# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=61

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 62

---

## [16 hours (56658224ms) were not queried between this rule execution and the last execution, so signals may have been missed. Consider increasing your look behind time or adding more Kibana instances](https://discuss.elastic.co/t/16-hours-56658224ms-were-not-queried-between-this-rule-execution-and-the-last-execution-so-signals-may-have-been-missed-consider-increasing-your-look-behind-time-or-adding-more-kibana-instances/356351)

<div class="topic-metadata">

**Author:** [@Abylay\_Kusogao](https://discuss.elastic.co/u/Abylay_Kusogao)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 5:02am UTC](https://discuss.elastic.co/t/16-hours-56658224ms-were-not-queried-between-this-rule-execution-and-the-last-execution-so-signals-may-have-been-missed-consider-increasing-your-look-behind-time-or-adding-more-kibana-instances/356351 "2024-03-28T05:02:14Z")

</div>

idk whats going on,but I have been receiving such errors since yesterday. First thought was that smth is wrong with exactly one rule, but just disabling didnt helped. Then thought smth is wrong with virtual machine an…

---

## [Kibana Iframe login working in Firefox but not in chrome](https://discuss.elastic.co/t/kibana-iframe-login-working-in-firefox-but-not-in-chrome/356348)

<div class="topic-metadata">

**Author:** [@ShreyanshPrakash](https://discuss.elastic.co/u/ShreyanshPrakash)\
**Replies:** 0\
**Last updated:** [March 28, 2024, 3:22am UTC](https://discuss.elastic.co/t/kibana-iframe-login-working-in-firefox-but-not-in-chrome/356348 "2024-03-28T03:22:48Z")

</div>

My use case is to integrate Kibana dashboard into our Web Application. I am able to make the changes and kibana login page is loading. once user submits the login form, chrome seems to fail login with 401 error while t…

---

## [Kibana Dashboards disappear on default space](https://discuss.elastic.co/t/kibana-dashboards-disappear-on-default-space/356306)

<div class="topic-metadata">

**Author:** [@ShimonB](https://discuss.elastic.co/u/ShimonB)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 4:56pm UTC](https://discuss.elastic.co/t/kibana-dashboards-disappear-on-default-space/356306 "2024-03-27T16:56:35Z")

</div>

Hello, I'm using Elastic-Kibana stack (v8.7.1) configured by docker-compose. After upgrade to version 8.8.0 - all the dashboards I configured were disappeared. Does anyone knows how to fix this ? Thanks ! Shimon. …

---

## [Kibana Dashboard elastic controls show "error not found"](https://discuss.elastic.co/t/kibana-dashboard-elastic-controls-show-error-not-found/356304)

<div class="topic-metadata">

**Author:** [@raveh](https://discuss.elastic.co/u/raveh)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 3:44pm UTC](https://discuss.elastic.co/t/kibana-dashboard-elastic-controls-show-error-not-found/356304 "2024-03-27T15:44:21Z")

</div>

I'm experiencing the same issue as Elastic Controls show error - Not Found Which was closed. Was there a fix implemented?

---

## [Hide Elastic managed dashboards](https://discuss.elastic.co/t/hide-elastic-managed-dashboards/356279)

<div class="topic-metadata">

**Author:** [@jsteenkamp](https://discuss.elastic.co/u/jsteenkamp)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 12:10pm UTC](https://discuss.elastic.co/t/hide-elastic-managed-dashboards/356279 "2024-03-27T12:10:50Z")

</div>

Starting release 8.13.0 Elastic managed dashboards can no longer be deleted (listed in the release notes). We don't use any and personally I find that annoying. Is there an option to at least hide the managed dashboard…

---

## [Kibana8.10 connet elasticsearch8.10 token 验证还要账户kibana\_system和密码登录](https://discuss.elastic.co/t/kibana8-10-connet-elasticsearch8-10-token-kibana-system/356238)

