# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=42

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 43

---

## [Looking for alternative ways to visualize status](https://discuss.elastic.co/t/looking-for-alternative-ways-to-visualize-status/365217)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [August 21, 2024, 5:08pm UTC](https://discuss.elastic.co/t/looking-for-alternative-ways-to-visualize-status/365217 "2024-08-21T17:08:06Z")

</div>

Hello, I am looking for any advice on how to find different ways to visualize this: The data showcases the last status of a task per host. Is there methods people use to showcase "status" events?

---

## [REGEX filtering on fields with embedded 'special chars'](https://discuss.elastic.co/t/regex-filtering-on-fields-with-embedded-special-chars/364800)

<div class="topic-metadata">

**Author:** [@andrew.laraia](https://discuss.elastic.co/u/andrew.laraia)\
**Replies:** 2\
**Last updated:** [August 21, 2024, 4:30pm UTC](https://discuss.elastic.co/t/regex-filtering-on-fields-with-embedded-special-chars/364800 "2024-08-21T16:30:50Z")

</div>

I know I can modify the current ingestion process to include more fields to make this example easier. But that's not the real goal. I'm trying to demonstrate using REGEX to isolates some specific data within a general da…

---

## [API KeyFailed - unable to find apikey with id xPIMCZABHLQpy59UBMie](https://discuss.elastic.co/t/api-keyfailed-unable-to-find-apikey-with-id-xpimczabhlqpy59ubmie/365156)

<div class="topic-metadata">

**Author:** [@ETFJeff](https://discuss.elastic.co/u/ETFJeff)\
**Replies:** 1\
**Last updated:** [August 21, 2024, 1:43pm UTC](https://discuss.elastic.co/t/api-keyfailed-unable-to-find-apikey-with-id-xpimczabhlqpy59ubmie/365156 "2024-08-21T13:43:27Z")

</div>

Hello, We are new to Elastic Cloud and we have odd errors in our cluster logs. Authentication using apikey failed - unable to find apikey with id xPIMCZABHLQpy59UBMie instance-0000000021 We have not setup this API ke…

---

## [Kibana query on data from Filebeat not returning anything](https://discuss.elastic.co/t/kibana-query-on-data-from-filebeat-not-returning-anything/365286)

<div class="topic-metadata">

**Author:** [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Replies:** 0\
**Last updated:** [August 21, 2024, 1:11pm UTC](https://discuss.elastic.co/t/kibana-query-on-data-from-filebeat-not-returning-anything/365286 "2024-08-21T13:11:15Z")

</div>

Elasticsearch version: 7.17.22 Kibana version: 7.17.22 Filebeat version: 7.17.7 Hello all, we're using Filebeat to ingest the Microsoft System Center Endpoint protection logs so we can monitor and alert on malware / …

---

## [Kibana stuck in a crash loop](https://discuss.elastic.co/t/kibana-stuck-in-a-crash-loop/364834)

<div class="topic-metadata">

**Author:** [@Glorified\_SysAdmin](https://discuss.elastic.co/u/Glorified_SysAdmin)\
**Replies:** 19\
**Last updated:** [August 21, 2024, 1:28pm UTC](https://discuss.elastic.co/t/kibana-stuck-in-a-crash-loop/364834 "2024-08-21T13:28:40Z")

</div>

Hello, I have a EFK stack deployed in EKS via helm. I have 6 nodes assigned to my ES cluster - 3 master, 2 ingest and 1 primary. All of my ES nodes are up and running. However, my Kibana pod is stuck on restart loop, ke…

---

## [Error when starting kibana.service](https://discuss.elastic.co/t/error-when-starting-kibana-service/365284)

<div class="topic-metadata">

**Author:** [@Ivan\_Sotirov](https://discuss.elastic.co/u/Ivan_Sotirov)\
**Replies:** 0\
**Last updated:** [August 21, 2024, 12:56pm UTC](https://discuss.elastic.co/t/error-when-starting-kibana-service/365284 "2024-08-21T12:56:27Z")

</div>

When staring the kibana service, it starts for a couple of seconds and then stops. Here are the errors i am getting: Failed to start Kibana kibana.service: Failed with result 'exit-code' kibana.service: Start request…

---

## [Alert to Ticket](https://discuss.elastic.co/t/alert-to-ticket/365207)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 2\
**Last updated:** [August 21, 2024, 7:34am UTC](https://discuss.elastic.co/t/alert-to-ticket/365207 "2024-08-21T07:34:15Z")

</div>

Hi Team , We have created an alert whenever the URL is down it has to trigger and create ticket in Servicenow. It is working . However we need to get the description part auto filled with the URL down . example: We ha…

