# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=74

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 75

---

## [Changing xpack settings via API](https://discuss.elastic.co/t/changing-xpack-settings-via-api/351316)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [January 18, 2024, 5:09am UTC](https://discuss.elastic.co/t/changing-xpack-settings-via-api/351316 "2024-01-18T05:09:07Z")

</div>

Hi, I wish to increase the timeout for CSV report generation on Kibana, but I don't have access to the kibana.yml file to change the xpack.reporting.queue.timeout value. Is there a way I can change it via the API method…

---

## [Read Only to Everything in Elastic/Kibana](https://discuss.elastic.co/t/read-only-to-everything-in-elastic-kibana/351089)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 5\
**Last updated:** [January 17, 2024, 9:03pm UTC](https://discuss.elastic.co/t/read-only-to-everything-in-elastic-kibana/351089 "2024-01-17T21:03:27Z")

</div>

Is there a quick/easy setting in Kibana Roles that would give a user full read only permissions to everything within the Elastic Stack? Basically, I want to create a user with a Role where they can see everything an adm…

---

## [GET \_cat/recovery How to display just 3 columns and where files\_percent \> 90%?](https://discuss.elastic.co/t/get-cat-recovery-how-to-display-just-3-columns-and-where-files-percent-90/351307)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 8:57pm UTC](https://discuss.elastic.co/t/get-cat-recovery-how-to-display-just-3-columns-and-where-files-percent-90/351307 "2024-01-17T20:57:01Z")

</div>

GET \_cat/recovery How to display just 3 columns and where files\_percent \> 90% ?

---

## [maxBodyLength limit](https://discuss.elastic.co/t/maxbodylength-limit/351162)

<div class="topic-metadata">

**Author:** [@fdranger](https://discuss.elastic.co/u/fdranger)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 5:03pm UTC](https://discuss.elastic.co/t/maxbodylength-limit/351162 "2024-01-17T17:03:11Z")

</div>

log: callAsCurrentUser:scroll|{"scrollId":"DXF1ZXJ5QW5kRmV0Y2gBAAAAAAA\_Q-QWOHdpMWswdlRUamlNX0hoVDBWUFowZw==","scroll":"1m","headers":{"x-kbn-domain":"\*\*\*\*\*\*","x-kbn-user":"\*\*\*\*\*\*"}};;undefined {"type":"log","@timestamp"…

---

## [Linux change monitoring](https://discuss.elastic.co/t/linux-change-monitoring/351281)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 2:04pm UTC](https://discuss.elastic.co/t/linux-change-monitoring/351281 "2024-01-17T14:04:20Z")

</div>

Hi there, what is the best way to monitor any changes made to an linux server ? I am trying to think of the most efficient way of capturing from a very broad perspective of linux changes.

---

## [Kibana v8.6.0 docker image build fails](https://discuss.elastic.co/t/kibana-v8-6-0-docker-image-build-fails/350851)

<div class="topic-metadata">

**Author:** [@salman\_kh](https://discuss.elastic.co/u/salman_kh)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 8:28am UTC](https://discuss.elastic.co/t/kibana-v8-6-0-docker-image-build-fails/350851 "2024-01-17T08:28:36Z")

</div>

Hello, I'm attempting to build a Kibana Docker image from the source code, specifically for version 8.6.0. However, I'm encountering an error. I followed the same procedure for this version a couple of months ago but di…

---

## [Able to Calculate Metrics, Unable to Visualize as Graphs \[beginner\]](https://discuss.elastic.co/t/able-to-calculate-metrics-unable-to-visualize-as-graphs-beginner/351146)

<div class="topic-metadata">

**Author:** [@Scharka](https://discuss.elastic.co/u/Scharka)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 8:47am UTC](https://discuss.elastic.co/t/able-to-calculate-metrics-unable-to-visualize-as-graphs-beginner/351146 "2024-01-17T08:47:54Z")

</div>

I'm new to Kibana, and I can't seem to figure out a completely trivial thing. Can you please point me in the right direction? I tried searching & googling, but I was not able to move on for more days. Minimal working ex…

---

## [Kibana Lens Dashboard Link Broken 404 Dashboard Not Found](https://discuss.elastic.co/t/kibana-lens-dashboard-link-broken-404-dashboard-not-found/350980)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 5\
**Last updated:** [January 16, 2024, 9:59pm UTC](https://discuss.elastic.co/t/kibana-lens-dashboard-link-broken-404-dashboard-not-found/350980 "2024-01-16T21:59:27Z")

</div>

Note: It may be necessary to check the user permissions first. TL/DR 1. (Hamburger Menu) --\> Stack Management --\> Saved Objects 2. Select the dashboard and Export 3. Open with Notepad++, CTRL +F, change the Search Mo…

---

## [Unable to retrieve version information from Elasticsearch nodes. security\_exception](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/350524)

