# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=43

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 44

---

## [Watcher - Creating a Payload](https://discuss.elastic.co/t/watcher-creating-a-payload/364909)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 14, 2024, 1:56pm UTC](https://discuss.elastic.co/t/watcher-creating-a-payload/364909 "2024-08-14T13:56:45Z")

</div>

Hello, Is there a way to create a new payload in the condition portion of watcher? I have this watcher that evaluates buckets, it checks to see if the buckets pass a condition. The issue I want to filter out the bucket…

---

## [Merge entries of data view](https://discuss.elastic.co/t/merge-entries-of-data-view/364841)

<div class="topic-metadata">

**Author:** [@sz118](https://discuss.elastic.co/u/sz118)\
**Replies:** 1\
**Last updated:** [August 14, 2024, 12:05pm UTC](https://discuss.elastic.co/t/merge-entries-of-data-view/364841 "2024-08-14T12:05:50Z")

</div>

Hello everyone, I’m new to Kibana and I’d like to find a way to merge the entries of my data view. The data view contains field2 with the values “Verification passed…” or “Verification failed…” and a following string. …

---

## [Security Warning: Multiple Node.js Vulnerabilities Detected in Elasticsearch](https://discuss.elastic.co/t/security-warning-multiple-node-js-vulnerabilities-detected-in-elasticsearch/364895)

<div class="topic-metadata">

**Author:** [@letsdiscusselasticse](https://discuss.elastic.co/u/letsdiscusselasticse)\
**Replies:** 0\
**Last updated:** [August 14, 2024, 8:13am UTC](https://discuss.elastic.co/t/security-warning-multiple-node-js-vulnerabilities-detected-in-elasticsearch/364895 "2024-08-14T08:13:43Z")

</div>

Hello everyone, I've run into a security issue flagged by my Nessus scanner related to the version of Node.js installed on my Elasticsearch server. According to the scan, several vulnerabilities have been detected, affe…

---

## [Two string fields, one with .text suffix](https://discuss.elastic.co/t/two-string-fields-one-with-text-suffix/364682)

<div class="topic-metadata">

**Author:** [@Rihards](https://discuss.elastic.co/u/Rihards)\
**Replies:** 3\
**Last updated:** [August 14, 2024, 6:51am UTC](https://discuss.elastic.co/t/two-string-fields-one-with-text-suffix/364682 "2024-08-14T06:51:47Z")

</div>

In Kibana, viewing security alerts, presumably from an Elastic-defined rule. There are some fields that seem to be duplicated, just with a .text suffix added. They both seem to be of the same type, "String field" (no…

---

## [Alerting Issue - Can't Save Rule after turning off Match Query](https://discuss.elastic.co/t/alerting-issue-cant-save-rule-after-turning-off-match-query/364856)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 13, 2024, 7:17pm UTC](https://discuss.elastic.co/t/alerting-issue-cant-save-rule-after-turning-off-match-query/364856 "2024-08-13T19:17:08Z")

</div>

Hello, I am using Metric Threshold and I noticed that everytime I create a rule. I see that if I deselect the "If alert matches a query" It stops me from saving my rule. The there's no way to stop this unless I add…

---

## [O365 connectors within Teams will be deprecated and notifications from this service will stop](https://discuss.elastic.co/t/o365-connectors-within-teams-will-be-deprecated-and-notifications-from-this-service-will-stop/363240)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 8:43am UTC](https://discuss.elastic.co/t/o365-connectors-within-teams-will-be-deprecated-and-notifications-from-this-service-will-stop/363240 "2024-08-13T08:43:32Z")

</div>

Action Required: O365 connectors within Teams will be deprecated and notifications from this service will stop. Learn more about the timing and how the Workflows app provides a more flexible and secure experience. If you…

---

## [Fields are not shown in KIbana](https://discuss.elastic.co/t/fields-are-not-shown-in-kibana/364634)

<div class="topic-metadata">

**Author:** [@peter170805](https://discuss.elastic.co/u/peter170805)\
**Replies:** 9\
**Last updated:** [August 12, 2024, 4:11pm UTC](https://discuss.elastic.co/t/fields-are-not-shown-in-kibana/364634 "2024-08-12T16:11:57Z")

</div>

Hello dear friends of the community. I wanted to know if you could give me some clues as to why I can't view the data loaded in Kibana in an index that I created. I created an index with the mapping to load all the data …

---

## [How to generate a sum of averages graph](https://discuss.elastic.co/t/how-to-generate-a-sum-of-averages-graph/364675)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [August 12, 2024, 1:45pm UTC](https://discuss.elastic.co/t/how-to-generate-a-sum-of-averages-graph/364675 "2024-08-12T13:45:27Z")