---

## [Service Account Unable to Authenticate](https://discuss.elastic.co/t/service-account-unable-to-authenticate/364734)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 11\
**Last updated:** [August 20, 2024, 10:20pm UTC](https://discuss.elastic.co/t/service-account-unable-to-authenticate/364734 "2024-08-20T22:20:02Z")

</div>

Hello, I have a healthy single node elasticsearch cluster but when I created a service token and plugged it into the kibana.yml file, I'm receiving an authentication error. { "name" : "es01", "cluster\_name" : "SANI…

---

## [Iframe error when changing Iframe content](https://discuss.elastic.co/t/iframe-error-when-changing-iframe-content/364903)

<div class="topic-metadata">

**Author:** [@StefanC](https://discuss.elastic.co/u/StefanC)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 6:12pm UTC](https://discuss.elastic.co/t/iframe-error-when-changing-iframe-content/364903 "2024-08-20T18:12:06Z")

</div>

Setup: Version 8.15.0 of kibana/elasticseach Create an application where kibana is hosted as an IFrame. Make serveral selections on the different dashboard. Navigate to other dashboards via drilldown When changing the…

---

## [Visualize - Replicate Last Reboot](https://discuss.elastic.co/t/visualize-replicate-last-reboot/365056)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [August 20, 2024, 4:51pm UTC](https://discuss.elastic.co/t/visualize-replicate-last-reboot/365056 "2024-08-20T16:51:28Z")

</div>

Hello, I wanted to recreate this bar chart:

---

## [Who can save me TypeError: Failed to fetch](https://discuss.elastic.co/t/who-can-save-me-typeerror-failed-to-fetch/365170)

<div class="topic-metadata">

**Author:** [@WHD](https://discuss.elastic.co/u/WHD)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 1:58pm UTC](https://discuss.elastic.co/t/who-can-save-me-typeerror-failed-to-fetch/365170 "2024-08-20T13:58:10Z")

</div>

I use docker to install ES and Kibana, ES can be accessed normally， { "name" : "5f6114f4c963", "cluster\_name" : "docker-cluster", "cluster\_uuid" : "e9a2-N-rRMmq\_cpiaJqnBw", "version" : { "number" : "7.10.1",…

---

## [Alerting - Updating the Role\`](https://discuss.elastic.co/t/alerting-updating-the-role/364929)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 1:07pm UTC](https://discuss.elastic.co/t/alerting-updating-the-role/364929 "2024-08-20T13:07:06Z")

</div>

In rules, you have to specify a role visibility: So how can I update this? I chose the wrong the role and now the option is missing from my rule: .

---

## [Is there any option to default the color themes in visualization libraries in kibana 8.x](https://discuss.elastic.co/t/is-there-any-option-to-default-the-color-themes-in-visualization-libraries-in-kibana-8-x/364815)

<div class="topic-metadata">

**Author:** [@tejashree](https://discuss.elastic.co/u/tejashree)\
**Replies:** 3\
**Last updated:** [August 20, 2024, 10:07am UTC](https://discuss.elastic.co/t/is-there-any-option-to-default-the-color-themes-in-visualization-libraries-in-kibana-8-x/364815 "2024-08-20T10:07:37Z")

</div>

We need to default the color codes in visulzation libraries since we have to keep changing the colors for standard dashboards. Please let us know if there is any option called themes in kibana

---

## [Date histogram don't work](https://discuss.elastic.co/t/date-histogram-dont-work/364685)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 3\
**Last updated:** [August 20, 2024, 7:47am UTC](https://discuss.elastic.co/t/date-histogram-dont-work/364685 "2024-08-20T07:47:48Z")

</div>

I have a dataset like that which was successfully imported into the elasticsearch: I want to generate the table of how many units of items were ordered per year or month. But when i do the settings on Kibana, no sing…

---

## [How to do Trellis/Facet/Small Multiple in Kibana Lens with a pie chart](https://discuss.elastic.co/t/how-to-do-trellis-facet-small-multiple-in-kibana-lens-with-a-pie-chart/364872)

<div class="topic-metadata">

**Author:** [@binarysamurais](https://discuss.elastic.co/u/binarysamurais)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 7:44am UTC](https://discuss.elastic.co/t/how-to-do-trellis-facet-small-multiple-in-kibana-lens-with-a-pie-chart/364872 "2024-08-20T07:44:08Z")

</div>

I have a pie chart that I would like to show the percentage between two metrics Blocked & Not Blocked but I would like to Trellis/Fact/Small Multiple this pie chart by Category/Mitre Tactic (Reconnaissance, Resource Deve…

