# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=39

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 40

---

## [About ILM policy](https://discuss.elastic.co/t/about-ilm-policy/366243)

<div class="topic-metadata">

**Author:** [@Sandeep\_Mishra](https://discuss.elastic.co/u/Sandeep_Mishra)\
**Replies:** 6\
**Last updated:** [September 16, 2024, 2:07pm UTC](https://discuss.elastic.co/t/about-ilm-policy/366243 "2024-09-16T14:07:05Z")

</div>

I have a client requirement to store the 2 years of data in my production environment. So How many days of data I need to keep in Hot,Warm,Cold and Delete phase. Please explain briefly.

---

## [How to parse fields that contain commas for a JSON Formatted response?](https://discuss.elastic.co/t/how-to-parse-fields-that-contain-commas-for-a-json-formatted-response/366593)

<div class="topic-metadata">

**Author:** [@bradleysb](https://discuss.elastic.co/u/bradleysb)\
**Replies:** 2\
**Last updated:** [September 16, 2024, 7:00am UTC](https://discuss.elastic.co/t/how-to-parse-fields-that-contain-commas-for-a-json-formatted-response/366593 "2024-09-16T07:00:41Z")

</div>

Hi community, I'm having somewhat of a hard time trying to correctly parse Json formatted data from an API call I'm doing using the Custom API integration within the Kibana UI. Example of my data im trying to parse in …

---

## [Kibana dev wont startup](https://discuss.elastic.co/t/kibana-dev-wont-startup/366488)

<div class="topic-metadata">

**Author:** [@OAJ](https://discuss.elastic.co/u/OAJ)\
**Replies:** 2\
**Last updated:** [September 15, 2024, 5:15pm UTC](https://discuss.elastic.co/t/kibana-dev-wont-startup/366488 "2024-09-15T17:15:33Z")

</div>

Hi all, So after running yarn build for my custom plugin. Only localhost:9200 works. But localhost:5601 wont startup for kibana dev

---

## [SNMP output and ES|QL](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 3\
**Last updated:** [September 13, 2024, 6:34pm UTC](https://discuss.elastic.co/t/snmp-output-and-es-ql/364546 "2024-09-13T18:34:16Z")

</div>

Hello community, i want to know if any of you have knowledge of ES|QL Im trying to do some viwes for a dashboard and i think this new feature can help but i was unable to do so. this is an example of the data but a…

---

## [Create a Boxplot with Elastic Index](https://discuss.elastic.co/t/create-a-boxplot-with-elastic-index/366344)

<div class="topic-metadata">

**Author:** [@brettmwerner](https://discuss.elastic.co/u/brettmwerner)\
**Replies:** 2\
**Last updated:** [September 13, 2024, 4:29pm UTC](https://discuss.elastic.co/t/create-a-boxplot-with-elastic-index/366344 "2024-09-13T16:29:26Z")

</div>

I'm trying to use Vega to create a boxplot with my elastic index data. My Vega code is here. { "$schema": "https://vega.github.io/schema/vega-lite/v4.json", "height": 400, "width": 100 "title": "Bootstrapped Mo…

---

## [Vega visualization sankey examples](https://discuss.elastic.co/t/vega-visualization-sankey-examples/365281)

<div class="topic-metadata">

**Author:** [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Replies:** 1\
**Last updated:** [September 13, 2024, 3:19pm UTC](https://discuss.elastic.co/t/vega-visualization-sankey-examples/365281 "2024-09-13T15:19:41Z")

</div>

We have added to the elastiflow\_for\_elasticsearch repository some sankey diagram examples based on Kibana's Vega visualization. You may find these a useful starting point for creating sankey diagrams for your own data. I…

---

## [Multiple dashboards/spaces through reverse proxy](https://discuss.elastic.co/t/multiple-dashboards-spaces-through-reverse-proxy/366391)

<div class="topic-metadata">

**Author:** [@PMF](https://discuss.elastic.co/u/PMF)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 8:27am UTC](https://discuss.elastic.co/t/multiple-dashboards-spaces-through-reverse-proxy/366391 "2024-09-11T08:27:14Z")

</div>

So, this is our use case: We have multiple dashboards with three levels of access. First, we have dashboards that we want to go public, we aim to embed them onto our webpage and allow everyone to see them. Those dashbo…

---

## [PacketBeat - Metric Visualization](https://discuss.elastic.co/t/packetbeat-metric-visualization/366267)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [September 13, 2024, 6:07am UTC](https://discuss.elastic.co/t/packetbeat-metric-visualization/366267 "2024-09-13T06:07:52Z")

</div>

Hello, I have question about displaying network data using Packetbeat. I was wondering for starters is there a way to determine the total packets? is that "count" of records in packetbeat?