</div>

Could someone help me? I don't even know where to start. I have the following data: location | quantity | A | 20 | B | 35 | C | 32 | B |…

---

## [Automating Rule Creation for Kibana](https://discuss.elastic.co/t/automating-rule-creation-for-kibana/361603)

<div class="topic-metadata">

**Author:** [@Emin](https://discuss.elastic.co/u/Emin)\
**Replies:** 14\
**Last updated:** [August 12, 2024, 12:45pm UTC](https://discuss.elastic.co/t/automating-rule-creation-for-kibana/361603 "2024-08-12T12:45:23Z")

</div>

I am trying to automate rule creation, updating and deletion via a Python script. I have tried both using curl and Python I use curl to create the rule: curl -k -X POST "https://192.168.10.131:5601/api/detection\_engine/…

---

## [403 Forbidden\\nPOST when verifying the repository of the snapshot](https://discuss.elastic.co/t/403-forbidden-npost-when-verifying-the-repository-of-the-snapshot/364768)

<div class="topic-metadata">

**Author:** [@tfkben](https://discuss.elastic.co/u/tfkben)\
**Replies:** 0\
**Last updated:** [August 12, 2024, 9:44am UTC](https://discuss.elastic.co/t/403-forbidden-npost-when-verifying-the-repository-of-the-snapshot/364768 "2024-08-12T09:44:33Z")

</div>

i have Elasticsearch and kibana installed in kubernetes (GKE) cluster with eck-operator i have a snapshots in GCS created from my old infrastructure in docker before adding the repository i create a service account wii…

---

## [Exim\_Main logs ingest pipeline](https://discuss.elastic.co/t/exim-main-logs-ingest-pipeline/364698)

<div class="topic-metadata">

**Author:** [@gareth-armstrong](https://discuss.elastic.co/u/gareth-armstrong)\
**Replies:** 0\
**Last updated:** [August 9, 2024, 3:53pm UTC](https://discuss.elastic.co/t/exim-main-logs-ingest-pipeline/364698 "2024-08-09T15:53:20Z")

</div>

Hi guys, I've got 4 exim servers that I want to collect the exim\_main log data from, and then present it in grafana dashboards, or possibly run investigations from the data in support of some email related issues that m…

---

## [Error: EACCES: permission denied, open '/usr/share/kibana/cert/elastic-certificates.key'](https://discuss.elastic.co/t/error-eacces-permission-denied-open-usr-share-kibana-cert-elastic-certificates-key/364690)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 0\
**Last updated:** [August 9, 2024, 2:39pm UTC](https://discuss.elastic.co/t/error-eacces-permission-denied-open-usr-share-kibana-cert-elastic-certificates-key/364690 "2024-08-09T14:39:14Z")

</div>

Hi all, getting error Error: EACCES: permission denied, open '/usr/share/kibana/cert/elastic-certificates.key' -----------------inside docker compose ------------ elasticsearch: image: docker.elastic.co/elasticsearch…

---

## [Logstash does not load data into elastic](https://discuss.elastic.co/t/logstash-does-not-load-data-into-elastic/364313)

<div class="topic-metadata">

**Author:** [@peter170805](https://discuss.elastic.co/u/peter170805)\
**Replies:** 10\
**Last updated:** [August 9, 2024, 3:04am UTC](https://discuss.elastic.co/t/logstash-does-not-load-data-into-elastic/364313 "2024-08-09T03:04:17Z")

</div>

Good afternoon friends, I have a question, I have Kibana version 7.5.1, the same as Elastic. I created an index to monitor a weblogic log. Before creating the index I tested the logstash configuration file (v 7.1.1), wh…

---

## [Implied Wildcard Search](https://discuss.elastic.co/t/implied-wildcard-search/364498)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 5\
**Last updated:** [August 8, 2024, 10:16pm UTC](https://discuss.elastic.co/t/implied-wildcard-search/364498 "2024-08-08T22:16:02Z")

</div>

When using the search bar, I'd like to have wildcards implied. For example, I have a dataset that has URLs in the url.full field. I'd like to be able to enter in the search bar url.domain: google and it matches on any …

---

## [Kibana - can't see data view in management panel](https://discuss.elastic.co/t/kibana-cant-see-data-view-in-management-panel/364570)

