# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=41

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 42

---

## [Kibana Fleet API for Logstash Output](https://discuss.elastic.co/t/kibana-fleet-api-for-logstash-output/365010)

<div class="topic-metadata">

**Author:** [@madra](https://discuss.elastic.co/u/madra)\
**Replies:** 1\
**Last updated:** [August 28, 2024, 11:40am UTC](https://discuss.elastic.co/t/kibana-fleet-api-for-logstash-output/365010 "2024-08-28T11:40:50Z")

</div>

Dear Community, we automise the Fleet deployment process. We want to add a logstash output to specify where the agent will send the data. What would be the proper API? Do you also have an example of the request-body. …

---

## [Azure Blob Storage connector](https://discuss.elastic.co/t/azure-blob-storage-connector/360400)

<div class="topic-metadata">

**Author:** [@Levinux](https://discuss.elastic.co/u/Levinux)\
**Replies:** 1\
**Last updated:** [August 28, 2024, 9:24am UTC](https://discuss.elastic.co/t/azure-blob-storage-connector/360400 "2024-08-28T09:24:54Z")

</div>

I am configuring Azure Blob Storage connector according to the following procedures: connectors/config.yml.example at main · elastic/connectors · GitHub Running from a Docker container | Enterprise Search documentation…

---

## [Date first occurrence of latest value](https://discuss.elastic.co/t/date-first-occurrence-of-latest-value/365557)

<div class="topic-metadata">

**Author:** [@apenootje](https://discuss.elastic.co/u/apenootje)\
**Replies:** 3\
**Last updated:** [August 27, 2024, 9:22pm UTC](https://discuss.elastic.co/t/date-first-occurrence-of-latest-value/365557 "2024-08-27T21:22:11Z")

</div>

Hello, i like to have the date of the first occurence of the latest value. Is this possible? I can use the latest value in metric but i like to have the date of the first occurence of this latest value

---

## [Anonymous user cannot log in](https://discuss.elastic.co/t/anonymous-user-cannot-log-in/365632)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [August 27, 2024, 7:32pm UTC](https://discuss.elastic.co/t/anonymous-user-cannot-log-in/365632 "2024-08-27T19:32:50Z")

</div>

Hi Team, I added an anonymous user "development", but it cannot log in due to security error. \[security\_exception Root causes: security\_exception: unable to authenticate user \[development\] for REST request \[/\_security/…

---

## [Kibana - Amount of Rules](https://discuss.elastic.co/t/kibana-amount-of-rules/365639)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 27, 2024, 6:57pm UTC](https://discuss.elastic.co/t/kibana-amount-of-rules/365639 "2024-08-27T18:57:57Z")

</div>

Hello, I am wondering how much rules is considered too much for kibana? Based off documentation: By default, each Kibana instance polls for work at three second intervals, and can run a maximum of ten concurrent tasks…

---

## [Create an alert based on moving time frame](https://discuss.elastic.co/t/create-an-alert-based-on-moving-time-frame/365626)

<div class="topic-metadata">

**Author:** [@kirankgummadi](https://discuss.elastic.co/u/kirankgummadi)\
**Replies:** 0\
**Last updated:** [August 27, 2024, 2:37pm UTC](https://discuss.elastic.co/t/create-an-alert-based-on-moving-time-frame/365626 "2024-08-27T14:37:33Z")

</div>

Hi - is there a way to create an alert based on an increase/decrease in average response time for the past 5 min compared to the last 30 mins? For example, if the average response time for past 30 mins is 300ms and the …

---

## [Timestamp dayOfWeek](https://discuss.elastic.co/t/timestamp-dayofweek/365605)

<div class="topic-metadata">

**Author:** [@Alexandre\_CHERAMY](https://discuss.elastic.co/u/Alexandre_CHERAMY)\
**Replies:** 1\
**Last updated:** [August 27, 2024, 1:24pm UTC](https://discuss.elastic.co/t/timestamp-dayofweek/365605 "2024-08-27T13:24:10Z")

</div>

Hi, I'm trying to create a visualization in kibana by filtering on the timestamp field. I want to filter by day of the week. For the moment, I obtain the sum for a given month, but I would like to remove specific days f…

---

## [Conditional formatting for Metric (empty field)](https://discuss.elastic.co/t/conditional-formatting-for-metric-empty-field/365540)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [August 27, 2024, 8:57am UTC](https://discuss.elastic.co/t/conditional-formatting-for-metric-empty-field/365540 "2024-08-27T08:57:52Z")

</div>

Hi, I'm creating a dashboard using Lens, and I'm reading the Last Value of a field that indicates the number of documents seen. Currently, I have set the visualization to be a Metric that shows the number of documents,…

