am UTC](https://discuss.elastic.co/t/how-can-i-get-the-interval-and-used-it-into-formula/367141 "2024-09-26T01:51:53Z")

</div>

Hello, I set a Customize time interval 1min in x axis，but when i select a long time range such as 10 hours, the x axis per value change to 5 mins. i get a wrong y axis value. how can i get the interval and used it into f…

---

## [Crowdstrike API Integration](https://discuss.elastic.co/t/crowdstrike-api-integration/367132)

<div class="topic-metadata">

**Author:** [@wesleyj-hub](https://discuss.elastic.co/u/wesleyj-hub)\
**Replies:** 0\
**Last updated:** [September 25, 2024, 8:22pm UTC](https://discuss.elastic.co/t/crowdstrike-api-integration/367132 "2024-09-25T20:22:26Z")

</div>

I am having an issue with getting the API instance set up to connect Crowdstrike. Crowdstrike seems to need a POST request in order to pull the token, but it doesn't appear to be a way to add that if it is needed. After …

---

## [Kibana' Short URLs](https://discuss.elastic.co/t/kibana-short-urls/367117)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 0\
**Last updated:** [September 25, 2024, 4:18pm UTC](https://discuss.elastic.co/t/kibana-short-urls/367117 "2024-09-25T16:18:30Z")

</div>

hello world :wink: let me backup a bit and start from the beginning ... it all started when we saw this msg: {"type":"log","@timestamp":"2024-09-24T16:09:22+00:00","tags":\["error","savedobjects-service"\],"pid":7,"mess…

---

## [ELK – Scraping](https://discuss.elastic.co/t/elk-scraping/367104)

<div class="topic-metadata">

**Author:** [@Marwa\_ZIDI](https://discuss.elastic.co/u/Marwa_ZIDI)\
**Replies:** 2\
**Last updated:** [September 25, 2024, 1:01pm UTC](https://discuss.elastic.co/t/elk-scraping/367104 "2024-09-25T13:01:22Z")

</div>

Hello everybody, I got this technical test from an employer, it is about using ELK an integrate a sentiment classification service in it. Here are the questions: install ELK (I have already Ubuntu) Enable authentificati…

---

## [ELK Upgradation](https://discuss.elastic.co/t/elk-upgradation/367090)

<div class="topic-metadata">

**Author:** [@Anjali3](https://discuss.elastic.co/u/Anjali3)\
**Replies:** 0\
**Last updated:** [September 25, 2024, 8:35am UTC](https://discuss.elastic.co/t/elk-upgradation/367090 "2024-09-25T08:35:51Z")

</div>

Hi Team, We have one ELK Cluster in which we need to upgrade its version from 8.7.1 to 8.14.2. But how to generate certificates between these new containers on docker compose

---

## [Kibana script "plugin\_helpers" returns 0 even when failure is encountered](https://discuss.elastic.co/t/kibana-script-plugin-helpers-returns-0-even-when-failure-is-encountered/364701)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 3\
**Last updated:** [September 24, 2024, 9:08pm UTC](https://discuss.elastic.co/t/kibana-script-plugin-helpers-returns-0-even-when-failure-is-encountered/364701 "2024-09-24T21:08:41Z")

</div>

The Kibana script "scripts/plugin\_helpers" returns 0 even when failure is encountered. This is not optimal has we want our build to fail if there is an error. yarn build yarn run v1.22.21 $ yarn plugin-helpers build --d…

---

## [Multilevel Vega Sankey Paths Not Lining Up](https://discuss.elastic.co/t/multilevel-vega-sankey-paths-not-lining-up/308691)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 2\
**Last updated:** [September 22, 2024, 3:39pm UTC](https://discuss.elastic.co/t/multilevel-vega-sankey-paths-not-lining-up/308691 "2024-09-22T15:39:46Z")

</div>

I am trying to create some multilevel sankey diagrams in Kibana using Vega. I have it almost done, but the paths do not align on the center stack when highlighting one of the outside stacks. See image. I don't know i…

---

## [Inconsistent data](https://discuss.elastic.co/t/inconsistent-data/366608)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 5\
**Last updated:** [September 24, 2024, 8:33am UTC](https://discuss.elastic.co/t/inconsistent-data/366608 "2024-09-24T08:33:43Z")

</div>

Hello, I'm getting different count of records when switching between lens and discover, the only explanation I could think of is due to duplicates but after extracting a CSV file, i did not find any duplicates. Lens co…

---

## [Timestamp per Hour/Day getting automatically](https://discuss.elastic.co/t/timestamp-per-hour-day-getting-automatically/366970)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [September 24, 2024, 7:16am UTC](https://discuss.elastic.co/t/timestamp-per-hour-day-getting-automatically/366970 "2024-09-24T07:16:55Z")

</div>

I am using 8.14 version. When I am preparing a tabular dashboard, and selecting Timestamp aggregated at Hour or Day. the naming automatically changed from Timestamp per Hour or Timestamp per Day. However I Need only Time…

---

## [Kibana cannot connect to browser](https://discuss.elastic.co/t/kibana-cannot-connect-to-browser/366984)

<div class="topic-metadata">

**Author:** [@edemseg](https://discuss.elastic.co/u/edemseg)\
**Replies:** 1\
**Last updated:** [September 23, 2024, 4:59pm UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-browser/366984 "2024-09-23T16:59:06Z")

</div>

I am new to kibana and trying to setup ELK on ubuntu server 24.04.1 Elasticsearch works fine but Kibana wont open in browser. 192.168.25.80:5601 # Kibana is served by a back end server. This setting specifies the port…

---

## [How to duration between two status changes?](https://discuss.elastic.co/t/how-to-duration-between-two-status-changes/366895)

<div class="topic-metadata">

**Author:** [@vincenty79](https://discuss.elastic.co/u/vincenty79)\
**Replies:** 2\
**Last updated:** [September 23, 2024, 4:17pm UTC](https://discuss.elastic.co/t/how-to-duration-between-two-status-changes/366895 "2024-09-23T16:17:01Z")

</div>

I'm wondering how I would get the duration how long something ran? For example the time when the hvac ran the ac (cooling) and when it stopped (idle). My goal is to keep them and eventually have weekly, monthly and seaso…

---

## [Configure visualization from dashboard](https://discuss.elastic.co/t/configure-visualization-from-dashboard/365444)

<div class="topic-metadata">

**Author:** [@cjessing](https://discuss.elastic.co/u/cjessing)\
**Replies:** 3\
**Last updated:** [September 23, 2024, 12:23pm UTC](https://discuss.elastic.co/t/configure-visualization-from-dashboard/365444 "2024-09-23T12:23:15Z")

</div>

I have finally managed to get my first visualization working using Vega Lite. Let's call it "host information". However it consists of 3 different queries, each based on the same value (hostname). What I would like is t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=36)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=38)