<div class="topic-metadata">

**Author:** [@aidin](https://discuss.elastic.co/u/aidin)\
**Replies:** 2\
**Last updated:** [August 8, 2024, 10:11pm UTC](https://discuss.elastic.co/t/kibana-cant-see-data-view-in-management-panel/364570 "2024-08-08T22:11:02Z")

</div>

I have a self-hosted Kibana, connected to a self-hosted Elasticsearch. Even when I login with the "elastic" user which is a super user, I don't see the "data view" in the "management" page. There's also no "Saved Objects…

---

## ["Forbidden" error when saving Dashboards](https://discuss.elastic.co/t/forbidden-error-when-saving-dashboards/364542)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 2\
**Last updated:** [August 8, 2024, 11:59am UTC](https://discuss.elastic.co/t/forbidden-error-when-saving-dashboards/364542 "2024-08-08T11:59:19Z")

</div>

Hi there, I'm having a weird issue where Kibana reports "Error: Forbidden" when trying to save a Dashboard. My logs in Kibana are looking like this: {"type":"log","@timestamp":"2024-08-07T13:23:47+00:00","tags":\["err…

---

## [Adding remark on data](https://discuss.elastic.co/t/adding-remark-on-data/364508)

<div class="topic-metadata">

**Author:** [@avocadojj](https://discuss.elastic.co/u/avocadojj)\
**Replies:** 0\
**Last updated:** [August 7, 2024, 3:45am UTC](https://discuss.elastic.co/t/adding-remark-on-data/364508 "2024-08-07T03:45:06Z")

</div>

Hi, I am currently working on a project to create rules that trigger alerts in Elasticsearch. After receiving an alert, I want to know if it's possible to add a new column of data through the Kibana UI, specifically vi…

---

## [Counting Terms In Text Field](https://discuss.elastic.co/t/counting-terms-in-text-field/363790)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [August 6, 2024, 8:40pm UTC](https://discuss.elastic.co/t/counting-terms-in-text-field/363790 "2024-08-06T20:40:11Z")

</div>

I'm using Logstash's RSS input to pull data into Elastic. I've configured the field title as a multi-type field, one as text, the other as a keyword. I want to count the frequency of words that appear in titles across …

---

## [Comparing different methods of rolling back database changes in pytest tests for SQLAlchemy](https://discuss.elastic.co/t/comparing-different-methods-of-rolling-back-database-changes-in-pytest-tests-for-sqlalchemy/364354)

<div class="topic-metadata">

**Author:** [@vivan](https://discuss.elastic.co/u/vivan)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 7:51pm UTC](https://discuss.elastic.co/t/comparing-different-methods-of-rolling-back-database-changes-in-pytest-tests-for-sqlalchemy/364354 "2024-08-06T19:51:37Z")

</div>

I'm working on a project that uses FastAPI and SQL Alchemy asynchronously. I've written pytest tests for this project and have successfully implemented database rollback after each test run. I've found two different im…

---

## [Email Connector: Multiple Responses In the Body, How to Separate](https://discuss.elastic.co/t/email-connector-multiple-responses-in-the-body-how-to-separate/363666)

<div class="topic-metadata">

**Author:** [@dune](https://discuss.elastic.co/u/dune)\
**Replies:** 2\
**Last updated:** [August 6, 2024, 6:37pm UTC](https://discuss.elastic.co/t/email-connector-multiple-responses-in-the-body-how-to-separate/363666 "2024-08-06T18:37:12Z")

</div>

Hello Elastic Team Member We have configured an Alert from a saved search. Job Runs every 15 minutes per 15 minutes of query history to retrieve document information. How can I space out each document entry response wh…

---

## [Working with dates](https://discuss.elastic.co/t/working-with-dates/364491)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 5:32pm UTC](https://discuss.elastic.co/t/working-with-dates/364491 "2024-08-06T17:32:30Z")

</div>

Hello Everyone I have a csv file(uploaded successfully into the elastic): but I cannot create a visualisation of how many companies founded in each year. I'm completely new to the ELK, can you help me?

---

## [Add \`\_id\` field to visualization](https://discuss.elastic.co/t/add-id-field-to-visualization/364415)

<div class="topic-metadata">

**Author:** [@hughes](https://discuss.elastic.co/u/hughes)\
**Replies:** 3\
**Last updated:** [August 6, 2024, 1:46pm UTC](https://discuss.elastic.co/t/add-id-field-to-visualization/364415 "2024-08-06T13:46:34Z")

</div>

Is there a way to add the \_id meta field to a table visualization?