---

## [Unable to edit custom Synthetics Alert in Kibana](https://discuss.elastic.co/t/unable-to-edit-custom-synthetics-alert-in-kibana/365576)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [August 26, 2024, 7:48pm UTC](https://discuss.elastic.co/t/unable-to-edit-custom-synthetics-alert-in-kibana/365576 "2024-08-26T19:48:45Z")

</div>

Elastic Cloud 8.15.0. I am creating a few custom Synthetics rules using monitor.tags in the Action query to do some specific alert routing by environment. However, I have an issue: When I create a custom Synthetics aler…

---

## [ERROR: Failed to determine the health of the cluster. , with exit code 69](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/365522)

<div class="topic-metadata">

**Author:** [@17HungLe02](https://discuss.elastic.co/u/17HungLe02)\
**Replies:** 7\
**Last updated:** [August 26, 2024, 4:56pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/365522 "2024-08-26T16:56:55Z")

</div>

I run the command to create token but the result is like this, what should I do?

---

## [When Rolling upgrades from Elasticsearch 6.8 to 7.x, The Kibana likely be unavailable](https://discuss.elastic.co/t/when-rolling-upgrades-from-elasticsearch-6-8-to-7-x-the-kibana-likely-be-unavailable/365016)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 2\
**Last updated:** [August 26, 2024, 12:59pm UTC](https://discuss.elastic.co/t/when-rolling-upgrades-from-elasticsearch-6-8-to-7-x-the-kibana-likely-be-unavailable/365016 "2024-08-26T12:59:35Z")

</div>

When Rolling upgrades from Elasticsearch 6.8 to 7.x, The Kibana likely be unavailable. I prepared to roll upgrade from Elasticsearch 6.8 to 7.x, But i found the kiabana likely be unavailable. If i used kiabana 6.8.23 ,…

---

## [Info about CVE-2024-37287](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587)

<div class="topic-metadata">

**Author:** [@lorepas](https://discuss.elastic.co/u/lorepas)\
**Replies:** 7\
**Last updated:** [August 26, 2024, 12:51pm UTC](https://discuss.elastic.co/t/info-about-cve-2024-37287/364587 "2024-08-26T12:51:22Z")

</div>

Hi all, I noticed the following security update regarding the CVE-2024-37287. I would like to understand if it could be affected also an on-prem installation of Kibana (v7.17.7) made with rpm, so without docker. I'm a …

---

## [How to show the correct count in table visualization](https://discuss.elastic.co/t/how-to-show-the-correct-count-in-table-visualization/365445)

<div class="topic-metadata">

**Author:** [@chun](https://discuss.elastic.co/u/chun)\
**Replies:** 9\
**Last updated:** [August 26, 2024, 11:34am UTC](https://discuss.elastic.co/t/how-to-show-the-correct-count-in-table-visualization/365445 "2024-08-26T11:34:20Z")

</div>

I have a index file with single document ID, 2 items under the single document: "hits": \[ { "\_index": "dremio\_sys\_jobs", "\_id": "sys\_jobs", "\_score": 1, "\_ignored": \[ "dre…

---

## [Unable to retrieve version information from Elasticsearch nodes. connect ETIMEDOUT 10.10.51.229:9200](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-etimedout-10-10-51-229-9200/363239)

<div class="topic-metadata">

**Author:** [@Thejashree\_TU](https://discuss.elastic.co/u/Thejashree_TU)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 11:21am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-etimedout-10-10-51-229-9200/363239 "2024-08-26T11:21:20Z")

</div>

I try to open localhost:5601 but for 2sec it is trying open the Kibana server is not ready yet. I am not getting what to do I tried many things

---

## [Heat Map not working when Time zone set to default](https://discuss.elastic.co/t/heat-map-not-working-when-time-zone-set-to-default/364439)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 8\
**Last updated:** [August 26, 2024, 9:34am UTC](https://discuss.elastic.co/t/heat-map-not-working-when-time-zone-set-to-default/364439 "2024-08-26T09:34:56Z")

</div>

Hello @everyone, I am trying to create heat map visualization which is not behaving as expected. The time zone is set to default. When creating heat map it works till selected timerange is Last 4 days. If I select ab…

---

## [Unable to disable "Apply custom time range" on visualization on canvas](https://discuss.elastic.co/t/unable-to-disable-apply-custom-time-range-on-visualization-on-canvas/365455)

<div class="topic-metadata">

**Author:** [@cjessing](https://discuss.elastic.co/u/cjessing)\
**Replies:** 2\
**Last updated:** [August 26, 2024, 9:34am UTC](https://discuss.elastic.co/t/unable-to-disable-apply-custom-time-range-on-visualization-on-canvas/365455 "2024-08-26T09:34:02Z")