---

## [Cant see my services inside APM with elastic user login](https://discuss.elastic.co/t/cant-see-my-services-inside-apm-with-elastic-user-login/365112)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 1\
**Last updated:** [August 19, 2024, 11:23am UTC](https://discuss.elastic.co/t/cant-see-my-services-inside-apm-with-elastic-user-login/365112 "2024-08-19T11:23:03Z")

</div>

hi all, 10.40.12.20 is my local IP ----------apm-server.yml-------- apm-server: host: "0.0.0.0:8200" kibana: enabled: true host: "http://10.40.12.20:5601" # Replace with your Kibana URL username: "kibana\_system"…

---

## [How to create a runtime field with an array](https://discuss.elastic.co/t/how-to-create-a-runtime-field-with-an-array/365155)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [August 19, 2024, 6:25pm UTC](https://discuss.elastic.co/t/how-to-create-a-runtime-field-with-an-array/365155 "2024-08-19T18:25:43Z")

</div>

Hello, I was wondering how I can create a runtime field based on a value inside of a field array. For example I have this keyword field: fruit.names : \[kiwi, bananas, apple\] I want to create a new field based on coup…

---

## [Importing panel to the dashboard](https://discuss.elastic.co/t/importing-panel-to-the-dashboard/365033)

<div class="topic-metadata">

**Author:** [@Nikita\_Vasyliev](https://discuss.elastic.co/u/Nikita_Vasyliev)\
**Replies:** 3\
**Last updated:** [August 19, 2024, 6:23pm UTC](https://discuss.elastic.co/t/importing-panel-to-the-dashboard/365033 "2024-08-19T18:23:26Z")

</div>

Hi everyone, I have a dashboard and I'd like to import the markdown visualisation (containing only text) to the chosen dashboard via API. First I export the visualisation data, analyse it and after I'd like to import t…

---

## [How to create thresholds in Lens](https://discuss.elastic.co/t/how-to-create-thresholds-in-lens/365034)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [August 19, 2024, 2:05pm UTC](https://discuss.elastic.co/t/how-to-create-thresholds-in-lens/365034 "2024-08-19T14:05:35Z")

</div>

Hello, I know this can be done with TVSB: TVSB Example: But is it possible to add thresholds to Lens: The reason I want to use Lens over TVSB is just that in the TVSB example it considers "/" as "empty"

---

## [How to fix the security problem of the EPR and logstash 8.15.0](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 3\
**Last updated:** [August 19, 2024, 1:26am UTC](https://discuss.elastic.co/t/how-to-fix-the-security-problem-of-the-epr-and-logstash-8-15-0/364997 "2024-08-19T01:26:02Z")

</div>

Elastic Package Registry and logstash has been scanned for the following vulnerabilities，is there anyway to fix them ? version 8.15.0 EPR: CVE-2023-42365 CVE-2023-42364 CVE-2023-42366 CVE-2023-42363 CVE-2023-69…

---

## [To separate x-pack plugin from core kibana](https://discuss.elastic.co/t/to-separate-x-pack-plugin-from-core-kibana/364821)

<div class="topic-metadata">

**Author:** [@mzm1370](https://discuss.elastic.co/u/mzm1370)\
**Replies:** 5\
**Last updated:** [August 17, 2024, 4:43am UTC](https://discuss.elastic.co/t/to-separate-x-pack-plugin-from-core-kibana/364821 "2024-08-17T04:43:35Z")

</div>

hi, we want to separate the x-pack plugin from core Kibana and move it to folder plugins in the root folder Kibana and convert the x-pack plugin to an external plugin then we can first bootstrap core Kibana and install …

---

## [Copying query doesn't copy group and threshold, only time window](https://discuss.elastic.co/t/copying-query-doesnt-copy-group-and-threshold-only-time-window/365050)

<div class="topic-metadata">

**Author:** [@ajtjavier](https://discuss.elastic.co/u/ajtjavier)\
**Replies:** 0\
**Last updated:** [August 16, 2024, 5:06pm UTC](https://discuss.elastic.co/t/copying-query-doesnt-copy-group-and-threshold-only-time-window/365050 "2024-08-16T17:06:26Z")

</div>

I'm trying to copy a query generated by a rule as described on this thread, and then convert that JSON to a TOML file for detection as code. See below the query I've built on Elastic: When I click on Copy query, thi…

---

## [8.14.1 KQL facing an index（message&event.original） that cannot display all characters](https://discuss.elastic.co/t/8-14-1-kql-facing-an-index-message-event-original-that-cannot-display-all-characters/364994)