---

## [How to config Control Button format to base64 decode?](https://discuss.elastic.co/t/how-to-config-control-button-format-to-base64-decode/365937)

<div class="topic-metadata">

**Author:** [@zhangzx1996](https://discuss.elastic.co/u/zhangzx1996)\
**Replies:** 2\
**Last updated:** [September 13, 2024, 2:43am UTC](https://discuss.elastic.co/t/how-to-config-control-button-format-to-base64-decode/365937 "2024-09-13T02:43:46Z")

</div>

I want to build a dashboard on kibana. But my field was base64 encode that I want to search. So I want the Control Button can be format base64 decode, and when I select one element ,kibana can use the base64 value to se…

---

## [HTML text in Kibana](https://discuss.elastic.co/t/html-text-in-kibana/366451)

<div class="topic-metadata">

**Author:** [@juandres117](https://discuss.elastic.co/u/juandres117)\
**Replies:** 1\
**Last updated:** [September 12, 2024, 11:13pm UTC](https://discuss.elastic.co/t/html-text-in-kibana/366451 "2024-09-12T23:13:14Z")

</div>

Hey everyone! I am willing to upload some data which has a field like this: Summary \<html\> \<body\> \<p\> Recent mass casualty attacks by militant groups in Burkina Faso are likely to put the military government under in…

---

## [Kibana Integration AWS SQS Error message](https://discuss.elastic.co/t/kibana-integration-aws-sqs-error-message/366497)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [September 12, 2024, 8:38pm UTC](https://discuss.elastic.co/t/kibana-integration-aws-sqs-error-message/366497 "2024-09-12T20:38:06Z")

</div>

Hi Team, I set up integration of AWS in Kibana with Elastic Agent to collect VPC flow logs from S3 via SQS queue URL. I got this error message: sqs ReceiveMessage failed: operation error SQS: ReceiveMessage, https resp…

---

## [When Rule is disabled, automatically disable alerts?](https://discuss.elastic.co/t/when-rule-is-disabled-automatically-disable-alerts/366454)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 2\
**Last updated:** [September 12, 2024, 10:48am UTC](https://discuss.elastic.co/t/when-rule-is-disabled-automatically-disable-alerts/366454 "2024-09-12T10:48:42Z")

</div>

Hello Elastic Team, I have multiple rules running in Elasticsearch instance. Out of which I stopped one rule which had "Active" alerts. Those alerts are still in active state. I am trying to find a way that when we cha…

---

## [Scheduled CSV Report - Email Body](https://discuss.elastic.co/t/scheduled-csv-report-email-body/366436)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [September 12, 2024, 4:56am UTC](https://discuss.elastic.co/t/scheduled-csv-report-email-body/366436 "2024-09-12T04:56:20Z")

</div>

Hello I created a watcher that sends a csv to email. Here's the watcher: { "trigger" : { "schedule": { "interval": "1h" } }, "actions" : { "email\_admin" : { "email": { "to": "\<red…

---

## [How to integrate cyble threat intelligence with ELK?](https://discuss.elastic.co/t/how-to-integrate-cyble-threat-intelligence-with-elk/366368)

<div class="topic-metadata">

**Author:** [@Rohit\_pol](https://discuss.elastic.co/u/Rohit_pol)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 7:53pm UTC](https://discuss.elastic.co/t/how-to-integrate-cyble-threat-intelligence-with-elk/366368 "2024-09-11T19:53:06Z")

</div>

I am try to integrate cyble with ELK but there is no default integration present in kibana so how to integrate cyble with kibana?

---

## [ElasticSearch upgrade 7.17.23 -\> 8.15.0 (Upgrade Assistant)](https://discuss.elastic.co/t/elasticsearch-upgrade-7-17-23-8-15-0-upgrade-assistant/366430)

<div class="topic-metadata">

**Author:** [@GeiserX](https://discuss.elastic.co/u/GeiserX)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 6:54pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-7-17-23-8-15-0-upgrade-assistant/366430 "2024-09-11T18:54:40Z")

</div>

Hi! I recently managed to get a 3-node ES cluster updated from 7.17.23 to 8.15.0 However, there are some search, transient errors after the upgrade. I followed all the upgrade guide, and checked for deprecations but the…

---

## [Unable to batch add lifecycle policy](https://discuss.elastic.co/t/unable-to-batch-add-lifecycle-policy/366413)

<div class="topic-metadata">

**Author:** [@Cyanat](https://discuss.elastic.co/u/Cyanat)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 1:55pm UTC](https://discuss.elastic.co/t/unable-to-batch-add-lifecycle-policy/366413 "2024-09-11T13:55:42Z")

