# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=44

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 45

---

## [Variety of data in Y axis](https://discuss.elastic.co/t/variety-of-data-in-y-axis/363701)

<div class="topic-metadata">

**Author:** [@juandres117](https://discuss.elastic.co/u/juandres117)\
**Replies:** 3\
**Last updated:** [August 5, 2024, 8:41am UTC](https://discuss.elastic.co/t/variety-of-data-in-y-axis/363701 "2024-08-05T08:41:29Z")

</div>

Hi! I have downloaded the data from: Democracy index - Our World in Data Which has the democracy index for countries and different years. I would like to represent something similar like this photo However I cannot …

---

## [Falling short on CPU memory](https://discuss.elastic.co/t/falling-short-on-cpu-memory/364353)

<div class="topic-metadata">

**Author:** [@Thunder1245](https://discuss.elastic.co/u/Thunder1245)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 7:49am UTC](https://discuss.elastic.co/t/falling-short-on-cpu-memory/364353 "2024-08-05T07:49:00Z")

</div>

I am falling short on CPU memory while starting KIbana. My RAM:8GB. Can someone help me?

---

## [Expose Kibana externally using NLB with AWS LoadBalancer Controller](https://discuss.elastic.co/t/expose-kibana-externally-using-nlb-with-aws-loadbalancer-controller/364347)

<div class="topic-metadata">

**Author:** [@toduythienluong](https://discuss.elastic.co/u/toduythienluong)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 6:37am UTC](https://discuss.elastic.co/t/expose-kibana-externally-using-nlb-with-aws-loadbalancer-controller/364347 "2024-08-05T06:37:22Z")

</div>

Hi, I am following this guide to have ECK then Elastic Search and Kibana installed on EKS. Everything is just fine, I have Kabana up and run with port-forwarding as documented, however when I expose the service with ty…

---

## [Connect ECONNREFUSED 192.168.138.12:9200](https://discuss.elastic.co/t/connect-econnrefused-192-168-138-12-9200/364322)

<div class="topic-metadata">

**Author:** [@g0nz0](https://discuss.elastic.co/u/g0nz0)\
**Replies:** 0\
**Last updated:** [August 4, 2024, 6:41am UTC](https://discuss.elastic.co/t/connect-econnrefused-192-168-138-12-9200/364322 "2024-08-04T06:41:10Z")

</div>

Hello, This is odd, I got this working on an old Ubuntu VM and old Docker/Compose, it might not be this, but I've build a new Ubunutu server and with all the latest versions and can't get Elastisearch/Kibana to work. I…

---

## [Custom Branding for Gold license](https://discuss.elastic.co/t/custom-branding-for-gold-license/364299)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 1\
**Last updated:** [August 3, 2024, 2:52pm UTC](https://discuss.elastic.co/t/custom-branding-for-gold-license/364299 "2024-08-03T14:52:03Z")

</div>

Is custom branding available with the Gold license for ELK ?

---

## [Kibana UX Background](https://discuss.elastic.co/t/kibana-ux-background/364294)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [August 2, 2024, 10:06pm UTC](https://discuss.elastic.co/t/kibana-ux-background/364294 "2024-08-02T22:06:08Z")

</div>

Hello, This is very random but it peaked my curiousity. I noticed the preview of a dashboard has a different background format: Versus what I am seeing: Keep in mind, I am not talking about the data and the err…

---

## [Kibana URL access header showing kbn-name](https://discuss.elastic.co/t/kibana-url-access-header-showing-kbn-name/363645)

<div class="topic-metadata">

**Author:** [@sameerpatel37](https://discuss.elastic.co/u/sameerpatel37)\
**Replies:** 7\
**Last updated:** [August 2, 2024, 3:23pm UTC](https://discuss.elastic.co/t/kibana-url-access-header-showing-kbn-name/363645 "2024-08-02T15:23:03Z")

</div>

When opening kibana URL in browser so in a inspect page header section kbn-name show the hostname of the server in response header. So is there anyway to remove kbn-name header from kibana. ES version = 7.17.0 Kibana v…

---

## [Best solution to visualize intermittend data of testruns?](https://discuss.elastic.co/t/best-solution-to-visualize-intermittend-data-of-testruns/364207)

<div class="topic-metadata">

**Author:** [@aendk](https://discuss.elastic.co/u/aendk)\
**Replies:** 3\
**Last updated:** [August 2, 2024, 10:40am UTC](https://discuss.elastic.co/t/best-solution-to-visualize-intermittend-data-of-testruns/364207 "2024-08-02T10:40:43Z")

</div>

Hey All, I am currently encountering a problem how to best visualize test run data. Most test runs take no more than a few hours and run at random times. Each data point contains a timestamp. In my approaches so far, t…

