# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=52

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 53

---

## [Context length is bigger than maximum allowed string](https://discuss.elastic.co/t/context-length-is-bigger-than-maximum-allowed-string/356985)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 4\
**Last updated:** [May 30, 2024, 4:14am UTC](https://discuss.elastic.co/t/context-length-is-bigger-than-maximum-allowed-string/356985 "2024-05-30T04:14:49Z")

</div>

Hi Team, We are trying to fetch log events on the discover tab and getting the following error. The log events consists of large Java stacks. We are using ELK version 8.10. I tried updating the server.maxPayload to…

---

## [Kibana error "kibana the content length is bigger than the maximum allowed string"](https://discuss.elastic.co/t/kibana-error-kibana-the-content-length-is-bigger-than-the-maximum-allowed-string/360511)

<div class="topic-metadata">

**Author:** [@amoghbarve](https://discuss.elastic.co/u/amoghbarve)\
**Replies:** 0\
**Last updated:** [May 29, 2024, 8:26pm UTC](https://discuss.elastic.co/t/kibana-error-kibana-the-content-length-is-bigger-than-the-maximum-allowed-string/360511 "2024-05-29T20:26:54Z")

</div>

Hi All I am getting error in kibana while accessing kindly suggest Error kibana the content length is bigger than the maximum allowed string

---

## [Import csv and match on column values](https://discuss.elastic.co/t/import-csv-and-match-on-column-values/360508)

<div class="topic-metadata">

**Author:** [@ACW606](https://discuss.elastic.co/u/ACW606)\
**Replies:** 0\
**Last updated:** [May 29, 2024, 8:13pm UTC](https://discuss.elastic.co/t/import-csv-and-match-on-column-values/360508 "2024-05-29T20:13:55Z")

</div>

We are using v8.11.3. I would like to import a csv with a long list of usernames. In my Kibana query of login logs, I'd like to match against values in the csv. Last, if a user login in my logs doesn't match a value in t…

---

## [Watcher - Possible Bug](https://discuss.elastic.co/t/watcher-possible-bug/360482)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [May 29, 2024, 2:48pm UTC](https://discuss.elastic.co/t/watcher-possible-bug/360482 "2024-05-29T14:48:50Z")

</div>

Hello, I create a watcher and then proceeded to simulate the watcher by force execute. The screen just goes blank: There are no errors in the watcher body, so I am not sure why it's causing this error.

---

## [Remote cluster status incorrect in Kibana](https://discuss.elastic.co/t/remote-cluster-status-incorrect-in-kibana/360464)

<div class="topic-metadata">

**Author:** [@fhegedus](https://discuss.elastic.co/u/fhegedus)\
**Replies:** 0\
**Last updated:** [May 29, 2024, 12:39pm UTC](https://discuss.elastic.co/t/remote-cluster-status-incorrect-in-kibana/360464 "2024-05-29T12:39:09Z")

</div>

Dear Community, I have a local cluster and three remote clusters, which I added using Kibana UI. Elasticsearch logs indicate that the connection is successful. In Kibana Dev Tools, the Remote Cluster Info API confirms…

---

## [Visutalization to Canvas](https://discuss.elastic.co/t/visutalization-to-canvas/359617)

<div class="topic-metadata">

**Author:** [@Emilio\_Astier](https://discuss.elastic.co/u/Emilio_Astier)\
**Replies:** 2\
**Last updated:** [May 29, 2024, 11:09am UTC](https://discuss.elastic.co/t/visutalization-to-canvas/359617 "2024-05-29T11:09:46Z")

</div>

Hello I want to pass a kibana visualization of type bars to Canvas. Is there a tutorial to do this? or it is necessary to construct an SQL statement. Any help welcome. Thanks and regards Emilio