<div class="topic-metadata">

**Author:** [@dobixu](https://discuss.elastic.co/u/dobixu)\
**Replies:** 0\
**Last updated:** [August 16, 2024, 3:23am UTC](https://discuss.elastic.co/t/8-14-1-kql-facing-an-index-message-event-original-that-cannot-display-all-characters/364994 "2024-08-16T03:23:47Z")

</div>

Elasticsearch Version 8.14.1 Installed Plugins No response Java Version openjdk 22.0.1 2024-04-16 OS Version CentOS Linux release 7.9.2009 (Core) Problem Description Problem Description Kibana KQL query index " inter…

---

## [How to close the auto fetch request?](https://discuss.elastic.co/t/how-to-close-the-auto-fetch-request/364938)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 4\
**Last updated:** [August 16, 2024, 1:45am UTC](https://discuss.elastic.co/t/how-to-close-the-auto-fetch-request/364938 "2024-08-16T01:45:56Z")

</div>

\[2024-08-15T10:55:50.769+08:00\]\[ERROR\]\[plugins.fleet\] Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to http://10.26.22.25:8080/search?package=synthetics&prerele…

---

## [Pass the data into alert actions](https://discuss.elastic.co/t/pass-the-data-into-alert-actions/364962)

<div class="topic-metadata">

**Author:** [@yar](https://discuss.elastic.co/u/yar)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 2:24pm UTC](https://discuss.elastic.co/t/pass-the-data-into-alert-actions/364962 "2024-08-15T14:24:13Z")

</div>

Hi, I have created the Threshold based alert. It is executing a query against staging\_logs and production\_logs indices. How can I pass down the index in actions? I mean if the rule got triggered on some log in staging\_l…

---

## [Kibana fails to start](https://discuss.elastic.co/t/kibana-fails-to-start/364771)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 9\
**Last updated:** [August 15, 2024, 12:20pm UTC](https://discuss.elastic.co/t/kibana-fails-to-start/364771 "2024-08-15T12:20:56Z")

</div>

The cmd stucks at this stage: Kibana is currently running with legacy OpenSSL providers enabled! For details and instructions on how to disable see https://www.elastic.co/guide/en/kibana/8.14/production.html#openssl-leg…

---

## [Incorrect query and I don't understand why](https://discuss.elastic.co/t/incorrect-query-and-i-dont-understand-why/364936)

<div class="topic-metadata">

**Author:** [@Yoann\_Buzenet](https://discuss.elastic.co/u/Yoann_Buzenet)\
**Replies:** 1\
**Last updated:** [August 15, 2024, 11:58am UTC](https://discuss.elastic.co/t/incorrect-query-and-i-dont-understand-why/364936 "2024-08-15T11:58:38Z")

</div>

Hello, I created a query that doesn't work and the kibana devtools is not showing me a syntax error. There must be something logical I missed. I wonder if it comes from the multiples "should" clauses I am using. Could y…

---

## [\[I18n\] A \`formats\` must be a non-empty object](https://discuss.elastic.co/t/i18n-a-formats-must-be-a-non-empty-object/364745)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 1\
**Last updated:** [August 15, 2024, 11:23am UTC](https://discuss.elastic.co/t/i18n-a-formats-must-be-a-non-empty-object/364745 "2024-08-15T11:23:44Z")

</div>

Hi. I tried to upgrade ELK 8.14.3 to 8.15.0 Ubuntu version 22.04 Using the following command: sudo apt-get update && sudo apt-get upgrade I got this error message on frontend: \[I18n\] A \`formats\` must be a non-empty…

---

## [Backing up Kibana dashboards](https://discuss.elastic.co/t/backing-up-kibana-dashboards/364944)

<div class="topic-metadata">

**Author:** [@it-intelliroad](https://discuss.elastic.co/u/it-intelliroad)\
**Replies:** 1\
**Last updated:** [August 15, 2024, 9:31am UTC](https://discuss.elastic.co/t/backing-up-kibana-dashboards/364944 "2024-08-15T09:31:43Z")

</div>

im pretty new to all of this, currently my setup consists of 3 ES instances and dockerized Kibana and Logstash. before i also had ES dockerized but i struggled with the backing FS as i used a networkFS with docker swarm…

---

## [Best way to deal with empty fields?](https://discuss.elastic.co/t/best-way-to-deal-with-empty-fields/364806)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [August 14, 2024, 10:07pm UTC](https://discuss.elastic.co/t/best-way-to-deal-with-empty-fields/364806 "2024-08-14T22:07:42Z")

</div>

Hello, I have a field that seems to come in as "--" so I removed it. The due to removing it, the field now its "(empty)". The issue I want to filter out these fields but both appear: I even did "exists" and they bo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=41)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=43)