---

## [RPA Monitoring in ELK](https://discuss.elastic.co/t/rpa-monitoring-in-elk/364264)

<div class="topic-metadata">

**Author:** [@hairyapple](https://discuss.elastic.co/u/hairyapple)\
**Replies:** 0\
**Last updated:** [August 2, 2024, 10:16am UTC](https://discuss.elastic.co/t/rpa-monitoring-in-elk/364264 "2024-08-02T10:16:36Z")

</div>

We use UiPath and Power Platform as automation tools but we don't currently invest in any monitoring tools. Has anyone got any experience of using ELK to validate things like: Checking to see if a process automation h…

---

## [No past data in Kibana](https://discuss.elastic.co/t/no-past-data-in-kibana/364254)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 2\
**Last updated:** [August 2, 2024, 10:08am UTC](https://discuss.elastic.co/t/no-past-data-in-kibana/364254 "2024-08-02T10:08:38Z")

</div>

Hi Team, After restart of cluster (2 data node + 1 master node) we are not able to see past data in Kibana. No spaces,dashboards, datavisuals,users etc.. In stack management 36 indices are showing but displaying only …

---

## [.kibana-event-log- index pollution (100+)](https://discuss.elastic.co/t/kibana-event-log-index-pollution-100/364259)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 0\
**Last updated:** [August 2, 2024, 9:47am UTC](https://discuss.elastic.co/t/kibana-event-log-index-pollution-100/364259 "2024-08-02T09:47:54Z")

</div>

Old problem not solved. Every version of kibana creates new index template .kibana-event-log-7.xx.y-template with kibana-event-log-policy ILM policy that delete index after 90 days, but also keep creating new index every…

---

## [401 Unauthorized on Kibana 8.13.2 when accessing canvas API](https://discuss.elastic.co/t/401-unauthorized-on-kibana-8-13-2-when-accessing-canvas-api/364257)

<div class="topic-metadata">

**Author:** [@pranat](https://discuss.elastic.co/u/pranat)\
**Replies:** 1\
**Last updated:** [August 2, 2024, 9:27am UTC](https://discuss.elastic.co/t/401-unauthorized-on-kibana-8-13-2-when-accessing-canvas-api/364257 "2024-08-02T09:27:01Z")

</div>

We have to deploy ECK and Elasticsearch 8.13.2 cluster on onpremise VM where K8S is installed. We have created the esadmin user on Elasticsearch with superuser privileges along with allow\_restricted-indices: true We ha…

---

## [Enriching Data with Custom Index](https://discuss.elastic.co/t/enriching-data-with-custom-index/364084)

<div class="topic-metadata">

**Author:** [@FlyNavy](https://discuss.elastic.co/u/FlyNavy)\
**Replies:** 28\
**Last updated:** [August 1, 2024, 10:34pm UTC](https://discuss.elastic.co/t/enriching-data-with-custom-index/364084 "2024-08-01T22:34:41Z")

</div>

I'm trying to enrich an alert generating event with a user name. The alert generating event only currently contains the SID of the account and it's randomly generated. I created a custom index to contain the SID and ac…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/364216)

<div class="topic-metadata">

**Author:** [@ppagano91](https://discuss.elastic.co/u/ppagano91)\
**Replies:** 0\
**Last updated:** [August 1, 2024, 2:55pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/364216 "2024-08-01T14:55:58Z")

</div>

Hi! I'm getting the follow error when I try to execute .\\packetbeat -c packetbeat.yml: Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver: …

---

## [Security\_exception: action \[indices:admin/create\] is unauthorized for user \[elasticsearch\] with effective roles \[superuser\] on restricted indices \[.kibana\_analytics\_8.13.4\_001\], this action is granted by the index privileges \[create\_index,manage,all\]'](https://discuss.elastic.co/t/security-exception-action-indices-admin-create-is-unauthorized-for-user-elasticsearch-with-effective-roles-superuser-on-restricted-indices-kibana-analytics-8-13-4-001-this-action-is-granted-by-the-index-privileges-create-index-manage-all/363865)

<div class="topic-metadata">

**Author:** [@ppagano91](https://discuss.elastic.co/u/ppagano91)\
**Replies:** 2\
**Last updated:** [August 1, 2024, 2:29pm UTC](https://discuss.elastic.co/t/security-exception-action-indices-admin-create-is-unauthorized-for-user-elasticsearch-with-effective-roles-superuser-on-restricted-indices-kibana-analytics-8-13-4-001-this-action-is-granted-by-the-index-privileges-create-index-manage-all/363865 "2024-08-01T14:29:54Z")

</div>

Hi there, I have been looking at similar topics, but I haven't been able to resolve this error. First of all, I wanted to mention that I faced some problems when I installed Elasticsearch, because the default user "elas…

