# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=79

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 80

---

## [How to combine 2 indexes in 1 graph](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335)

<div class="topic-metadata">

**Author:** [@remco\_zwaan](https://discuss.elastic.co/u/remco_zwaan)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 10:22am UTC](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335 "2023-12-14T10:22:55Z")

</div>

0 We have 2 indexes called lodging\_index and price\_index. The relation is lodgings has many prices. In the price\_index there is a field called lodging\_id. We use this indexes in our api for frontend purpose. First call …

---

## [Error connecting to package registry](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299)

<div class="topic-metadata">

**Author:** [@A\_Niu](https://discuss.elastic.co/u/A_Niu)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 1:17am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299 "2023-12-14T01:17:04Z")

</div>

My Kibana is running behind corporate proxy, with curl, epr.elastic.co is reachable, but with Kibana service, I got below error, and added signer certificates into /etc/default/kibana NODE\_EXTRA\_CA\_CERTS="/etc/kibana/ce…

---

## [Kibana - Unable to sync case with alert](https://discuss.elastic.co/t/kibana-unable-to-sync-case-with-alert/349219)

<div class="topic-metadata">

**Author:** [@BigM1](https://discuss.elastic.co/u/BigM1)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 5:41pm UTC](https://discuss.elastic.co/t/kibana-unable-to-sync-case-with-alert/349219 "2023-12-13T17:41:28Z")

</div>

Hello, in Kibana, using the SIEM security alert. When i try to create a case and choses option to sync case with alert it throws error below: "Detected an unhandled Promise rejection. Message: illegal\_argument\_exc…

---

## [Undefined reading 'searchSourceJSON' Postfix dashboard](https://discuss.elastic.co/t/undefined-reading-searchsourcejson-postfix-dashboard/348952)

<div class="topic-metadata">

**Author:** [@skmessage](https://discuss.elastic.co/u/skmessage)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 4:05pm UTC](https://discuss.elastic.co/t/undefined-reading-searchsourcejson-postfix-dashboard/348952 "2023-12-13T16:05:36Z")

</div>

Greetings! I am trying to port the elastic-kibana-postfix .json files to .ndjson files to visualize a dashboard for Postfix for Elasticsearch 8.10.2. The PR and issue discussion are available at the following links: …

---

## [Kibana drilldown on lens metrics doesn't work](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 3:10pm UTC](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698 "2023-12-13T15:10:52Z")

</div>

I am trying to add a dashboard drill for a lens metrics. It let's me add the dashboard link but the visualization is not clickable. I am using Kibana 8.10 version. Could someone tell me if I am missing some setting or th…

---

## [Displaying Clusters of Last Hits on Kibana Maps](https://discuss.elastic.co/t/displaying-clusters-of-last-hits-on-kibana-maps/349232)

<div class="topic-metadata">

**Author:** [@yuval3210](https://discuss.elastic.co/u/yuval3210)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 2:03pm UTC](https://discuss.elastic.co/t/displaying-clusters-of-last-hits-on-kibana-maps/349232 "2023-12-13T14:03:16Z")

</div>

TL;DR: Is there a way to configure Kibana maps to display clusters based only on the last hits for each entity, rather than aggregating all hits over the selected timeframe? Hello Elastic Community :slight\_smile: I'm …

---

## [KIbana having (filtering groups)](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142)

<div class="topic-metadata">

**Author:** [@chenchen40](https://discuss.elastic.co/u/chenchen40)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142 "2023-12-13T13:25:44Z")

</div>

Hi guys, using 8.6, i can't find option to filter out groups with values i don't want to show. What do i miss?

---

## [Fielddata is disabled on \[host.name\] in \[metricbeat-8.10.3\]](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [December 12, 2023, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261 "2023-12-12T21:03:10Z")

</div>

Hello good morning! I am ingesting data from metricbeat to elasticsearch and loading the dashboards of version metricbeat 8.10.3 with the command "./metricbeat setup --dashboard" but when viewing the dashboards it shows…

---

## [Subqueries in Kibana Discover screen](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 6:24pm UTC](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931 "2023-12-12T18:24:27Z")

</div>

I need to query data based on some other record timestamp, I have a log with requests and responses from a service, but i don't really have a way to know which response is for which request besides the endpoint and the t…

---

## [Create visualization for sum of system.cpu.cores per host](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595)

<div class="topic-metadata">

**Author:** [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595 "2023-12-12T17:23:46Z")

</div>

I'm trying to create a visualization for the total cores for each host and then sum them all up to get a count for each of our clusters. Is it possible?