---

## [Kibana - Enterprise Search Connector Issue](https://discuss.elastic.co/t/kibana-enterprise-search-connector-issue/360248)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 15\
**Last updated:** [May 29, 2024, 10:10am UTC](https://discuss.elastic.co/t/kibana-enterprise-search-connector-issue/360248 "2024-05-29T10:10:11Z")

</div>

Hi All, I was trying to migrate my connector configurations over from my testing environment into my live environment. However, every single time i enter the configuration page of my connector, it prompts the error "An u…

---

## ["Server Authentication using apikey failed - unable to find apikey with id id"](https://discuss.elastic.co/t/server-authentication-using-apikey-failed-unable-to-find-apikey-with-id-id/360413)

<div class="topic-metadata">

**Author:** [@ski](https://discuss.elastic.co/u/ski)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 9:00pm UTC](https://discuss.elastic.co/t/server-authentication-using-apikey-failed-unable-to-find-apikey-with-id-id/360413 "2024-05-28T21:00:10Z")

</div>

Good day. I currently operate a single node air-gapped configuration of Elasticsearch & Kibana (Version 8.13). As soon as the cluster is booted up, we receive the following error basically Every minute with an unspecifie…

---

## [percentage by row not overall](https://discuss.elastic.co/t/percentage-by-row-not-overall/360239)

<div class="topic-metadata">

**Author:** [@Ahmed2](https://discuss.elastic.co/u/Ahmed2)\
**Replies:** 3\
**Last updated:** [May 29, 2024, 8:22am UTC](https://discuss.elastic.co/t/percentage-by-row-not-overall/360239 "2024-05-29T08:22:30Z")

</div>

I am using metric visualization type in kibana. In Metric section, I have used 'count' aggregation and in bucket section, i have used 'terms' aggregation with field 'executionStatus.keyword' and clicked on 'update' butto…

---

## [Cannot read existing Message Signing Key pair for all integrations and fleet actions](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205)

<div class="topic-metadata">

**Author:** [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Replies:** 6\
**Last updated:** [May 28, 2024, 8:35pm UTC](https://discuss.elastic.co/t/cannot-read-existing-message-signing-key-pair-for-all-integrations-and-fleet-actions/360205 "2024-05-28T20:35:51Z")

</div>

Hi, I have deployed Elasticsearch and Kibana on a aws eks cluster by mostly following the quickstart guide for elastic cloud on kubernetes. I was able to get both elasticsearch and kibana running but know I want to set…

---

## [Create a query to obtain a user's average between two dates](https://discuss.elastic.co/t/create-a-query-to-obtain-a-users-average-between-two-dates/360389)

<div class="topic-metadata">

**Author:** [@Melman](https://discuss.elastic.co/u/Melman)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 2:52pm UTC](https://discuss.elastic.co/t/create-a-query-to-obtain-a-users-average-between-two-dates/360389 "2024-05-28T14:52:57Z")

</div>

Hello everyone, I'm looking to create a rule that will allow me to obtain the average of a date between two dates. For example, a user usually generates logs between 8am and 6pm. I've tried an approach with ES|QL but I…

---

## [Elasticsearch Internal URl](https://discuss.elastic.co/t/elasticsearch-internal-url/360376)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 0\
**Last updated:** [May 28, 2024, 12:22pm UTC](https://discuss.elastic.co/t/elasticsearch-internal-url/360376 "2024-05-28T12:22:12Z")

</div>

I am hosting Elasticsearch internally on a VM. I want to allow others to login to Kibana. What is the correct setting? Are there changes required to kibana.yml, elasticsearch.yml or both?

---

## [Time filter](https://discuss.elastic.co/t/time-filter/359021)

<div class="topic-metadata">

**Author:** [@tonichu](https://discuss.elastic.co/u/tonichu)\
**Replies:** 3\
**Last updated:** [May 28, 2024, 7:58am UTC](https://discuss.elastic.co/t/time-filter/359021 "2024-05-28T07:58:21Z")

</div>

I have a kibana graph made with vega that shows in a line graph some metrics over time and I want to be able to filter by time but the selector does not work for me.