<div class="topic-metadata">

**Author:** [@chenkang404](https://discuss.elastic.co/u/chenkang404)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 8:22am UTC](https://discuss.elastic.co/t/kibana8-10-connet-elasticsearch8-10-token-kibana-system/356238 "2024-03-27T08:22:10Z")

</div>

为什么不能用elastic用户，从哪里获得账户kibana\_system的密码

---

## [Kibana/Dashboard Zoom Settings](https://discuss.elastic.co/t/kibana-dashboard-zoom-settings/356213)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 11:33pm UTC](https://discuss.elastic.co/t/kibana-dashboard-zoom-settings/356213 "2024-03-26T23:33:00Z")

</div>

Hello, I am wondering if there's away to change the zoom settings of Kibana, specifically dashboards? It feels like depending on your computer monitor, the dashboards can look distortional. Also, It feels like the das…

---

## [ELK Stack on VM directly or docker environment using docker swarm](https://discuss.elastic.co/t/elk-stack-on-vm-directly-or-docker-environment-using-docker-swarm/356188)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [March 26, 2024, 6:46pm UTC](https://discuss.elastic.co/t/elk-stack-on-vm-directly-or-docker-environment-using-docker-swarm/356188 "2024-03-26T18:46:01Z")

</div>

Hello, I'm looking advice regarding the deployment of the ELK stack and Fleet Server. Should I opt for directly deploying them on virtual machines (VMs) or utilize a Docker environment with Docker Swarm to deploy all se…

---

## [Parsing Clamscan logs when redirecting logs to Kibana using Filebeat](https://discuss.elastic.co/t/parsing-clamscan-logs-when-redirecting-logs-to-kibana-using-filebeat/356202)

<div class="topic-metadata">

**Author:** [@Cexico](https://discuss.elastic.co/u/Cexico)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 6:30pm UTC](https://discuss.elastic.co/t/parsing-clamscan-logs-when-redirecting-logs-to-kibana-using-filebeat/356202 "2024-03-26T18:30:28Z")

</div>

what should I do to understand the clamscan result that I do in the terminal in kibana logs normally? how should I do the parsing part, write a grok filter?

---

## [Dev Tools console not maintaining prefix\_path v8.12.2](https://discuss.elastic.co/t/dev-tools-console-not-maintaining-prefix-path-v8-12-2/354975)

<div class="topic-metadata">

**Author:** [@B\_Blank](https://discuss.elastic.co/u/B_Blank)\
**Replies:** 4\
**Last updated:** [March 26, 2024, 1:53pm UTC](https://discuss.elastic.co/t/dev-tools-console-not-maintaining-prefix-path-v8-12-2/354975 "2024-03-26T13:53:58Z")

</div>

I'm seeing in Kibana 8.12.2 that the prefix\_path is being dropped by Dev Tools Console commands. i.e. the "/kibana" in the example below. kibana.yml elasticsearch.hosts: "server.mydomain.com:443/kibana In Dev Tools C…

---

## [Import saved object of type "apm-indices" does not work correctly](https://discuss.elastic.co/t/import-saved-object-of-type-apm-indices-does-not-work-correctly/356174)

<div class="topic-metadata">

**Author:** [@fuphil](https://discuss.elastic.co/u/fuphil)\
**Replies:** 1\
**Last updated:** [March 26, 2024, 1:45pm UTC](https://discuss.elastic.co/t/import-saved-object-of-type-apm-indices-does-not-work-correctly/356174 "2024-03-26T13:45:41Z")

</div>

Hi, I am running version 8.12.2 and have an issue with the import of a saved object of type "apm-indices". It is not possible to set the attribute "apmIndices", it is always empty. API: /s/myspace/api/saved\_objects/\_i…

---

## [I can't create this metric in my kibana dashboard](https://discuss.elastic.co/t/i-cant-create-this-metric-in-my-kibana-dashboard/356177)

<div class="topic-metadata">

**Author:** [@Federico\_Ruso](https://discuss.elastic.co/u/Federico_Ruso)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 12:44pm UTC](https://discuss.elastic.co/t/i-cant-create-this-metric-in-my-kibana-dashboard/356177 "2024-03-26T12:44:35Z")

</div>

I want to create a metric that outputs the rounded value in red but i can't. I try with various forms of formulas, but none worked. The last one was this sum(uc\_pend / overall\_sum(uc\_pend) \* dias) Thks!

