# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=71

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 72

---

## [Kibana oidc (azure) role assignment not working (too many groups)](https://discuss.elastic.co/t/kibana-oidc-azure-role-assignment-not-working-too-many-groups/350568)

<div class="topic-metadata">

**Author:** [@rafi0101](https://discuss.elastic.co/u/rafi0101)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 12:15pm UTC](https://discuss.elastic.co/t/kibana-oidc-azure-role-assignment-not-working-too-many-groups/350568 "2024-02-02T12:15:11Z")

</div>

I am using Kibana/Elasticsearch with Oidc (Microsoft Azure) for authentication. Currently I have the problem that not all defined role mappings are working correctly. We are using Azure groups in role mappings to assig…

---

## [Kibana.yml file with server.host having integer host name issue](https://discuss.elastic.co/t/kibana-yml-file-with-server-host-having-integer-host-name-issue/351946)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 4:24am UTC](https://discuss.elastic.co/t/kibana-yml-file-with-server-host-having-integer-host-name-issue/351946 "2024-02-02T04:24:31Z")

</div>

I am getting Fatal Error with invalid host name for Kibana service because of server has host name starting with integer. Any idea why Kibana service doesnt like host name starting with integer because as per RFC 1123, …

---

## [Schedule backup using kibana](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:10am UTC](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266 "2024-02-02T04:10:03Z")

</div>

Hi Team, I schedule a job on Kibana to take schedule backup. the job should be fire every day 15:00pm for that my cron expression is 0 0 15 ? \* \* but on Kibana it is showing 08:30pm

---

## [Kibana service giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 4:02am UTC](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913 "2024-02-02T04:02:00Z")

</div>

On the VM where we have installed Elasticsearch and Kibana service, Kibana service is giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error. After troubleshootin…

---

## [Webhook connector generated invalid """ json elements](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 2:18am UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950 "2024-02-02T02:18:41Z")

</div>

Hi, I'm using the webhook connector to send some JSON data to a webhook destination whenever a rule triggers. One of the JSON fields I'm sending is multiline, but anytime I try to embed \\ns in the JSON, kibana converts…

---

## [JAVA APM Agent, System CPU reporting with java 8](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326)

<div class="topic-metadata">

**Author:** [@Yasim\_Zeballos](https://discuss.elastic.co/u/Yasim_Zeballos)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:07pm UTC](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326 "2024-02-01T16:07:27Z")

</div>

Kibana version: 7.17.X Elasticsearch version: 7.17.X APM Server version: 7.17.X jar java agent: opentelemetry-javaagent-2.0.0.jar Java version: Java 8 As image shows, only thread count is shown. Why CPU usage is…

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299)

<div class="topic-metadata">

**Author:** [@Twobuy1](https://discuss.elastic.co/u/Twobuy1)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299 "2024-02-01T14:03:56Z")

</div>

Elasticsearch starts up good then when i open up kibana i start gettting this issue. Please keep aware this is my first time doing this and new to any type of code. \[2024-02-01T05:55:42.170-08:00\]\[INFO \]\[plugins.alertin…

---

## [Help with my Query :)](https://discuss.elastic.co/t/help-with-my-query/351975)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:46pm UTC](https://discuss.elastic.co/t/help-with-my-query/351975 "2024-02-01T13:46:28Z")

</div>

Can anyone advise where im going wrong with my query ? I am trying to achieve the following: Generate an Alert whenever event.code 4648 is seen - with the only exception being to not alert if the winlog.event\_data.Subj…

---

## [How to set precision\_threshold in Kibana 8.10 version](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904)

<div class="topic-metadata">

**Author:** [@Sagesh](https://discuss.elastic.co/u/Sagesh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:45pm UTC](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904 "2024-02-01T13:45:04Z")

</div>

Precision\_threshold is not working in Kibana 8.10.2 version. I tried providing it in Advance Json like "{ "precision\_threshold":4000} but it throws an error. Thanks, Sagesh

---

## [How can a Threshold line be provided on a Vertical bar graph in Kibana?](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259)

<div class="topic-metadata">

**Author:** [@Pushpender\_Singh](https://discuss.elastic.co/u/Pushpender_Singh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:33pm UTC](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259 "2024-02-01T13:33:07Z")

</div>

Hi Elastic Community, I am not able to get a threshold line on my Vertical bar graph, after selecting "Show Threshold Line" and configuring Panel Settings as shown below. Even after I update all the details as shown bel…

---

## [Snapshot policy snapshot name as uniq ID](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:29pm UTC](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279 "2024-02-01T12:29:50Z")