---

## [Kibana map timestamp on layer with geoshapes](https://discuss.elastic.co/t/kibana-map-timestamp-on-layer-with-geoshapes/360179)

<div class="topic-metadata">

**Author:** [@smartjack](https://discuss.elastic.co/u/smartjack)\
**Replies:** 3\
**Last updated:** [May 28, 2024, 7:16am UTC](https://discuss.elastic.co/t/kibana-map-timestamp-on-layer-with-geoshapes/360179 "2024-05-28T07:16:34Z")

</div>

Hello, I'm trying to create a network visualisation using a map and ran into trouble with filtering of the documents using the time range picker in a dashboard. The flow is following: Send data with geo\_shape informat…

---

## [Get rid of suffix "per \[interval\]" in kibana lens visualisations when using Date histograms](https://discuss.elastic.co/t/get-rid-of-suffix-per-interval-in-kibana-lens-visualisations-when-using-date-histograms/360308)

<div class="topic-metadata">

**Author:** [@Knut\_Knackwurst](https://discuss.elastic.co/u/Knut_Knackwurst)\
**Replies:** 1\
**Last updated:** [May 27, 2024, 3:50pm UTC](https://discuss.elastic.co/t/get-rid-of-suffix-per-interval-in-kibana-lens-visualisations-when-using-date-histograms/360308 "2024-05-27T15:50:12Z")

</div>

Is it possible to get rid of the suffix "per \[inteval\]" in kibana lens visualisations when using Date histograms? For example, in Bar charts, when i use a Date histogram as an axis, choose "Month" as the interval and na…

---

## [Is there way to suppress the watcher alert at the single shot and activate it back](https://discuss.elastic.co/t/is-there-way-to-suppress-the-watcher-alert-at-the-single-shot-and-activate-it-back/360282)

<div class="topic-metadata">

**Author:** [@Kannan\_Rajendran](https://discuss.elastic.co/u/Kannan_Rajendran)\
**Replies:** 1\
**Last updated:** [May 27, 2024, 1:06pm UTC](https://discuss.elastic.co/t/is-there-way-to-suppress-the-watcher-alert-at-the-single-shot-and-activate-it-back/360282 "2024-05-27T13:06:18Z")

</div>

is there way to automate this enable and disable of the watchers based on any scheduled manner? Regards, Kannan R

---

## [Manual snapshot one index only](https://discuss.elastic.co/t/manual-snapshot-one-index-only/360269)

<div class="topic-metadata">

**Author:** [@tapiojaa](https://discuss.elastic.co/u/tapiojaa)\
**Replies:** 2\
**Last updated:** [May 27, 2024, 10:53am UTC](https://discuss.elastic.co/t/manual-snapshot-one-index-only/360269 "2024-05-27T10:53:22Z")

</div>

Is it possible to manually take snapshot from one index? I found from the documentation that it is be possible to snapshot all indices, but I want just one index backed up. PUT \_snapshot/my\_repository/%3Cmy\_snapshot\_%7B…

---

## [Filtering with wildcard](https://discuss.elastic.co/t/filtering-with-wildcard/360085)

<div class="topic-metadata">

**Author:** [@Cebula](https://discuss.elastic.co/u/Cebula)\
**Replies:** 2\
**Last updated:** [May 27, 2024, 10:16am UTC](https://discuss.elastic.co/t/filtering-with-wildcard/360085 "2024-05-27T10:16:17Z")

</div>

Need some help with the use of wildcard in filter. Filter log.level : ERROR and message: "This topic with id\*" will – as expected – list all data which starts with ’This topic with id’ If I include the not keyword in l…