---

## [Kibana API call unathorized](https://discuss.elastic.co/t/kibana-api-call-unathorized/355915)

<div class="topic-metadata">

**Author:** [@h.d.intodata](https://discuss.elastic.co/u/h.d.intodata)\
**Replies:** 2\
**Last updated:** [March 26, 2024, 10:47am UTC](https://discuss.elastic.co/t/kibana-api-call-unathorized/355915 "2024-03-26T10:47:35Z")

</div>

Hi team, I have a series of dashboards that i need to copy from one kibana server to another. I tried using POST http://\<ip\_address\>:\<kibana\_port\>/api/saved\_objects/\_export However, all i get is { "statusCode": 4…

---

## [Unable to format rule/alert in Kibana](https://discuss.elastic.co/t/unable-to-format-rule-alert-in-kibana/354730)

<div class="topic-metadata">

**Author:** [@Nikhil\_SA](https://discuss.elastic.co/u/Nikhil_SA)\
**Replies:** 3\
**Last updated:** [March 26, 2024, 9:52am UTC](https://discuss.elastic.co/t/unable-to-format-rule-alert-in-kibana/354730 "2024-03-26T09:52:33Z")

</div>

I'm using a email connector for action in our rule and I'm unable to format the alert mail body. This is creating very clumsy mail being sent which is not at all appealing to the customer. How to format the alert proper…

---

## [Elastic Agent Unhealthy - No valid comms client available](https://discuss.elastic.co/t/elastic-agent-unhealthy-no-valid-comms-client-available/356133)

<div class="topic-metadata">

**Author:** [@Kreb](https://discuss.elastic.co/u/Kreb)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 1:40am UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy-no-valid-comms-client-available/356133 "2024-03-26T01:40:36Z")

</div>

When I install the elastic agent onto a Ubuntu machine through Security Onion the device will check in as healthy for about 30 seconds and then it will go to an Unhealthy state. I have installed the agent on another Ubun…

---

## [Error fetching fields for data view](https://discuss.elastic.co/t/error-fetching-fields-for-data-view/356018)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 3\
**Last updated:** [March 25, 2024, 6:58pm UTC](https://discuss.elastic.co/t/error-fetching-fields-for-data-view/356018 "2024-03-25T18:58:20Z")

</div>

Update: I've resolved the CSP and 403 errors I saw, but now am being blocked by this: https://elk-1.XXXXX.com/internal/data\_views/\_fields\_for\_wildcard?pattern=ecs-logstash-\*&meta\_fields=\_source&meta\_fields=\_id&meta\_fiel…

---

## [Kibana Dashboards Gallery](https://discuss.elastic.co/t/kibana-dashboards-gallery/355950)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [March 25, 2024, 4:27pm UTC](https://discuss.elastic.co/t/kibana-dashboards-gallery/355950 "2024-03-25T16:27:39Z")

</div>

Hello, I don't believe this exists but is there a way where we can have a repository of custom dashboards, where people can share all their own creations. It would help alot of people to use other dashboards as templat…

---

## [How to create a hidden control to my dashboard?](https://discuss.elastic.co/t/how-to-create-a-hidden-control-to-my-dashboard/356005)

<div class="topic-metadata">

**Author:** [@Federico\_Ruso](https://discuss.elastic.co/u/Federico_Ruso)\
**Replies:** 6\
**Last updated:** [March 25, 2024, 2:26pm UTC](https://discuss.elastic.co/t/how-to-create-a-hidden-control-to-my-dashboard/356005 "2024-03-25T14:26:58Z")

</div>

Hello, i need to create a hidden control to my dashboard. I'm using ES v 8.12.1. Thks!!