---

## [Is Vega performance good on large dataset?](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 2:15pm UTC](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713 "2023-12-12T14:15:37Z")

</div>

I am working on a large timeseries dataset, around 120000 document approx. I want to know how the performance is of Vega on such large database. Does it take a lot of time to load to show charts and graphs. Or it works a…

---

## [Save index-template in helm chart](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038)

<div class="topic-metadata">

**Author:** [@nkarthik](https://discuss.elastic.co/u/nkarthik)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 1:02pm UTC](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038 "2023-12-12T13:02:05Z")

</div>

Hi, I am using the 7.17 elastic stack. I know that we can create the index template in the kibana UI. But is there a way to create index-template as a YAML of any Kubernetes resource, so that every time kibana gets deplo…

---

## [Field not found message](https://discuss.elastic.co/t/field-not-found-message/349040)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:17am UTC](https://discuss.elastic.co/t/field-not-found-message/349040 "2023-12-12T11:17:36Z")

</div>

Hi all, I received an error message for a metric, saying the field wasn't found. The field not being found is fine since it does not apply to all my users, but is there a way to remove the error message. Instead having …

---

## [Elastic Map Service : Unable to find EMS tile configuration for id:road\_map : Kibana 7.17.0](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 9:59am UTC](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122 "2023-12-12T09:59:05Z")

</div>

We have done on premise Kibana deployment at client location on Windows Server VM. VM does not have public internet access. We are getting below error while loading map. Unable to load layer Unable to find EMS tile con…

---

## [Allow multi-line breaking using \\n in Discover Datatable](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975)

<div class="topic-metadata">

**Author:** [@Saar\_Tamir](https://discuss.elastic.co/u/Saar_Tamir)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975 "2023-12-12T08:29:34Z")

</div>

Hello, I'm sending strings with \\n so I can see logs in multi-line formatting, but all I see is the literal '\\n'. For example: I found this previous issue and PR: and I see that it added on 8.4.0 but only for Lens…

---

## [Kibana visualization bar chart not as expected](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:05am UTC](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099 "2023-12-12T04:05:31Z")

</div>

Hi, I'm new to Kibana / Elastic service and trying to create a bar chart. I have 2 fields that store the number of storage capacity. What I'm trying to achieve here is that I wanted to display the bar separately. But s…

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/349026)

<div class="topic-metadata">

**Author:** [@AbcDE](https://discuss.elastic.co/u/AbcDE)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 3:55pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/349026 "2023-12-11T15:55:50Z")

</div>

Hi I'm a new user of Kibana&Ubuntu(and forum) and i'm trying to start Kibana service for view the log of Suricata with a graphical interface, so please if you give me help be clear and precise Thanks. ok so i'm on Ubun…

---

## [Kibana Log In Error](https://discuss.elastic.co/t/kibana-log-in-error/348861)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 5:31am UTC](https://discuss.elastic.co/t/kibana-log-in-error/348861 "2023-12-11T05:31:12Z")

</div>

Hi Team, When my mount point in Elasticsearch server reaches between 85-90 percent , we are not able to login the Kibana UI as per screenshot. While checking log in Kibana show disk usage issue and after adding space a…

---

## [ILM policy implement for different enviornment](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 4:25pm UTC](https://discuss.elastic.co/t/ilm-policy-implement-for-different-enviornment/347281 "2023-12-09T16:25:35Z")

</div>

Hello All, I want to know better way to implement lifecycle policy for diff env like(DEV,QA,PROD). I have around 60 indices and lifecycle policy for different env would be different. ex: DEV-90 days, PROD -30 days and…

---

## [Can't find "enableEsql" option on advanced settings](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cant-find-enableesql-option-on-advanced-settings/348933 "2023-12-09T15:50:19Z")

</div>

Hello there guys, I have kibana 8.11.1 running, went to stack management and to advanced settings, I search for discover: or esql and the only option showing up is discover:enableSql, the option discover:enableESQL is n…

---

## [How to enable CORS in Kibana server](https://discuss.elastic.co/t/how-to-enable-cors-in-kibana-server/348703)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 4\
**Last updated:** [December 9, 2023, 3:49pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-in-kibana-server/348703 "2023-12-09T15:49:18Z")

</div>

Hi, I am using Kibana dashboards as iframes under a web application. The problem is that the Kibana server is authenticated by SSO and there is no guarantee that the user's browser session is having a valid active sessi…

---

## [The following is the code for creating a user dictionary Kibana plugin. However, when executed, it cannot reference the module named 'files:Filesetup', resulting in an error with 'undefined'. Is there anything I might be missing in my plugin development?](https://discuss.elastic.co/t/the-following-is-the-code-for-creating-a-user-dictionary-kibana-plugin-however-when-executed-it-cannot-reference-the-module-named-files-filesetup-resulting-in-an-error-with-undefined-is-there-anything-i-might-be-missing-in-my-plugin-development/348845)