---

## [Outlook connector integration](https://discuss.elastic.co/t/outlook-connector-integration/360232)

<div class="topic-metadata">

**Author:** [@John\_Ivon](https://discuss.elastic.co/u/John_Ivon)\
**Replies:** 0\
**Last updated:** [May 26, 2024, 10:46am UTC](https://discuss.elastic.co/t/outlook-connector-integration/360232 "2024-05-26T10:46:58Z")

</div>

Hello team, i run version 8.13.0 of the ELK. I m trying to configure the outlook connector but i m having this error: Application Not Found No application was found at this URL. Try going back or choosing an app from …

---

## [Task Manager is unhealthy - Reason: setting HealthStatus.Error because assumedRequired Throughput PerMinutePerKibana](https://discuss.elastic.co/t/task-manager-is-unhealthy-reason-setting-healthstatus-error-because-assumedrequired-throughput-perminuteperkibana/360070)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 1\
**Last updated:** [May 25, 2024, 11:59am UTC](https://discuss.elastic.co/t/task-manager-is-unhealthy-reason-setting-healthstatus-error-because-assumedrequired-throughput-perminuteperkibana/360070 "2024-05-25T11:59:25Z")

</div>

Hello Comuninty, I'm facing this issue in my kibana after upgrading it from 8.9 to 8.13 here is the error i,m facing Task Manager is unhealthy - Reason: setting HealthStatus.Error because assumedRequiredThroughputPerM…

---

## [Kibana anonymous access "TypeError: Cannot read properties of null (reading 'statusCode')"](https://discuss.elastic.co/t/kibana-anonymous-access-typeerror-cannot-read-properties-of-null-reading-statuscode/359267)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 3:49pm UTC](https://discuss.elastic.co/t/kibana-anonymous-access-typeerror-cannot-read-properties-of-null-reading-statuscode/359267 "2024-05-24T15:49:38Z")

</div>

Hello guys! I faced the issue that my dashbaords and data views break How I reproduce my issue: Deployed Elastic and Kibana 8.13.3 and logged in under elastic superuser to Kibana Added "Sample eCommerce orders" sampl…

---

## [Not able to send dynamic content(log messages) in Kibana Alerts ( v 8.13.2)](https://discuss.elastic.co/t/not-able-to-send-dynamic-content-log-messages-in-kibana-alerts-v-8-13-2/360068)

<div class="topic-metadata">

**Author:** [@Satyajeet\_Singh](https://discuss.elastic.co/u/Satyajeet_Singh)\
**Replies:** 0\
**Last updated:** [May 23, 2024, 10:25am UTC](https://discuss.elastic.co/t/not-able-to-send-dynamic-content-log-messages-in-kibana-alerts-v-8-13-2/360068 "2024-05-23T10:25:55Z")

</div>

we are sending alerts to overture from kibana logs. Every matching log should create an alert and we want to see the log message in alert. below is the alert body, I have tried several things but could not get the error…

---

## [In lens breakdown, the "others" is not an accumulated value](https://discuss.elastic.co/t/in-lens-breakdown-the-others-is-not-an-accumulated-value/360162)

<div class="topic-metadata">

**Author:** [@mekanix](https://discuss.elastic.co/u/mekanix)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 1:46pm UTC](https://discuss.elastic.co/t/in-lens-breakdown-the-others-is-not-an-accumulated-value/360162 "2024-05-24T13:46:34Z")

</div>

Setup: set of servers that sends filesystem metrics with metricbeat. I'm creating a stacked area visualization in lens with @timestamp on horizontal axis and formula "Maximum" of system.filesystem.used.bytes. I then br…

---

## [Lens Line Chart - Average of Sum of Fields Per Session](https://discuss.elastic.co/t/lens-line-chart-average-of-sum-of-fields-per-session/360028)

<div class="topic-metadata">

**Author:** [@sfageol](https://discuss.elastic.co/u/sfageol)\
**Replies:** 7\
**Last updated:** [May 24, 2024, 1:17pm UTC](https://discuss.elastic.co/t/lens-line-chart-average-of-sum-of-fields-per-session/360028 "2024-05-24T13:17:36Z")