</div>

I have a Vega-Lite visualization that I've added to a canvas. I've switched off "Show title" and "Apply custom time range" in settings but each time the page is reloaded, the "Apply custom time range" is switched back on…

---

## [Ingest pipelines 7.17.9](https://discuss.elastic.co/t/ingest-pipelines-7-17-9/365492)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 0\
**Last updated:** [August 24, 2024, 2:16pm UTC](https://discuss.elastic.co/t/ingest-pipelines-7-17-9/365492 "2024-08-24T14:16:18Z")

</div>

Hello, I have the following haproxy log as shown in Kibana: {"log":"\\u003c150\\u003eApr 10 19:00:56 haproxy\[51\]: 172.69.63.101:63258 \[24/Apr/2024:19:00:56.284\] ha~ stat/\\u003cNOSRV\\u003e 0/-1/-1/-1/0 503 217 - - SCNN 3/…

---

## [I do not see Log out option](https://discuss.elastic.co/t/i-do-not-see-log-out-option/365468)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [August 24, 2024, 3:16am UTC](https://discuss.elastic.co/t/i-do-not-see-log-out-option/365468 "2024-08-24T03:16:16Z")

</div>

I try to log out this account, but I do not see Log out option. How can I log out and log in with another account? Thanks

---

## [Runtime fields not generated](https://discuss.elastic.co/t/runtime-fields-not-generated/364623)

<div class="topic-metadata">

**Author:** [@jonathan.wong](https://discuss.elastic.co/u/jonathan.wong)\
**Replies:** 4\
**Last updated:** [August 23, 2024, 6:37pm UTC](https://discuss.elastic.co/t/runtime-fields-not-generated/364623 "2024-08-23T18:37:25Z")

</div>

We're trying to set up a runtime field for certain index or data stream that has the same field from another index. We've tried to run the following on the Dev Console and different alteration of it, but every attempt do…

---

## [Alternatives to old .kibana indices to retrieve dashboards title](https://discuss.elastic.co/t/alternatives-to-old-kibana-indices-to-retrieve-dashboards-title/364925)

<div class="topic-metadata">

**Author:** [@plcharl](https://discuss.elastic.co/u/plcharl)\
**Replies:** 3\
**Last updated:** [August 23, 2024, 2:55pm UTC](https://discuss.elastic.co/t/alternatives-to-old-kibana-indices-to-retrieve-dashboards-title/364925 "2024-08-23T14:55:12Z")

</div>

Hello all ! My client just migrated from ELK7 -\> ELK8. We have a logstash pipeline indexing some kibana audit logs to make statistics over defined spaces/dashboard on our Kibana, which was using .kibana indexes to retr…

---

## [Filter Lens components in Canvas using a Timerange Filter](https://discuss.elastic.co/t/filter-lens-components-in-canvas-using-a-timerange-filter/364134)

<div class="topic-metadata">

**Author:** [@DataBjorn](https://discuss.elastic.co/u/DataBjorn)\
**Replies:** 1\
**Last updated:** [August 23, 2024, 11:40am UTC](https://discuss.elastic.co/t/filter-lens-components-in-canvas-using-a-timerange-filter/364134 "2024-08-23T11:40:47Z")

</div>

I am using Lens components in my Canvas board, and these have local time ranges. How can I use the time range filter of the Canvas board to filter these? I have disabled the "Apply Custom Time Range", but when setting t…

---

## [Question about Kibana vulnerability (CVE-2024-37287)](https://discuss.elastic.co/t/question-about-kibana-vulnerability-cve-2024-37287/365448)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 0\
**Last updated:** [August 23, 2024, 9:38am UTC](https://discuss.elastic.co/t/question-about-kibana-vulnerability-cve-2024-37287/365448 "2024-08-23T09:38:44Z")

</div>

Hello from Japan I'm concerned about Elastic's security announcement. Specifically, it's about the Kibana vulnerability (CVE-2024-37287). I created an elasticsearch.serviceAccountToken for Kibana using the command bel…

---

## [When creating indices and aliases in ES, user re\_test encounters errors, even though the user's index permissions are already set to all. How should this issue be handled? Thanks！](https://discuss.elastic.co/t/when-creating-indices-and-aliases-in-es-user-re-test-encounters-errors-even-though-the-users-index-permissions-are-already-set-to-all-how-should-this-issue-be-handled-thanks/365005)

<div class="topic-metadata">

**Author:** [@TYQ33](https://discuss.elastic.co/u/TYQ33)\
**Replies:** 2\
**Last updated:** [August 23, 2024, 2:35am UTC](https://discuss.elastic.co/t/when-creating-indices-and-aliases-in-es-user-re-test-encounters-errors-even-though-the-users-index-permissions-are-already-set-to-all-how-should-this-issue-be-handled-thanks/365005 "2024-08-23T02:35:44Z")