---

## [SNOW connector to create cases instead of incidents](https://discuss.elastic.co/t/snow-connector-to-create-cases-instead-of-incidents/356096)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 1:30pm UTC](https://discuss.elastic.co/t/snow-connector-to-create-cases-instead-of-incidents/356096 "2024-03-25T13:30:03Z")

</div>

Hi guys, I want to use the SNOW connector to, after create a case in elastic, create case or incident on SNOW depending on the situation. I know it only creates a incident right now, is there any possibility to create a…

---

## [How to group or merge multiple fields to one field name](https://discuss.elastic.co/t/how-to-group-or-merge-multiple-fields-to-one-field-name/355985)

<div class="topic-metadata">

**Author:** [@Aton](https://discuss.elastic.co/u/Aton)\
**Replies:** 7\
**Last updated:** [March 25, 2024, 10:31am UTC](https://discuss.elastic.co/t/how-to-group-or-merge-multiple-fields-to-one-field-name/355985 "2024-03-25T10:31:40Z")

</div>

hi, I have a problem, I have several fields with similar names, for example: rest.direction, mmu.direction, xml.direction, and I need them to be displayed in Kiban only under one field, for example "direction". Is it po…

---

## [O365 integration Return Wrong data Types](https://discuss.elastic.co/t/o365-integration-return-wrong-data-types/355276)

<div class="topic-metadata">

**Author:** [@rajith\_pathiraja](https://discuss.elastic.co/u/rajith_pathiraja)\
**Replies:** 3\
**Last updated:** [March 25, 2024, 7:35am UTC](https://discuss.elastic.co/t/o365-integration-return-wrong-data-types/355276 "2024-03-25T07:35:56Z")

</div>

Hi I have tried to integrate Microsoft O365 with Elastic and i have followed the given instruction but still didnt get log details return. So i tried using Dev tools and saw im getting below " { "statusCode": 400, "er…

---

## [Problem with data transformation for vega visualization](https://discuss.elastic.co/t/problem-with-data-transformation-for-vega-visualization/356051)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 0\
**Last updated:** [March 24, 2024, 9:30am UTC](https://discuss.elastic.co/t/problem-with-data-transformation-for-vega-visualization/356051 "2024-03-24T09:30:29Z")

</div>

Hello, I'm trying to create a network graph that can display domains, IPs, subdomains, etc. and associated links. For this, I found a code sample that allows you to draw this kind of graph: LINK So I transformed my dat…

---

## [Elastic, kibana alerting](https://discuss.elastic.co/t/elastic-kibana-alerting/356049)

<div class="topic-metadata">

**Author:** [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Replies:** 0\
**Last updated:** [March 24, 2024, 7:20am UTC](https://discuss.elastic.co/t/elastic-kibana-alerting/356049 "2024-03-24T07:20:39Z")

</div>

Hi, i try to find way how to manage security alerts in kibana. Only option right now is just open case or close a alerts. Case system is really complicated and waste of time its a fault positive. I need something like:…

---

## [HTTP 502 into APM service metrics](https://discuss.elastic.co/t/http-502-into-apm-service-metrics/356015)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 0\
**Last updated:** [March 22, 2024, 6:03pm UTC](https://discuss.elastic.co/t/http-502-into-apm-service-metrics/356015 "2024-03-22T18:03:51Z")

</div>

Hello guys. I have an elastic apm implemented in my environment. When I try to get metrics on service with time range, like one week, after waiting time, I got a 502 error on kibana. This error don't happen in time ran…

---

## [Re-install Kibana](https://discuss.elastic.co/t/re-install-kibana/355993)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 0\
**Last updated:** [March 22, 2024, 2:24pm UTC](https://discuss.elastic.co/t/re-install-kibana/355993 "2024-03-22T14:24:25Z")