<div class="topic-metadata">

**Author:** [@unknownuser](https://discuss.elastic.co/u/unknownuser)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 3:20pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/350524 "2024-01-16T15:20:56Z")

</div>

Hi Pal, I recently encountered an issue from my Kibana 8.11.1 version upgrade. The token I used is from monitoring node, this is for the kibana and monitoring connections. However, the kibana UI shows "Kibana server is …

---

## [Does single node Elasticsearch supports ILM ploicy](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 41\
**Last updated:** [January 15, 2024, 6:46pm UTC](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124 "2024-01-15T18:46:05Z")

</div>

Hello, I have applied the ILM policy because the disk space usage was seen very high. But I don't see any changes in the disk space after implementing the ILM policy for filebeat. shards disk.indices disk.used disk.to…

---

## [Saved Objects link disappeared except the default space](https://discuss.elastic.co/t/saved-objects-link-disappeared-except-the-default-space/350992)

<div class="topic-metadata">

**Author:** [@Zakwan\_hajjar](https://discuss.elastic.co/u/Zakwan_hajjar)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 4:39pm UTC](https://discuss.elastic.co/t/saved-objects-link-disappeared-except-the-default-space/350992 "2024-01-15T16:39:56Z")

</div>

I'm using the latest stable version 8.11.4 and I have a strange case in Kibana that I don't have an option for "Saved Objects". This problem exists in all spaces except the default space. I am logged in as root user so I…

---

## [Question about Kibana connectors](https://discuss.elastic.co/t/question-about-kibana-connectors/351081)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 4:23pm UTC](https://discuss.elastic.co/t/question-about-kibana-connectors/351081 "2024-01-15T16:23:05Z")

</div>

Hello, I was wandering, the kibana email connetor, is assume that's different from xpack.notification.email namespace in \`elasticsearch.yml. So from a watcher I can only use the xpack one? KR Henk

---

## [How to save a time range in kibana?](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 4:12pm UTC](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065 "2024-01-15T16:12:28Z")

</div>

I've seen in some kibana instances that instead of selecting the preconfigured range (1 day, 7 days, etc) you can store a custom timerange with a name. Any idea how to do it?

---

## [Kibana not starting & Cluster Status Yellow](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052 "2024-01-15T10:27:18Z")

</div>

Hi guys, Could you help me, why my kibana not starting, and im check the cluster status Yellow? Collect in elastic Log : \[2024-01-14T22:53:17,827\]\[INFO \]\[o.e.i.m.MapperService \] \[Desktop\] \[.kibana-observability-ai-…

---

## [Error connecting to package registry : reason: self-signed certificate in certificate chain](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 8:40am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057 "2024-01-15T08:40:52Z")

</div>

Hello everyone ! I have this issue when i start Kibana. I saw different solution on linux but not on windows and I work on windows Failed to fetch latest version of synthetics from registry: Error connecting to package…

---

## [Configure elastic search query to alert when the average of Total time taken exceeds a threshold](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274)

<div class="topic-metadata">

**Author:** [@Vanya](https://discuss.elastic.co/u/Vanya)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 6:02am UTC](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274 "2024-01-15T06:02:47Z")

</div>

Hi All, I am trying to write a search query for Kibana rules for it to alert when the average of the total time taken exceeds a certain thereshold. Have tried using aggegators, filters and also scripts but on testing th…

---

## [Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 3:15am UTC](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540 "2024-01-15T03:15:18Z")

</div>

Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[actions-logs\] does not point to index \[actions-logs\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 7\
**Last updated:** [January 14, 2024, 11:04am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-actions-logs-does-not-point-to-index-actions-logs/350916 "2024-01-14T11:04:16Z")

</div>

Got a template with this { "index": { "lifecycle": { "name": "logstash-policy", "rollover\_alias": "actions-logs" }, "number\_of\_replicas": "0" } } Got index with name "actions-logs" But at index "actiong-logs…

---

## [Do not alert for no data for decommissioned server](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997)

<div class="topic-metadata">

**Author:** [@Kodito](https://discuss.elastic.co/u/Kodito)\
**Replies:** 4\
**Last updated:** [January 13, 2024, 10:41am UTC](https://discuss.elastic.co/t/do-not-alert-for-no-data-for-decommissioned-server/350997 "2024-01-13T10:41:08Z")

</div>

My cluster fires a kibana alert when there is no metricbeat data for a server for the last 15 minutes, which is very useful in the case where there is an issue with the beat/server. However, when a server is decommissio…

---

## [Toggling rules on or off](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435)

<div class="topic-metadata">

**Author:** [@Gromit27](https://discuss.elastic.co/u/Gromit27)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 5:53pm UTC](https://discuss.elastic.co/t/toggling-rules-on-or-off/350435 "2024-01-12T17:53:52Z")

</div>

Is there any way of knowing if a rule is toggled on or off, can I see that in an index or something? I would like to create a rule that is triggered when a rule is toggeld from status on to status off. BR