</div>

Failed to connect to backoff(elasticsearch(ES with IP:端口)): Connection marked as failed because the onConnect callback failed: failed to create alias: {"error":{"root\_cause":\[{"type":"security\_exception","reason":"action…

---

## [Need help with webhook alerts](https://discuss.elastic.co/t/need-help-with-webhook-alerts/365410)

<div class="topic-metadata">

**Author:** [@poqdavid](https://discuss.elastic.co/u/poqdavid)\
**Replies:** 0\
**Last updated:** [August 22, 2024, 9:03pm UTC](https://discuss.elastic.co/t/need-help-with-webhook-alerts/365410 "2024-08-22T21:03:45Z")

</div>

Hi, I have a small problem. When the alert status changes to “flapping,” it doesn’t send an update to the webhook, only indicating that it is flapping. I was wondering if it’s possible to enable an alert for the flappin…

---

## [Reference Different Log Than Alerting On](https://discuss.elastic.co/t/reference-different-log-than-alerting-on/364419)

<div class="topic-metadata">

**Author:** [@sfageol](https://discuss.elastic.co/u/sfageol)\
**Replies:** 2\
**Last updated:** [August 22, 2024, 8:52pm UTC](https://discuss.elastic.co/t/reference-different-log-than-alerting-on/364419 "2024-08-22T20:52:39Z")

</div>

I am setting up a "Rule". I send a request and that request might have 500 log lines. I have a "final failure" log line that I need to alert off of, but the failure reason is in a separate log line. Is it possible to dis…

---

## [Create a piechart based on values](https://discuss.elastic.co/t/create-a-piechart-based-on-values/365368)

<div class="topic-metadata">

**Author:** [@javidr](https://discuss.elastic.co/u/javidr)\
**Replies:** 2\
**Last updated:** [August 22, 2024, 3:33pm UTC](https://discuss.elastic.co/t/create-a-piechart-based-on-values/365368 "2024-08-22T15:33:03Z")

</div>

Hi I have a document with the number of items in stock used and unused {total: 50, used: 38, unused: 12} How can i create a pie chart to display as the total, 50, and split it in used and unused? I have been able to …

---

## [Drilldown in Dashboard](https://discuss.elastic.co/t/drilldown-in-dashboard/365374)

<div class="topic-metadata">

**Author:** [@sintim](https://discuss.elastic.co/u/sintim)\
**Replies:** 3\
**Last updated:** [August 22, 2024, 11:41am UTC](https://discuss.elastic.co/t/drilldown-in-dashboard/365374 "2024-08-22T11:41:22Z")

</div>

Is there a way to add a drilldown to visualization on a dashboard to open another dashbaord. If yes, can i get a step by step approach to how that can be achieved.

---

## [Duplicate documents](https://discuss.elastic.co/t/duplicate-documents/365354)

<div class="topic-metadata">

**Author:** [@Anjali\_Singh](https://discuss.elastic.co/u/Anjali_Singh)\
**Replies:** 3\
**Last updated:** [August 22, 2024, 11:02am UTC](https://discuss.elastic.co/t/duplicate-documents/365354 "2024-08-22T11:02:00Z")

</div>

Hi, May i know how can we avoid duplication of documents in kibana

---

## [Elastic Agent - Fleet Server Configuration yml](https://discuss.elastic.co/t/elastic-agent-fleet-server-configuration-yml/365360)

<div class="topic-metadata">

**Author:** [@Leo3](https://discuss.elastic.co/u/Leo3)\
**Replies:** 0\
**Last updated:** [August 22, 2024, 9:44am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-server-configuration-yml/365360 "2024-08-22T09:44:09Z")

</div>

Hello. I was able to spin up Elastic, Kibana and Fleet server in docker based on the official docker-compose.yml and this repo. My setup is not intended for production use. It is used purely for my personal experiments …

---

## [Using Grafana's Increase Function In Kibana](https://discuss.elastic.co/t/using-grafanas-increase-function-in-kibana/365330)

<div class="topic-metadata">

**Author:** [@harris\_p](https://discuss.elastic.co/u/harris_p)\
**Replies:** 0\
**Last updated:** [August 22, 2024, 2:30am UTC](https://discuss.elastic.co/t/using-grafanas-increase-function-in-kibana/365330 "2024-08-22T02:30:48Z")

</div>

Hello, I need to replicate Grafana visualization using Kibana. The visualization in Grafana is using this query: SUM(increase(requests\_total{operation\_type="query",instance=~"$instance",job=~"$job",response\_status!="su…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=40)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=42)