</div>

Hi Team, here is my snapshot policy snapshot name math expression \<test-snap-{now{MM-dd-yyyy\_HH-mm|Asia/Kolkata}}\> so the result should be test-snap-02-01-2024\_17-09 but in kibana UI the snapshot name showing as test-s…

---

## [Get the result of split two values into alert or another value](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:01pm UTC](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645 "2024-02-01T12:01:13Z")

</div>

I have data with 2 variables, one is the total number of http response code and another is only the total of http response code with the value of "200". the structure is the result of transform the result is like this …

---

## [Stylizing TSVB or Lens in Canvas](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459)

<div class="topic-metadata">

**Author:** [@Tom-Gorup](https://discuss.elastic.co/u/Tom-Gorup)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:54am UTC](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459 "2024-02-01T11:54:43Z")

</div>

Running into a few challenges as I attempt to tackle this problem in myriad ways. First, my desired outcome is a (1) stylized horizontal bar chart using percentage (2) as the value for each aggregated row while includin…

---

## [log whoever connects to the kibana web interface](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222)

<div class="topic-metadata">

**Author:** [@clocker87](https://discuss.elastic.co/u/clocker87)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 9:44am UTC](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222 "2024-02-01T09:44:58Z")

</div>

Hi everyone, I need to have logs of who connects to the kibana web interface, I have several accounts and I would like to be able to monitor these accesses. I have kibana version 8.3.2, what can I do? Thank you

---

## [How to create Sub categories in Data table?](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117)

<div class="topic-metadata">

**Author:** [@Shubhankar](https://discuss.elastic.co/u/Shubhankar)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 8:05pm UTC](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117 "2024-01-31T20:05:20Z")

</div>

I have generated a data table using the Kibana 8 lens visualization, but I'm uncertain about adding subcategories to it. Specifically, after including the necessary columns, I aim to further segment the data from the sec…

---

## [Unable to download Kibana Windows Winzip](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365)

<div class="topic-metadata">

**Author:** [@SPT](https://discuss.elastic.co/u/SPT)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 5:29pm UTC](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365 "2024-01-31T17:29:46Z")

</div>

I tried to extract the zip file but it complains that the path is too long on some files. Any advice or an alternate option to get this? Thanks.

---

## [Creating Secrets in Elastic Fleet](https://discuss.elastic.co/t/creating-secrets-in-elastic-fleet/352116)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 4:01pm UTC](https://discuss.elastic.co/t/creating-secrets-in-elastic-fleet/352116 "2024-01-31T16:01:56Z")

</div>

I'm using Elastic Cloud v8.12.0. Documentation for Fleet gives instructions on how to use a Fleet secret in an integration policy, but how to I actually CREATE one? I can't find the information in the documentation. E…

---

## [Loop array in table markdown canvas kibana](https://discuss.elastic.co/t/loop-array-in-table-markdown-canvas-kibana/351116)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 3:24pm UTC](https://discuss.elastic.co/t/loop-array-in-table-markdown-canvas-kibana/351116 "2024-01-31T15:24:28Z")

</div>

Hello friend I have array value example arr = \[1, 4, 7\] and in canvas kibana i want to loop array in markdown here my code expression {{#each rows}} | All In Array | |---------------| {{arr}} {{/each}} but it loop …

---

## [PUT aliases for multiple index](https://discuss.elastic.co/t/put-aliases-for-multiple-index/350654)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 2:02pm UTC](https://discuss.elastic.co/t/put-aliases-for-multiple-index/350654 "2024-01-31T14:02:53Z")

</div>

Hello. I am changing the organization of the indexes in my cluster. I have added an alias to the template and from now all indexes I need will get a correct view alias. But I have a bunch (1k of them) without view alia…

---

## [Vertical Data Tables](https://discuss.elastic.co/t/vertical-data-tables/351895)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 11:56pm UTC](https://discuss.elastic.co/t/vertical-data-tables/351895 "2024-01-30T23:56:28Z")

</div>

Hello, Currently, we can create data tables (horizontal) via Lens. Will it be possible to create a vertical data table in the future? Example:

---

## [Aggregate by time only](https://discuss.elastic.co/t/aggregate-by-time-only/351063)

<div class="topic-metadata">

**Author:** [@Maiky](https://discuss.elastic.co/u/Maiky)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 8:27pm UTC](https://discuss.elastic.co/t/aggregate-by-time-only/351063 "2024-01-30T20:27:49Z")

</div>

I would like to do a count of the amount of log entries over a certain time window, let's say one hour buckets. So log entries from monday 3-4pm should be counted with those from tuesday 3-4pm etc. I have a timestamp fi…