---

## [How to set password for built-in user kibana\_system through environment variable for docker container](https://discuss.elastic.co/t/how-to-set-password-for-built-in-user-kibana-system-through-environment-variable-for-docker-container/364200)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 3\
**Last updated:** [August 1, 2024, 1:10pm UTC](https://discuss.elastic.co/t/how-to-set-password-for-built-in-user-kibana-system-through-environment-variable-for-docker-container/364200 "2024-08-01T13:10:39Z")

</div>

I have no problem set password for elastic user through ELASTIC\_PASSWORD. I hope I can also set password for built-in users like kibana\_system. I tried KIBANA\_SYSTEM\_PASSWORD but it doesn't work. I have not found useful …

---

## [Kibana globaly change discover:sampleSize](https://discuss.elastic.co/t/kibana-globaly-change-discover-samplesize/364126)

<div class="topic-metadata">

**Author:** [@elkuser1234](https://discuss.elastic.co/u/elkuser1234)\
**Replies:** 2\
**Last updated:** [August 1, 2024, 11:17am UTC](https://discuss.elastic.co/t/kibana-globaly-change-discover-samplesize/364126 "2024-08-01T11:17:40Z")

</div>

Hello I need to change globally one setting in Kibana "discover:sampleSize" I don't want to give users access to advanced options for fear of damaging something How can I do this?

---

## [Kibana Canvas Dropdown Filter v. 8.12.2](https://discuss.elastic.co/t/kibana-canvas-dropdown-filter-v-8-12-2/364149)

<div class="topic-metadata">

**Author:** [@Hunter\_Knott](https://discuss.elastic.co/u/Hunter_Knott)\
**Replies:** 1\
**Last updated:** [July 31, 2024, 9:02pm UTC](https://discuss.elastic.co/t/kibana-canvas-dropdown-filter-v-8-12-2/364149 "2024-07-31T21:02:24Z")

</div>

Hi there, I've got a question regarding the dropdown filter used in Kibana's canvas workpads, version 8.12.2. So I have a table with various fields being listed off. The query (field and index names have been changed her…

---

## [System Information](https://discuss.elastic.co/t/system-information/364150)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [July 31, 2024, 9:01pm UTC](https://discuss.elastic.co/t/system-information/364150 "2024-07-31T21:01:18Z")

</div>

Can Elastic grab information about the actual name of processor on system? Like for example: Intel(R) Xeon(R) Platinum 8358?

---

## [OSQuery Configuration - Change triggers retrieval of entire table contents](https://discuss.elastic.co/t/osquery-configuration-change-triggers-retrieval-of-entire-table-contents/364140)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [July 31, 2024, 2:35pm UTC](https://discuss.elastic.co/t/osquery-configuration-change-triggers-retrieval-of-entire-table-contents/364140 "2024-07-31T14:35:42Z")

</div>

Hello everyone, i'am currently working with osquery (which is a requirement) for information retrieval about my hosts. Now my issue relates to the way the osquery manager integration handles updates to the osquery conf…

---

## [Disable stack monitoring in Kibana](https://discuss.elastic.co/t/disable-stack-monitoring-in-kibana/364131)

<div class="topic-metadata">

**Author:** [@Cyanat](https://discuss.elastic.co/u/Cyanat)\
**Replies:** 3\
**Last updated:** [July 31, 2024, 2:04pm UTC](https://discuss.elastic.co/t/disable-stack-monitoring-in-kibana/364131 "2024-07-31T14:04:14Z")

</div>

Hello! I have wanted to see what monitoring of stack was offerring. As I don't have metricbeat installed, I chose a self monitoring. Now, I would like to revert this change and disable monitoring (because I'm afraid mo…

---

## [Anomaly Detection Job Results Index](https://discuss.elastic.co/t/anomaly-detection-job-results-index/364002)

<div class="topic-metadata">

**Author:** [@aphadnis](https://discuss.elastic.co/u/aphadnis)\
**Replies:** 1\
**Last updated:** [July 31, 2024, 1:57pm UTC](https://discuss.elastic.co/t/anomaly-detection-job-results-index/364002 "2024-07-31T13:57:17Z")

</div>

Hi, I had a question regarding the results index used in anomaly detection. So far, I've created an anomaly detection job (let's say it has the job id 'ad-job'), in which I'm using partition\_field and by\_field. I notic…

---

## [Find saved objects with certain index pattern](https://discuss.elastic.co/t/find-saved-objects-with-certain-index-pattern/363781)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [July 29, 2024, 9:09pm UTC](https://discuss.elastic.co/t/find-saved-objects-with-certain-index-pattern/363781 "2024-07-29T21:09:01Z")