</div>

Hello, On Index management page: when selecting a single index, under "Manage Index" button, I have option to "Add a lifecycle policy" when selecting several indexes, this option isn't proposed anymore Can't see any …

---

## [Adding a custom field in alerts](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 1:54pm UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts/366216 "2024-09-11T13:54:53Z")

</div>

Hello team, I am trying to create new rule in kibana for cpu utilization is more than 80 %. I am monitoring 3 host in my community version of Kibana. When it meet threshold criteare i am creating index and data is gett…

---

## [Kibana auto login](https://discuss.elastic.co/t/kibana-auto-login/366251)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 1\
**Last updated:** [September 9, 2024, 3:21pm UTC](https://discuss.elastic.co/t/kibana-auto-login/366251 "2024-09-09T15:21:59Z")

</div>

Hi OS - 22.04 Elasticsearch - 7.17.0 kibana - 7.17.23 we have enabled auto login feature with below code in kibana. xpack.security.authc.providers: anonymous.anonymous1: order: 0 credentials: username: "test" p…

---

## [Unable to create or save Data Views, even as Superuser in Elasticsearch](https://discuss.elastic.co/t/unable-to-create-or-save-data-views-even-as-superuser-in-elasticsearch/366296)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 2\
**Last updated:** [September 11, 2024, 7:13am UTC](https://discuss.elastic.co/t/unable-to-create-or-save-data-views-even-as-superuser-in-elasticsearch/366296 "2024-09-11T07:13:09Z")

</div>

Hello, I am encountering an issue where, even when using the Elastic user with the superuser role, I am unable to create or save Data Views in Elasticsearch 8.14.1. The superuser role is a default role and, as expected,…

---

## [Clarification On escaping characters witch MATCHES operator in Rule Exclusions](https://discuss.elastic.co/t/clarification-on-escaping-characters-witch-matches-operator-in-rule-exclusions/366350)

<div class="topic-metadata">

**Author:** [@Jakub\_Mihalov](https://discuss.elastic.co/u/Jakub_Mihalov)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 5:04pm UTC](https://discuss.elastic.co/t/clarification-on-escaping-characters-witch-matches-operator-in-rule-exclusions/366350 "2024-09-10T17:04:35Z")

</div>

Hello Elastic Community, I’m working on creating rule exclusions in Kibana using the MATCHES operator. While reviewing the official documentation, I found this explanation: ---Add and manage exceptions | Elastic Securi…

---

## [Kibana plugin development](https://discuss.elastic.co/t/kibana-plugin-development/366325)

<div class="topic-metadata">

**Author:** [@OAJ](https://discuss.elastic.co/u/OAJ)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 1:45pm UTC](https://discuss.elastic.co/t/kibana-plugin-development/366325 "2024-09-10T13:45:18Z")

</div>

Hi all, When running yarn kbn bootstrap The command runs in wsl (because im on windows) and then gets stucks on \[bazel\] warning Workspaces can only be enabled in private projects. Any guesses on why that is the case T…

---

## [Filter out character like "|" , "\\---------/" using KQL](https://discuss.elastic.co/t/filter-out-character-like-using-kql/366309)

<div class="topic-metadata">

**Author:** [@Shivani\_Kushwaha](https://discuss.elastic.co/u/Shivani_Kushwaha)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 11:45am UTC](https://discuss.elastic.co/t/filter-out-character-like-using-kql/366309 "2024-09-10T11:45:41Z")

</div>

I am trying to filter out the characters/ symbols like "|" , "/---------------", in logs, i tried filter out method but it is not working. looking for suggesstions, Thanks! :slight\_smile:

---

## [Need to create a custom default color in kibana individual visualizations and Dashboards](https://discuss.elastic.co/t/need-to-create-a-custom-default-color-in-kibana-individual-visualizations-and-dashboards/366303)

<div class="topic-metadata">

**Author:** [@Roshini](https://discuss.elastic.co/u/Roshini)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 9:45am UTC](https://discuss.elastic.co/t/need-to-create-a-custom-default-color-in-kibana-individual-visualizations-and-dashboards/366303 "2024-09-10T09:45:24Z")

</div>

Hi, I would like to know do we have an option for setting up a default color theme for individual visualizations and Dashboards? Attached screen shot for which we need to apply the default color theme setting