---

## [Kibana error, assumed Required Throughput Per Minute Per Kibana](https://discuss.elastic.co/t/kibana-error-assumed-required-throughput-per-minute-per-kibana/352104)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:04pm UTC](https://discuss.elastic.co/t/kibana-error-assumed-required-throughput-per-minute-per-kibana/352104 "2024-01-30T17:04:54Z")

</div>

Hi, Im getting this error from kibana: setting HealthStatus.Error because assumed Required Throughput Per Minute Per Kibana (46.54236111111111) \>= capacityPerMinutePerKibana (18) AND assumedAverageRecurringRequiredThroug…

---

## [Fleet Agent Upgrade](https://discuss.elastic.co/t/fleet-agent-upgrade/351053)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 8\
**Last updated:** [January 30, 2024, 12:11pm UTC](https://discuss.elastic.co/t/fleet-agent-upgrade/351053 "2024-01-30T12:11:31Z")

</div>

When using Fleet to upgrade the Elastic Agent, Kibana and Elasticsearch needed to bu upgraded first, before the Agent Upgrade becomes available according to the docs. If I upgrade Kibana/Elasticsearch from 8.11.1 to 8.1…

---

## [Kibana role privileges in upgrade 7.15.2 to 7.17.10](https://discuss.elastic.co/t/kibana-role-privileges-in-upgrade-7-15-2-to-7-17-10/350589)

<div class="topic-metadata">

**Author:** [@rcopping](https://discuss.elastic.co/u/rcopping)\
**Replies:** 4\
**Last updated:** [January 30, 2024, 11:14am UTC](https://discuss.elastic.co/t/kibana-role-privileges-in-upgrade-7-15-2-to-7-17-10/350589 "2024-01-30T11:14:59Z")

</div>

Hi Team, We have recently upgrade from 7.15.2 to 7.17.10 and it appears the privileges hierarchy has changed . We used to use the following for a dashboard role to manage dashboard editing in kibana and this had runtim…

---

## [Unable to parse watcher payload field which contains a json](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157)

<div class="topic-metadata">

**Author:** [@AlekseyK](https://discuss.elastic.co/u/AlekseyK)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:55am UTC](https://discuss.elastic.co/t/unable-to-parse-watcher-payload-field-which-contains-a-json/351157 "2024-01-30T10:55:06Z")

</div>

Hello, I have a watcher that works perfectly fine and when executed I get an email in html format listing basic string and numeric fields I chose to select from a hit. I use a webhook action to email the results. Now, I…

---

## [URL templating - Is it possible to split the output of event.values?](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:29am UTC](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659 "2024-01-30T05:29:49Z")

</div>

Hi there! I'm working on a "Table row click" drill down for one of my Lens tables, my goal is to have a drill down off a hidden field (report Id) to make it easier for the users. the event.values variable return an arr…

---

## [EFK Deployment on Openshift](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053)

<div class="topic-metadata">

**Author:** [@bkrraj](https://discuss.elastic.co/u/bkrraj)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 4:47am UTC](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053 "2024-01-30T04:47:14Z")

</div>

Hi , We are planning to Implement EFK on our PROD RedHat OpenShift cluster. Can anyone help us with the steps. Thanks Bala

---

## [How to send JSON body in rule?](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768)

<div class="topic-metadata">

**Author:** [@navin547](https://discuss.elastic.co/u/navin547)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 3:45pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768 "2024-01-29T15:45:43Z")

</div>

Hi, I have created a webhook connector which uses servicenow api to send, then I have created a rule and used that webhook connector so whenever that rule trigger I need to send that alert data in body as a JSON as ser…

---

## [No output shown in Metric Explorer or Inventory but Metricbeat is running](https://discuss.elastic.co/t/no-output-shown-in-metric-explorer-or-inventory-but-metricbeat-is-running/351871)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 9:10am UTC](https://discuss.elastic.co/t/no-output-shown-in-metric-explorer-or-inventory-but-metricbeat-is-running/351871 "2024-01-29T09:10:21Z")

</div>

Hi, i deployed metricbeat on Kubernetes Cluster but when i want to see metrics in Metric Explorer or Inventory it's showing nothing But metricbeat is still running without error

---

## [Kibana server is not ready](https://discuss.elastic.co/t/kibana-server-is-not-ready/351652)

<div class="topic-metadata">

**Author:** [@prajeet](https://discuss.elastic.co/u/prajeet)\
**Replies:** 1\
**Last updated:** [January 29, 2024, 8:31am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready/351652 "2024-01-29T08:31:02Z")

</div>

Hi, I have created a new elastic, Kibana and logstash instances on RHEL. They are not clustered and elastic responds to curl. I have used server host name for elastic server.hostname with port 9200. But when it comes to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=70)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=72)