</div>

I want a line chart that shows the average length of a web session. The issue is that we are logging the numeric value in 4 separate parts with no total logged. Here are my fields per log line: SessionID = 123 Resource…

---

## [Formula reference documentation](https://discuss.elastic.co/t/formula-reference-documentation/360144)

<div class="topic-metadata">

**Author:** [@anpama](https://discuss.elastic.co/u/anpama)\
**Replies:** 1\
**Last updated:** [May 24, 2024, 10:27am UTC](https://discuss.elastic.co/t/formula-reference-documentation/360144 "2024-05-24T10:27:43Z")

</div>

Hello, Is it possible to display the “Formula reference” documentation in a dedicated tab, either on Kibana directly or in the doc?

---

## [Kibana search for multiple data views](https://discuss.elastic.co/t/kibana-search-for-multiple-data-views/360134)

<div class="topic-metadata">

**Author:** [@tapiojaa](https://discuss.elastic.co/u/tapiojaa)\
**Replies:** 2\
**Last updated:** [May 24, 2024, 9:34am UTC](https://discuss.elastic.co/t/kibana-search-for-multiple-data-views/360134 "2024-05-24T09:34:40Z")

</div>

I've configured spaces where are multiple data views. Is it possible to search from all or certain data views in that space? I've noticed that there is metafield "\_index", but users don't know index names. They only see …

---

## [Adding multiple conditions in a Kibana watcher](https://discuss.elastic.co/t/adding-multiple-conditions-in-a-kibana-watcher/359897)

<div class="topic-metadata">

**Author:** [@Neha2](https://discuss.elastic.co/u/Neha2)\
**Replies:** 2\
**Last updated:** [May 24, 2024, 8:11am UTC](https://discuss.elastic.co/t/adding-multiple-conditions-in-a-kibana-watcher/359897 "2024-05-24T08:11:49Z")

</div>

Hello everyone, I need to set up a watcher in Kibana with the following conditions: a. Trigger an alert when the threshold reaches 100 between 6 AM and 11 AM. b. Trigger an alert when the threshold reaches 400 during o…

---

## [Lowercase host.name FQDN Beta Fleet policy setting](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 3\
**Last updated:** [May 23, 2024, 3:37pm UTC](https://discuss.elastic.co/t/lowercase-host-name-fqdn-beta-fleet-policy-setting/360047 "2024-05-23T15:37:51Z")

</div>

Hello, We are working through an effort to make sure host.name is indexed as lowercase fqdn everywhere. We put the original hostname in host.hostname. Considering we have multiple domains, this is not only necessary to…

---

## [How remove the red cross "Fields were not found](https://discuss.elastic.co/t/how-remove-the-red-cross-fields-were-not-found/359991)

<div class="topic-metadata">

**Author:** [@jeromeguillaume](https://discuss.elastic.co/u/jeromeguillaume)\
**Replies:** 4\
**Last updated:** [May 23, 2024, 3:02pm UTC](https://discuss.elastic.co/t/how-remove-the-red-cross-fields-were-not-found/359991 "2024-05-23T15:02:12Z")

</div>

When sometimes some fields are not there there is a red cross icon saying: "Fields a.b.c, d.e.f were not found." Can we disable this message? I found some blogs referring to "Hide missing fields" option but I was not ab…

---

## [Kibana VIP](https://discuss.elastic.co/t/kibana-vip/360073)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 5\
**Last updated:** [May 23, 2024, 1:03pm UTC](https://discuss.elastic.co/t/kibana-vip/360073 "2024-05-23T13:03:41Z")

</div>

Hello, My Elasticsearch is sending data to two distinct Kibana instances, and it works with two different URLs. Now, I want to use a VIP (Virtual IP) for these two Kibana instances. Do I need to modify my kibana.yml c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=51)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=53)