---

## [Group results in visualization](https://discuss.elastic.co/t/group-results-in-visualization/350735)

<div class="topic-metadata">

**Author:** [@KaBergmanis](https://discuss.elastic.co/u/KaBergmanis)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 5:31pm UTC](https://discuss.elastic.co/t/group-results-in-visualization/350735 "2024-01-12T17:31:05Z")

</div>

Hello! I've set up search that pulls out OS versions from VPN data feed. All working as expected. Then I created pie chart showing count of OS versions, again, so far so good, please see attached. Issue: There are mul…

---

## [Need Help Monitoring Windows Logs with ELK Stack](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130)

<div class="topic-metadata">

**Author:** [@qu\_c\_th\_nguy\_n](https://discuss.elastic.co/u/qu_c_th_nguy_n)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:59pm UTC](https://discuss.elastic.co/t/need-help-monitoring-windows-logs-with-elk-stack/350130 "2024-01-12T16:59:40Z")

</div>

Hey everyone, I'm a newbie trying to figure out how to monitor Windows log events using ELK Stack and Winlogbeat. I've got them installed, but now I'm a bit lost on what to do with all the info. Any advice, tutorials, …

---

## [Sum average](https://discuss.elastic.co/t/sum-average/350945)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:51pm UTC](https://discuss.elastic.co/t/sum-average/350945 "2024-01-12T16:51:24Z")

</div>

could you help me create a dashboard and a canvas, which first adds up to a group and then makes an average, dividing

---

## [Mapping conflict](https://discuss.elastic.co/t/mapping-conflict/350919)

<div class="topic-metadata">

**Author:** [@mb19](https://discuss.elastic.co/u/mb19)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 2:30pm UTC](https://discuss.elastic.co/t/mapping-conflict/350919 "2024-01-12T14:30:14Z")

</div>

Hello everyone, I am new to using the Elasticsearch and Kiabana stack, I do not currently have Logstash installed and would prefer not to install it. I recently had this error: I don't know how to fix it, I think I…

---

## [Analysis is not available for this field](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:25pm UTC](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965 "2024-01-12T14:25:19Z")

</div>

Kibana for some fields that used to work now returns me a Analysis is not available for this field. message and they do not show up in Discover tables etc. It is also impossible to search using these fields such as field…

---

## [Watcher to index all data from /cat/indices/\*,-.\* each indexname should be inserted as one doc](https://discuss.elastic.co/t/watcher-to-index-all-data-from-cat-indices-each-indexname-should-be-inserted-as-one-doc/350672)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 9:38am UTC](https://discuss.elastic.co/t/watcher-to-index-all-data-from-cat-indices-each-indexname-should-be-inserted-as-one-doc/350672 "2024-01-12T09:38:38Z")

</div>

Hi team, Can you please help me on below requirement: Get index name and size (in bytes) from GET /cat/indices/,-. Insert this data into new index IDs should be elastic generated. Add timestamp field in every doc Pro…

---

## [Visualization (pie) of index with all fields included](https://discuss.elastic.co/t/visualization-pie-of-index-with-all-fields-included/350845)

<div class="topic-metadata">

**Author:** [@Anomalous\_User](https://discuss.elastic.co/u/Anomalous_User)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 9:14am UTC](https://discuss.elastic.co/t/visualization-pie-of-index-with-all-fields-included/350845 "2024-01-12T09:14:07Z")

</div>

Hi, I'm using 7.17 (we're upgrading soon). At the moment I have lens/graph/visualize library all open searching for a way to include all fields (many) from an index and display them in a pie chart. I can see how to do th…

---

## [Collect values from elasticsearch/kibana](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886)

<div class="topic-metadata">

**Author:** [@cyberphantom](https://discuss.elastic.co/u/cyberphantom)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:54pm UTC](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886 "2024-01-11T20:54:08Z")

</div>

Hello! I'm trying to retrieve specific values from my Elasticsearch/Kibana graphs to manipulate them in another environment. Initially, I thought I could achieve this using the Elasticsearch API, but being relatively ne…

---

## [TLS/SSL Certification](https://discuss.elastic.co/t/tls-ssl-certification/350859)

<div class="topic-metadata">

**Author:** [@jhanani](https://discuss.elastic.co/u/jhanani)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:58pm UTC](https://discuss.elastic.co/t/tls-ssl-certification/350859 "2024-01-11T12:58:00Z")

</div>

I am running Elasticsearch and Kibana 8.11.3 version on ubuntu VM using docker. If I try to connect the Elasticsearch with PowerBI through API key. It is showing the below error. Error Message: -"The underlying connect…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350771)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 11:50am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350771 "2024-01-11T11:50:39Z")

</div>

I am trying to set up an ELK stack with communication between Kibana and Elasticsearch. I am new to ELK and I am having trouble. I will present my configurations and the results that I am getting. To start, I downloaded…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=73)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=75)