<div class="topic-metadata">

**Author:** [@choije](https://discuss.elastic.co/u/choije)\
**Replies:** 1\
**Last updated:** [December 9, 2023, 2:23am UTC](https://discuss.elastic.co/t/the-following-is-the-code-for-creating-a-user-dictionary-kibana-plugin-however-when-executed-it-cannot-reference-the-module-named-files-filesetup-resulting-in-an-error-with-undefined-is-there-anything-i-might-be-missing-in-my-plugin-development/348845 "2023-12-09T02:23:45Z")

</div>

The following is the code for creating a user dictionary Kibana plugin. However, when executed, it cannot reference the module named 'files:Filesetup', resulting in an error with 'undefined'. Is there anything I might be…

---

## [How to show one entry per day](https://discuss.elastic.co/t/how-to-show-one-entry-per-day/348913)

<div class="topic-metadata">

**Author:** [@soad20000](https://discuss.elastic.co/u/soad20000)\
**Replies:** 10\
**Last updated:** [December 8, 2023, 9:06pm UTC](https://discuss.elastic.co/t/how-to-show-one-entry-per-day/348913 "2023-12-08T21:06:14Z")

</div>

Hello, I am on Elastic V8.10.4 and I have a dashboard for NTP that looks like this: I want it to show only one entry per day, instead of multiple per day like it currently does. How can I accomplish this?

---

## [Subtracting one value out of another and showing the percentage difference](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 9\
**Last updated:** [December 8, 2023, 7:18pm UTC](https://discuss.elastic.co/t/subtracting-one-value-out-of-another-and-showing-the-percentage-difference/348926 "2023-12-08T19:18:22Z")

</div>

I am trying to get a pie dashboard of successful vs abendent processes out of my logs. My issue is that there is no way to filter the abendent processes. So what I can do is filter based on the values that are successf…

---

## [Kibana Pie Chart custom colors still not assignable](https://discuss.elastic.co/t/kibana-pie-chart-custom-colors-still-not-assignable/348577)

<div class="topic-metadata">

**Author:** [@dc\_3](https://discuss.elastic.co/u/dc_3)\
**Replies:** 10\
**Last updated:** [December 8, 2023, 8:15am UTC](https://discuss.elastic.co/t/kibana-pie-chart-custom-colors-still-not-assignable/348577 "2023-12-08T08:15:18Z")

</div>

Hello, I've researched and checked the forums here for this answer, but unfortunately the suggestions on how to assign custom colors in a pie chart seem unavailable to me. Can you help? Currently, I've only got a choic…

---

## [After enabling - xpack.security.enabled=true, in kibana logs is not updating](https://discuss.elastic.co/t/after-enabling-xpack-security-enabled-true-in-kibana-logs-is-not-updating/348855)

<div class="topic-metadata">

**Author:** [@venkatesh121](https://discuss.elastic.co/u/venkatesh121)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 5:29am UTC](https://discuss.elastic.co/t/after-enabling-xpack-security-enabled-true-in-kibana-logs-is-not-updating/348855 "2023-12-08T05:29:46Z")

</div>

After enabling - xpack.security.enabled=true, in kibana logs is not updating but if i changed - xpack.security.enabled=true to false its updating note: already added passwords in docker-copose.yml file ./elasticsearch-…

---

## [Create a metric out of the last values from multiple log files](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748)

<div class="topic-metadata">

**Author:** [@Jospaul](https://discuss.elastic.co/u/Jospaul)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 3:58pm UTC](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748 "2023-12-07T15:58:47Z")

</div>

I need to find the current active threads in a system. The log files spit this information per log file, but as I am running multiple of them in parallel. There are multiple log files created each showing the active thre…

---

## [Links Panel Font SIze](https://discuss.elastic.co/t/links-panel-font-size/348811)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 1:23pm UTC](https://discuss.elastic.co/t/links-panel-font-size/348811 "2023-12-07T13:23:28Z")

</div>

Hello, I love the new Links Panel, but the default font size is way too big imho. In the previous years we always made menus with the Markdown panel, which allows to resize the font size. Please please add this funct…

---

## [Hide all panels, using control or filter](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:03pm UTC](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804 "2023-12-07T12:03:15Z")

</div>

Hello Team, Please help to tell how to hide all panels, of a dashboard using controls or filter

---

## [Not able to get file logs from otel collector to elasticsearch using APM server](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 5\
**Last updated:** [December 7, 2023, 11:56am UTC](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214 "2023-12-07T11:56:08Z")

</div>

extensions: health\_check: pprof: endpoint: 0.0.0.0:1777 zpages: endpoint: 0.0.0.0:55679 receivers: filelog: include: \[/path/to log/.log\] operators: - type: regex\_parser regex: '^(?P\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=78)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=80)
