# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=60

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 61

---

## [Any progress in embedded url? (?embed=true to hide headers in canvas workpad)](https://discuss.elastic.co/t/any-progress-in-embedded-url-embed-true-to-hide-headers-in-canvas-workpad/356509)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 4:11am UTC](https://discuss.elastic.co/t/any-progress-in-embedded-url-embed-true-to-hide-headers-in-canvas-workpad/356509 "2024-04-04T04:11:40Z")

</div>

Hello~! I've used to render kibana dashboards usually and embed=true works well. but this time, i want to render my es index as Table and found that "canvas" fits for me. so, i made url and put it in iframe but ?embed…

---

## [Kibana - same old ... (logging.dest broken, /etc/systemd vs. /usr/lib/systemd, etc](https://discuss.elastic.co/t/kibana-same-old-logging-dest-broken-etc-systemd-vs-usr-lib-systemd-etc/356703)

<div class="topic-metadata">

**Author:** [@Joe\_J](https://discuss.elastic.co/u/Joe_J)\
**Replies:** 0\
**Last updated:** [April 3, 2024, 3:57pm UTC](https://discuss.elastic.co/t/kibana-same-old-logging-dest-broken-etc-systemd-vs-usr-lib-systemd-etc/356703 "2024-04-03T15:57:05Z")

</div>

steps: point repo to elastic 8.x apt install kibana/stable 8.13.1 amd64 sudo to enroll to elastic-- seems to work ok ... seems like no config/ dir, mkdir + chown ... odd try again -- complaints about \[logging\].dest - e…

---

## [Searching IP Address with regex](https://discuss.elastic.co/t/searching-ip-address-with-regex/355465)

<div class="topic-metadata">

**Author:** [@martcus](https://discuss.elastic.co/u/martcus)\
**Replies:** 6\
**Last updated:** [April 3, 2024, 12:36pm UTC](https://discuss.elastic.co/t/searching-ip-address-with-regex/355465 "2024-04-03T12:36:16Z")

</div>

Hi All, I need to search for the presence of ip addresses on application logs in the following format: http://xxx.xxx.xxx.xxx https://xxx.xxx.xxx.xxx The field could also contain information other than the ip address …

---

## [Regarding visualization created for status code monitoring](https://discuss.elastic.co/t/regarding-visualization-created-for-status-code-monitoring/356393)

<div class="topic-metadata">

**Author:** [@vaishnavi1](https://discuss.elastic.co/u/vaishnavi1)\
**Replies:** 10\
**Last updated:** [April 3, 2024, 10:18am UTC](https://discuss.elastic.co/t/regarding-visualization-created-for-status-code-monitoring/356393 "2024-04-03T10:18:21Z")

</div>

We have created visualization for status code monitoring, for 15 days its showing 99.99 % and for 30 days' timeframe it is showing 100. query is that why it's not showing other status code rather than 401 and 400.

---

## [Vega visualization Issue](https://discuss.elastic.co/t/vega-visualization-issue/356653)

<div class="topic-metadata">

**Author:** [@Zzh\_Peter](https://discuss.elastic.co/u/Zzh_Peter)\
**Replies:** 2\
**Last updated:** [April 3, 2024, 7:53am UTC](https://discuss.elastic.co/t/vega-visualization-issue/356653 "2024-04-03T07:53:43Z")

</div>

Hi, I'm a new user using vega to customize my own dashboard. However, I'm facing some strange issues now... what I'm trying to do is use vega to create a bar chart showing some results from the Elasticsearch data pool. …

---

## [Webhook - Case Management connector \`PUT\` updates fails to send \`Content-Type: application/json\` header](https://discuss.elastic.co/t/webhook-case-management-connector-put-updates-fails-to-send-content-type-application-json-header/356492)

<div class="topic-metadata">

**Author:** [@W24800](https://discuss.elastic.co/u/W24800)\
**Replies:** 2\
**Last updated:** [April 2, 2024, 11:53pm UTC](https://discuss.elastic.co/t/webhook-case-management-connector-put-updates-fails-to-send-content-type-application-json-header/356492 "2024-04-02T23:53:46Z")

</div>

Elastic Version: 8.12.0 As the title states, the "Webhook - Case Management" connector PUT update fails to send the Content-Type: application/json HTTP header to case management platform. In my case, the platform is Red…

---

## [Kibana Dashboard Filter](https://discuss.elastic.co/t/kibana-dashboard-filter/356640)

<div class="topic-metadata">

**Author:** [@0593098](https://discuss.elastic.co/u/0593098)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 9:33pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filter/356640 "2024-04-02T21:33:36Z")

</div>

How do i fetch only top values of column Transaction.Status for latest time value in last\_date field Currently kibana shows data based on alphabetical order .I am unable to rank transaction\_status on last value functi…