</div>

I have a working Elasticsearch installation with Logstash-fed data. I am having problems with Kibana and am at the point where I want to reinstall it from scratch. I've read that I can delete all .kibana\* indexes, and a …

---

## [Regarding the logstash cacerts issue](https://discuss.elastic.co/t/regarding-the-logstash-cacerts-issue/355961)

<div class="topic-metadata">

**Author:** [@HSc](https://discuss.elastic.co/u/HSc)\
**Replies:** 1\
**Last updated:** [March 22, 2024, 12:24pm UTC](https://discuss.elastic.co/t/regarding-the-logstash-cacerts-issue/355961 "2024-03-22T12:24:08Z")

</div>

Hi, I am new to ELK. As i am using beats to send logs to logstash and then to elasticsearch but the issue is when i run the logstash as service then the status is running but when i went to logs of logstash it shows.. e…

---

## [Custom API Integration Pagination](https://discuss.elastic.co/t/custom-api-integration-pagination/355978)

<div class="topic-metadata">

**Author:** [@Jiawei\_Cheah](https://discuss.elastic.co/u/Jiawei_Cheah)\
**Replies:** 1\
**Last updated:** [March 22, 2024, 10:09am UTC](https://discuss.elastic.co/t/custom-api-integration-pagination/355978 "2024-03-22T10:09:27Z")

</div>

Hi, i am running issues when i am trying to achieve pagination within this API. In this case, I have indicated that if the offset is not equal to the total, the offset number will increment by 100 for the next call. Th…

---

## [Kibana - Aggregation based - "Show values on chart" doesn't work correctly](https://discuss.elastic.co/t/kibana-aggregation-based-show-values-on-chart-doesnt-work-correctly/355969)

<div class="topic-metadata">

**Author:** [@JenniferL](https://discuss.elastic.co/u/JenniferL)\
**Replies:** 2\
**Last updated:** [March 22, 2024, 8:52am UTC](https://discuss.elastic.co/t/kibana-aggregation-based-show-values-on-chart-doesnt-work-correctly/355969 "2024-03-22T08:52:48Z")

</div>

Hi evryone :blush: I'm using the "aggregation based" visualisation on my Dashboard, specifically the Vertical bar chart and I have something very strange which is happening: I'm using the "Show values on chart" button o…

---

## [Imported Grafana csv to CPU Dashboard?](https://discuss.elastic.co/t/imported-grafana-csv-to-cpu-dashboard/355835)

<div class="topic-metadata">

**Author:** [@Bit\_Addict](https://discuss.elastic.co/u/Bit_Addict)\
**Replies:** 1\
**Last updated:** [March 22, 2024, 8:01am UTC](https://discuss.elastic.co/t/imported-grafana-csv-to-cpu-dashboard/355835 "2024-03-22T08:01:04Z")

</div>

Hi guys, I need some help on this one: I exported a csv file from Grafana, only fields are "time" and "cpu", delimited by a comma, example lines: 2024-03-13 12:15:00,38% 2024-03-13 12:30:00,34% 2024-03-13 12:45:00,35%…

---

## [Scripted field - script doesn't runs all the keys in my document](https://discuss.elastic.co/t/scripted-field-script-doesnt-runs-all-the-keys-in-my-document/355585)

<div class="topic-metadata">

**Author:** [@JenniferL](https://discuss.elastic.co/u/JenniferL)\
**Replies:** 8\
**Last updated:** [March 22, 2024, 7:53am UTC](https://discuss.elastic.co/t/scripted-field-script-doesnt-runs-all-the-keys-in-my-document/355585 "2024-03-22T07:53:42Z")

</div>

Hey All! I'm new here, I hope I will be clear on my request :nerd\_face: So I'm creating a scripted field on my index Pattern. I have multiple documents and in each documents there are multiple keys. What I want is: if …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=60)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=62)