---

## [Embedding Webview in Kibana Dashboard](https://discuss.elastic.co/t/embedding-webview-in-kibana-dashboard/366291)

<div class="topic-metadata">

**Author:** [@OAJ](https://discuss.elastic.co/u/OAJ)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 10:25am UTC](https://discuss.elastic.co/t/embedding-webview-in-kibana-dashboard/366291 "2024-09-10T10:25:26Z")

</div>

Hi all, I want to embed a Webview in my kibana dashboard. I used the markdown visualiser and inserted my iframe but it renders the iframe as text. It's there something I'm missing

---

## [Connect ECONNREFUSED for Kibana with xpack.security.enabled: true](https://discuss.elastic.co/t/connect-econnrefused-for-kibana-with-xpack-security-enabled-true/366265)

<div class="topic-metadata">

**Author:** [@RSaravanaPrasad](https://discuss.elastic.co/u/RSaravanaPrasad)\
**Replies:** 0\
**Last updated:** [September 9, 2024, 5:12pm UTC](https://discuss.elastic.co/t/connect-econnrefused-for-kibana-with-xpack-security-enabled-true/366265 "2024-09-09T17:12:28Z")

</div>

Version: Elasticsearch and kibana on version 8.13.4 Environment: Minikube. While setting up xpack.security, getting following errors. Logs from kibana pod: {"type":"log","@timestamp":"2024-09-09T14:35:51+00:00","tags…

---

## [Possibly allow Kibana to dynamically change i18n config?](https://discuss.elastic.co/t/possibly-allow-kibana-to-dynamically-change-i18n-config/366140)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 1\
**Last updated:** [September 9, 2024, 3:58pm UTC](https://discuss.elastic.co/t/possibly-allow-kibana-to-dynamically-change-i18n-config/366140 "2024-09-09T15:58:08Z")

</div>

From i18n settings in Kibana | Kibana Guide \[8.15\] | Elastic , changing Kibana's Web UI usually requires setting specific environment variables when launching Kibana's Docker Container, which sounds like I18N\_LOCALE: zh…

---

## [How can you create reusable Vega-Lite components?](https://discuss.elastic.co/t/how-can-you-create-reusable-vega-lite-components/366246)

<div class="topic-metadata">

**Author:** [@ani\_Watches](https://discuss.elastic.co/u/ani_Watches)\
**Replies:** 1\
**Last updated:** [September 9, 2024, 1:19pm UTC](https://discuss.elastic.co/t/how-can-you-create-reusable-vega-lite-components/366246 "2024-09-09T13:19:27Z")

</div>

Hello everyone, As a newcomer to Vega, I'm working on a dashboard that displays various metrics for different servers (such as status, number of containers, and names). All data comes from metricbeat/heartbeat queries. …

---

## [Limit anonymous user's ability on embedded Kibana dashboard](https://discuss.elastic.co/t/limit-anonymous-users-ability-on-embedded-kibana-dashboard/366240)

<div class="topic-metadata">

**Author:** [@Muhammad\_Adil\_Talay](https://discuss.elastic.co/u/Muhammad_Adil_Talay)\
**Replies:** 1\
**Last updated:** [September 9, 2024, 1:00pm UTC](https://discuss.elastic.co/t/limit-anonymous-users-ability-on-embedded-kibana-dashboard/366240 "2024-09-09T13:00:52Z")

</div>

Hi, I'm following this tutorial on Elastic blog to embed Kibana dashboard on my website. I expect only the dashboard to appear using this method. However, the Elasticsearch bar, side bar and some other items also appear. …

---

## [Kibana: Browse Integration loads infinitely](https://discuss.elastic.co/t/kibana-browse-integration-loads-infinitely/366207)

<div class="topic-metadata">

**Author:** [@tripoli](https://discuss.elastic.co/u/tripoli)\
**Replies:** 1\
**Last updated:** [September 8, 2024, 3:22pm UTC](https://discuss.elastic.co/t/kibana-browse-integration-loads-infinitely/366207 "2024-09-08T15:22:52Z")

</div>

Hi, I'm creating an elasticsearch cluster with docker (portainer). However, the page to "Browse Integrations" on Kibana loads endlessly. Below is the screen Kibana (Docker-compose) kibana: depends\_on: …

---

## [Why doesn't the Elastic Package Registry Docker Image have \`/bin/bash\`?](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 6\
**Last updated:** [September 8, 2024, 9:20am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138 "2024-09-08T09:20:03Z")

</div>

Assume there is the following docker-compose.yml. services: elastic-package-registry: image: docker.elastic.co/package-registry/distribution:8.15.0 Start it, docker compose pull docker compose up -d docker com…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=38)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=40)