---

## [Kibana monitoring issues with task not found](https://discuss.elastic.co/t/kibana-monitoring-issues-with-task-not-found/356403)

<div class="topic-metadata">

**Author:** [@Maxime\_Beaudry](https://discuss.elastic.co/u/Maxime_Beaudry)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 9:22pm UTC](https://discuss.elastic.co/t/kibana-monitoring-issues-with-task-not-found/356403 "2024-04-02T21:22:48Z")

</div>

Currently working out some issues on our ELK deployment related to data loss and corrupted snapshots. I've since fixed the snapshot but previous ones are essentially lost. Now, for context, we've had to remove the data\_…

---

## [Kibana visualization - Aggregating data for dashboard](https://discuss.elastic.co/t/kibana-visualization-aggregating-data-for-dashboard/356601)

<div class="topic-metadata">

**Author:** [@mislav.kuzmic](https://discuss.elastic.co/u/mislav.kuzmic)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 9:54am UTC](https://discuss.elastic.co/t/kibana-visualization-aggregating-data-for-dashboard/356601 "2024-04-02T09:54:13Z")

</div>

Hello, we're trying to come up with a dashboard to monitor our services running in a Kubernetes cluster. We use prometheus to scrape metrics and push them to Elastic Kibana via remove write feature. We managed to get t…

---

## [Visualization split series doesn't bring all the data](https://discuss.elastic.co/t/visualization-split-series-doesnt-bring-all-the-data/356537)

<div class="topic-metadata">

**Author:** [@box2m](https://discuss.elastic.co/u/box2m)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 8:41am UTC](https://discuss.elastic.co/t/visualization-split-series-doesnt-bring-all-the-data/356537 "2024-04-02T08:41:19Z")

</div>

On a basic visualization, when I add a "Split series" by significant terms, it doesn't show all data. This was executed using Elasticsearch & Kibana version 8.13.0 hosted in Kubernetes. Both queries are successful in th…

---

## [How to Stop REST API Command triggered in Dev Tools in Kibana](https://discuss.elastic.co/t/how-to-stop-rest-api-command-triggered-in-dev-tools-in-kibana/356595)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 0\
**Last updated:** [April 2, 2024, 7:28am UTC](https://discuss.elastic.co/t/how-to-stop-rest-api-command-triggered-in-dev-tools-in-kibana/356595 "2024-04-02T07:28:28Z")

</div>

Hi Team, Is there anyway we can stop the REST API command which is triggered from DEV tools in Kibana UI. We do not want to shutdown the Elastic cluster to stop the command. Thanks, Debasis

---

## [Automatic Re-creation of Deleted Index in Wazuh System](https://discuss.elastic.co/t/automatic-re-creation-of-deleted-index-in-wazuh-system/355769)

<div class="topic-metadata">

**Author:** [@Mahdi\_Khezrabadi](https://discuss.elastic.co/u/Mahdi_Khezrabadi)\
**Replies:** 2\
**Last updated:** [April 2, 2024, 6:41am UTC](https://discuss.elastic.co/t/automatic-re-creation-of-deleted-index-in-wazuh-system/355769 "2024-04-02T06:41:28Z")

</div>

I deleted the index wazuh-alerts-4.x-2024.03.19 in the Wazuh system. However, this index is automatically recreated, what is the reason for this?

---

## [Kibana Reporting timeout errors](https://discuss.elastic.co/t/kibana-reporting-timeout-errors/356580)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 5:30am UTC](https://discuss.elastic.co/t/kibana-reporting-timeout-errors/356580 "2024-04-02T05:30:14Z")

</div>

Hi Team, while creating PDF/PNG reports from the Kibana dashboard noticed the below error from the Kibana.log file can anyone look into this one? {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version"…

---

## [Kibana visualization dashboard support boolean operators AND, OR and NOT](https://discuss.elastic.co/t/kibana-visualization-dashboard-support-boolean-operators-and-or-and-not/356400)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 2\
**Last updated:** [April 2, 2024, 3:45am UTC](https://discuss.elastic.co/t/kibana-visualization-dashboard-support-boolean-operators-and-or-and-not/356400 "2024-04-02T03:45:28Z")

</div>

Hi, Does kibana visualization dashboard support boolean operators AND, OR and NOT? For example I want to extract data relevant to payment string and not payment-inquiry on kibana visualization dashboard search bar. P…

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. connect ETIMEDOUT](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-etimedout/356120)

<div class="topic-metadata">

**Author:** [@Devanshu\_Rastogi](https://discuss.elastic.co/u/Devanshu_Rastogi)\
**Replies:** 12\
**Last updated:** [April 1, 2024, 6:18pm UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-etimedout/356120 "2024-04-01T18:18:19Z")