</div>

Hi, I'd like to find visualizations which have direct relationship to certain index pattern. Is it possible to write query for search something like this type:(visualization) child:(type=index-pattern, title=certain-i…

---

## [Looking forward for help！Kibana source code run about 3min output Server crashed with status code 1](https://discuss.elastic.co/t/looking-forward-for-help-kibana-source-code-run-about-3min-output-server-crashed-with-status-code-1/364133)

<div class="topic-metadata">

**Author:** [@juda](https://discuss.elastic.co/u/juda)\
**Replies:** 1\
**Last updated:** [July 31, 2024, 11:20am UTC](https://discuss.elastic.co/t/looking-forward-for-help-kibana-source-code-run-about-3min-output-server-crashed-with-status-code-1/364133 "2024-07-31T11:20:31Z")

</div>

I want to run kibana source code ，i have runned the project ,but when it run about 5min,some ERROR output.Please help me. Unhandled Promise rejection detected: { Error: connect ETIMEDOUT 0.0.30.210:80 at TCPConnect…

---

## [Discover: alerts-\* threshold/value displayed as 0 and not the actual decimal values](https://discuss.elastic.co/t/discover-alerts-threshold-value-displayed-as-0-and-not-the-actual-decimal-values/363874)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [July 30, 2024, 5:48pm UTC](https://discuss.elastic.co/t/discover-alerts-threshold-value-displayed-as-0-and-not-the-actual-decimal-values/363874 "2024-07-30T17:48:33Z")

</div>

It appears Kibana is not displaying the decimal values for threshold/value in the alerts-\* indices on the Discover page. If you navigate to the "Expanded document" and select JSON then you see the actual values W…

---

## [Need to capture User input in Kibana](https://discuss.elastic.co/t/need-to-capture-user-input-in-kibana/359387)

<div class="topic-metadata">

**Author:** [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Replies:** 2\
**Last updated:** [July 30, 2024, 4:11pm UTC](https://discuss.elastic.co/t/need-to-capture-user-input-in-kibana/359387 "2024-07-30T16:11:11Z")

</div>

Hi, We are using Elastic ML to detect anomalies. User receives an email with link to Kibana to see actual anomaly there. Now like to give User possibility to provide feedback for detected anomaly (thumb up/down plus a …

---

## [How can I change data type of a field in Filebeat index](https://discuss.elastic.co/t/how-can-i-change-data-type-of-a-field-in-filebeat-index/363946)

<div class="topic-metadata">

**Author:** [@Mahnaz\_Haghighi](https://discuss.elastic.co/u/Mahnaz_Haghighi)\
**Replies:** 2\
**Last updated:** [July 30, 2024, 6:42am UTC](https://discuss.elastic.co/t/how-can-i-change-data-type-of-a-field-in-filebeat-index/363946 "2024-07-30T06:42:18Z")

</div>

Hi.I have a string field in my Filebeat index. When I want to make a visualization with that field I cant find it in list of terms. How can I make it aggregatable?

---

## [How to hide create visualizations button in Kibana dashboard using iframe](https://discuss.elastic.co/t/how-to-hide-create-visualizations-button-in-kibana-dashboard-using-iframe/363956)

<div class="topic-metadata">

**Author:** [@tejashree](https://discuss.elastic.co/u/tejashree)\
**Replies:** 4\
**Last updated:** [July 30, 2024, 5:00am UTC](https://discuss.elastic.co/t/how-to-hide-create-visualizations-button-in-kibana-dashboard-using-iframe/363956 "2024-07-30T05:00:52Z")

</div>

I need to hide the create visualizations button to specific users, Users should have edit access to dashboards without access to create visualization button. Please let know

---

## [Filter index to get the field max value](https://discuss.elastic.co/t/filter-index-to-get-the-field-max-value/363438)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 2\
**Last updated:** [July 30, 2024, 1:53am UTC](https://discuss.elastic.co/t/filter-index-to-get-the-field-max-value/363438 "2024-07-30T01:53:02Z")

</div>

Hi everyone, I'm trying to filter my index to display based on the field max value. I searched around the internet but couldn't understand how to do it. Currently running kibana 7.17.1 Below is the sample index, what I…

---

## ["How can I divide a rule into specific time frames in Kibana?](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815)

<div class="topic-metadata">

**Author:** [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Replies:** 2\
**Last updated:** [July 29, 2024, 11:09pm UTC](https://discuss.elastic.co/t/how-can-i-divide-a-rule-into-specific-time-frames-in-kibana/363815 "2024-07-29T23:09:05Z")

</div>

For example, if I want a rule to check logs every 10 hours and apply a 1-hour span for analysis, how would I set this up?" This is my rule: from logs-\* | WHERE (CIDR\_MATCH(source.ip, "10.0.0.0/8") OR CIDR\_MATCH(source…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=43)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=45)