---

## [Logstash seems to be working but no indices in Kibana](https://discuss.elastic.co/t/logstash-seems-to-be-working-but-no-indices-in-kibana/364444)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 4\
**Last updated:** [August 6, 2024, 11:54am UTC](https://discuss.elastic.co/t/logstash-seems-to-be-working-but-no-indices-in-kibana/364444 "2024-08-06T11:54:40Z")

</div>

Hi everyone, I am a new learner to the ELK stack Here is my logstash conf file: input { file { path =\> "C:\\Users\\umutc\\Desktop\\kibanaproject\\organisations.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } …

---

## [Show the difference between aggregated records for two filters in visualization](https://discuss.elastic.co/t/show-the-difference-between-aggregated-records-for-two-filters-in-visualization/363641)

<div class="topic-metadata">

**Author:** [@jvester](https://discuss.elastic.co/u/jvester)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 8:31am UTC](https://discuss.elastic.co/t/show-the-difference-between-aggregated-records-for-two-filters-in-visualization/363641 "2024-08-06T08:31:57Z")

</div>

Hi, I use a bargraph visualization to get insights in our logs. I have used a filter to find logs related to a specific event. If an error occurs we log that in a separate line and I used a different filter to find all …

---

## [Ingest log if field exists](https://discuss.elastic.co/t/ingest-log-if-field-exists/364380)

<div class="topic-metadata">

**Author:** [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Replies:** 2\
**Last updated:** [August 6, 2024, 7:03am UTC](https://discuss.elastic.co/t/ingest-log-if-field-exists/364380 "2024-08-06T07:03:45Z")

</div>

Hello, I'm trying to set a condition in my phpfpm pipeline that sends the log to a different index if field log.context.extra.asyncapi.name exists but is not doing anything. It keeps sending the log to the phpfpm index …

---

## [Building my own custom kibana docker image from source code](https://discuss.elastic.co/t/building-my-own-custom-kibana-docker-image-from-source-code/364436)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 0\
**Last updated:** [August 6, 2024, 6:58am UTC](https://discuss.elastic.co/t/building-my-own-custom-kibana-docker-image-from-source-code/364436 "2024-08-06T06:58:11Z")

</div>

hello, i've searched for some ways to build my own kibana docker image from cloned source code using 8.11.4 version i found several links but those are all outdated (kibana 6.xx or 7.xx) and does not work. Is there any…

---

## [Evaluating range of values using ES|QL](https://discuss.elastic.co/t/evaluating-range-of-values-using-es-ql/364418)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 2:35am UTC](https://discuss.elastic.co/t/evaluating-range-of-values-using-es-ql/364418 "2024-08-06T02:35:26Z")

</div>

I was wondering if anyone might want to take a stab at this one. I have an ES|QL query I'm trying to get to work. Right now I'm able to get the field "http.status" to "not equal" a value of "200": | eval failures = ca…

---

## [Unexpected Rule Failure](https://discuss.elastic.co/t/unexpected-rule-failure/364137)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [August 5, 2024, 7:08pm UTC](https://discuss.elastic.co/t/unexpected-rule-failure/364137 "2024-08-05T19:08:49Z")

</div>

Hello, I created a Elasticsearch Query Rule awhile back about 8 months ago. This rule appeared to be working as expected until recently it was brought to my attention that it stopped working. I checked the alert and it…

---

## [Exiting: error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory ...\\packetbeat\\kibana: failed to import Kibana index pattern: 1 error](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana-error-importing-directory-packetbeat-kibana-failed-to-import-kibana-index-pattern-1-error/364224)

<div class="topic-metadata">

**Author:** [@ppagano91](https://discuss.elastic.co/u/ppagano91)\
**Replies:** 4\
**Last updated:** [August 5, 2024, 6:02pm UTC](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana-error-importing-directory-packetbeat-kibana-failed-to-import-kibana-index-pattern-1-error/364224 "2024-08-05T18:02:28Z")

</div>

Hi! I'm getting the follow error when I try to execute .\\packetbeat -c packetbeat.yml :slight\_smile: Exiting: error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory C:\\Prog…

---

## [Packetbeat error](https://discuss.elastic.co/t/packetbeat-error/364412)

<div class="topic-metadata">

**Author:** [@PAWAN\_KUMAR2](https://discuss.elastic.co/u/PAWAN_KUMAR2)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 4:50pm UTC](https://discuss.elastic.co/t/packetbeat-error/364412 "2024-08-05T16:50:59Z")

</div>

I am having issues with packetbeat on Windows. i connected to my wifi and trying run packetbeat and capture the network. but in kibana I am seeing only empty data fields........PS C:\\Program Files\\Elastic\\Beats\\8.14.3\\pa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=42)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=44)