</div>

Hi I am new to Elasticsearch and kibana and today I ran into an error due to which my kibana is not starting. My kibana.yaml - # The Kibana server's name. This is used for display purposes. #server.name: "your-hostname…

---

## [Sharing dashboard links (markdown widget) across spaces](https://discuss.elastic.co/t/sharing-dashboard-links-markdown-widget-across-spaces/354618)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [April 1, 2024, 9:15am UTC](https://discuss.elastic.co/t/sharing-dashboard-links-markdown-widget-across-spaces/354618 "2024-04-01T09:15:57Z")

</div>

I'm using the metricbeat generated dashboard "\[Metricbeat System\] Overview ECS", but I need to make copies of this dashboard to monitor machines related to each team separately. After adjusting the dashboard IDs in the …

---

## [Kibana Email Alert/Connectors](https://discuss.elastic.co/t/kibana-email-alert-connectors/356266)

<div class="topic-metadata">

**Author:** [@Maria\_Dalavagka](https://discuss.elastic.co/u/Maria_Dalavagka)\
**Replies:** 1\
**Last updated:** [March 31, 2024, 6:51pm UTC](https://discuss.elastic.co/t/kibana-email-alert-connectors/356266 "2024-03-31T18:51:28Z")

</div>

Hi everyone! I'd like to know how I connect Kibana with MailCatcher since the organization I work for does not allow to send emails to our personal mailboxes. We have a cloud dev environment (AWS) where we have created…

---

## [How to create add link in the format template of field?](https://discuss.elastic.co/t/how-to-create-add-link-in-the-format-template-of-field/356498)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [March 31, 2024, 9:51am UTC](https://discuss.elastic.co/t/how-to-create-add-link-in-the-format-template-of-field/356498 "2024-03-31T09:51:13Z")

</div>

Hello, i have columns in he index with order ID (contains the order id) and linktoOrder (contains the link to order ). So i actually want to add the link on the order id . link this so text will will be order id but t…

---

## [Dynamic watcher/alerting... without creating 100+ watchers](https://discuss.elastic.co/t/dynamic-watcher-alerting-without-creating-100-watchers/356408)

<div class="topic-metadata">

**Author:** [@eStrux-MAB](https://discuss.elastic.co/u/eStrux-MAB)\
**Replies:** 1\
**Last updated:** [March 30, 2024, 4:52pm UTC](https://discuss.elastic.co/t/dynamic-watcher-alerting-without-creating-100-watchers/356408 "2024-03-30T16:52:31Z")

</div>

Here's one for the "is this possible?" category. Is it possible to alert on specific conditions and aggregations of data within one index, without having to create an enormous number of watchers? Consider this: I have …

---

## [Default Max date field to be the filter in dashboard](https://discuss.elastic.co/t/default-max-date-field-to-be-the-filter-in-dashboard/356473)

<div class="topic-metadata">

**Author:** [@Liwei\_Zhang](https://discuss.elastic.co/u/Liwei_Zhang)\
**Replies:** 0\
**Last updated:** [March 29, 2024, 7:42pm UTC](https://discuss.elastic.co/t/default-max-date-field-to-be-the-filter-in-dashboard/356473 "2024-03-29T19:42:04Z")

</div>

Hello all, My question related to Is it possible today? I want to always have max date field as the default filter for a dashboard, can someone kindly assist please? Thanks!!!

---

## [Not possible to reorder sequence of processors in ingest pipelines v.8.12.2](https://discuss.elastic.co/t/not-possible-to-reorder-sequence-of-processors-in-ingest-pipelines-v-8-12-2/356461)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [March 29, 2024, 4:31pm UTC](https://discuss.elastic.co/t/not-possible-to-reorder-sequence-of-processors-in-ingest-pipelines-v-8-12-2/356461 "2024-03-29T16:31:37Z")

</div>

Seems I've lost the ability to reorder the sequence of my processors in an ingest pipeline after updating to v.8.12.2 from v.8.10.2, tried both via a filefox and chrome browser on Window$ 10, is this just me or a bug/fea…

---

## [Kibana Node.js - JavaScript run-time environment is affected by multiple vulnerabilities](https://discuss.elastic.co/t/kibana-node-js-javascript-run-time-environment-is-affected-by-multiple-vulnerabilities/356380)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 4\
**Last updated:** [March 29, 2024, 4:05pm UTC](https://discuss.elastic.co/t/kibana-node-js-javascript-run-time-environment-is-affected-by-multiple-vulnerabilities/356380 "2024-03-29T16:05:00Z")

</div>

After scanning it was discovered that Solution: Upgrade to Node.js version 18.19.1 / 20.11.1 / 21.6.2 or later. Path : /usr/share/kibana/node/bin/node Installed version : 18.18.2 Fixed version : 18.…

---

## [Wildcard pattern not working for trusted applications](https://discuss.elastic.co/t/wildcard-pattern-not-working-for-trusted-applications/356437)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 0\
**Last updated:** [March 29, 2024, 4:09am UTC](https://discuss.elastic.co/t/wildcard-pattern-not-working-for-trusted-applications/356437 "2024-03-29T04:09:25Z")

</div>

Hi I was trying to add a trusted application to a policy. Adding full path works but the moment I change it to a wildcard pattern, it stops working Eg: C:\\Users\\IEUser\\Desktop\\app.exe works fine but C:\\Users\\\*\\Desktop\\…

---

## [Combine a few rules into 1 rule](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [March 28, 2024, 10:29pm UTC](https://discuss.elastic.co/t/combine-a-few-rules-into-1-rule/356375 "2024-03-28T22:29:47Z")

</div>

Hello guys, I have a case about alerting here. so, the condition to trigger this alert is so simple. there are 3 codes that I watched using this alert which are 68, 40, X5 if code 68 appeared 10 times in 1 minute, the…

---

## [Fields in Kibana from Filebeat](https://discuss.elastic.co/t/fields-in-kibana-from-filebeat/356392)

<div class="topic-metadata">

**Author:** [@Yerbolat\_Talasbekov](https://discuss.elastic.co/u/Yerbolat_Talasbekov)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 6:39pm UTC](https://discuss.elastic.co/t/fields-in-kibana-from-filebeat/356392 "2024-03-28T18:39:55Z")

</div>

Hello EveryOne, help me please!! Can't understand why I am getting 7306 fields from Filebeat logs. Here is from Kibana Fields (7306) Scripted fields (0) Field filters (0) Relationships (0)

---

## [Export data to pdf](https://discuss.elastic.co/t/export-data-to-pdf/356191)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 5\
**Last updated:** [March 28, 2024, 4:52pm UTC](https://discuss.elastic.co/t/export-data-to-pdf/356191 "2024-03-28T16:52:00Z")

</div>

HI I want to export my charts that I visualize in kibana to pdf I can't find this option in my dashboard hwo can I export my charts to pdf ??

---

## [Unsupported Media Type - issues when trying to do a comparison of spaces components and copying over into existing space all types in one ansible script](https://discuss.elastic.co/t/unsupported-media-type-issues-when-trying-to-do-a-comparison-of-spaces-components-and-copying-over-into-existing-space-all-types-in-one-ansible-script/356409)

<div class="topic-metadata">

**Author:** [@lcarr](https://discuss.elastic.co/u/lcarr)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 4:39pm UTC](https://discuss.elastic.co/t/unsupported-media-type-issues-when-trying-to-do-a-comparison-of-spaces-components-and-copying-over-into-existing-space-all-types-in-one-ansible-script/356409 "2024-03-28T16:39:39Z")

</div>

We are migrating from one space in our kibana to another - there are over 500 elements in the one space, visualizations, queries, lens, dashboards etc. We have been able to get a file created but when we run the ansible…

---

## [Comparing two data sources in a data table or visualization?](https://discuss.elastic.co/t/comparing-two-data-sources-in-a-data-table-or-visualization/356407)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 3:24pm UTC](https://discuss.elastic.co/t/comparing-two-data-sources-in-a-data-table-or-visualization/356407 "2024-03-28T15:24:44Z")

</div>

Hello, I was wondering about how I can compare two different data sources but have the same field. For example, I want to do analysis by comparing users that are present in one data source and user that are disabled fro…

---

## [Kibana Visualize for nested field](https://discuss.elastic.co/t/kibana-visualize-for-nested-field/356299)

<div class="topic-metadata">

**Author:** [@bertugmete](https://discuss.elastic.co/u/bertugmete)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 2:47pm UTC](https://discuss.elastic.co/t/kibana-visualize-for-nested-field/356299 "2024-03-28T14:47:54Z")

</div>

I'm trying to create a visualization in Kibana where I display the data from my Elasticsearch index in a data table format. However, when I select the "Terms" aggregation, the "violation\_list" field does not appear. My g…

---

## [Number formatting of Gauge legend](https://discuss.elastic.co/t/number-formatting-of-gauge-legend/355834)

<div class="topic-metadata">

**Author:** [@bianca\_s](https://discuss.elastic.co/u/bianca_s)\
**Replies:** 3\
**Last updated:** [March 28, 2024, 7:09am UTC](https://discuss.elastic.co/t/number-formatting-of-gauge-legend/355834 "2024-03-28T07:09:57Z")

</div>

Hi all, I am trying to create a Gauge visalization but wasn't able to achieve nicely formatted numbers in the legend. The problem is, that the ranges we use are quite high numbers and hence without any formatting quite …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=59)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=61)
