# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=8

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 9

---

## [I need to monitor bigfix relay and display as a block green if running and red is stopped or not running](https://discuss.elastic.co/t/i-need-to-monitor-bigfix-relay-and-display-as-a-block-green-if-running-and-red-is-stopped-or-not-running/382706)

<div class="topic-metadata">

**Author:** [@Prashant\_Kadam](https://discuss.elastic.co/u/Prashant_Kadam)\
**Replies:** 1\
**Last updated:** [October 15, 2025, 6:02am UTC](https://discuss.elastic.co/t/i-need-to-monitor-bigfix-relay-and-display-as-a-block-green-if-running-and-red-is-stopped-or-not-running/382706 "2025-10-15T06:02:44Z")

</div>

I need to monitor bigfix relay and display as a block green if running and red is stopped or not running

---

## [Azure - Entra ID - SIgnin Logs Stopped](https://discuss.elastic.co/t/azure-entra-id-signin-logs-stopped/382718)

<div class="topic-metadata">

**Author:** [@yachee](https://discuss.elastic.co/u/yachee)\
**Replies:** 0\
**Last updated:** [October 14, 2025, 6:41pm UTC](https://discuss.elastic.co/t/azure-entra-id-signin-logs-stopped/382718 "2025-10-14T18:41:03Z")

</div>

Hi, Our sign-in logs from Azure suddenly stopped 3 months ago. We did it twice by deleting and resetting the integration, but it could bring it back for 2 days, then it would stop again. We are still receiving the audit…

---

## [Unable to view any data in Kibana maps](https://discuss.elastic.co/t/unable-to-view-any-data-in-kibana-maps/382642)

<div class="topic-metadata">

**Author:** [@ramenon](https://discuss.elastic.co/u/ramenon)\
**Replies:** 2\
**Last updated:** [October 14, 2025, 8:05am UTC](https://discuss.elastic.co/t/unable-to-view-any-data-in-kibana-maps/382642 "2025-10-14T08:05:14Z")

</div>

Hello , I am unable to view any datapoints in Kibana maps from my index : - I see from the mappings that it is marked as Geopoint "clientgeoip": { "properties": { "geo": { "prope…

---

## [MISP → Filebeat → Elasticsearch (9210) : Data not visible in Kibana](https://discuss.elastic.co/t/misp-filebeat-elasticsearch-9210-data-not-visible-in-kibana/382646)

<div class="topic-metadata">

**Author:** [@omar\_embarak](https://discuss.elastic.co/u/omar_embarak)\
**Replies:** 0\
**Last updated:** [October 13, 2025, 4:27pm UTC](https://discuss.elastic.co/t/misp-filebeat-elasticsearch-9210-data-not-visible-in-kibana/382646 "2025-10-13T16:27:54Z")

</div>

Hi everyone, I'm currently integrating MISP with the Elastic Stack (ELK 8.17.3) and need some help figuring out why data isn't showing up in Kibana. Setup overview: MISP server running Filebeat. Filebeat sends data d…

---

## [API \[GET /api/streams/\_status\] is unauthorized for user](https://discuss.elastic.co/t/api-get-api-streams-status-is-unauthorized-for-user/382578)

<div class="topic-metadata">

**Author:** [@fuphil](https://discuss.elastic.co/u/fuphil)\
**Replies:** 0\
**Last updated:** [October 10, 2025, 8:26am UTC](https://discuss.elastic.co/t/api-get-api-streams-status-is-unauthorized-for-user/382578 "2025-10-10T08:26:37Z")

</div>

Hey, after the upgrade from 8.15.5 to 8.18.6 I found lots of the following errors in the Kibana logs. During investigation I found out, that this is related to the user permissions. It always occurs if a user opens a …

---

## [Kibana audit log](https://discuss.elastic.co/t/kibana-audit-log/382542)

<div class="topic-metadata">

**Author:** [@vijay117](https://discuss.elastic.co/u/vijay117)\
**Replies:** 0\
**Last updated:** [October 9, 2025, 10:06am UTC](https://discuss.elastic.co/t/kibana-audit-log/382542 "2025-10-09T10:06:15Z")

</div>

how to store user email id in user meta data, which will go into kibana audit log? I want to see the user email in kibana audit log. just mapping this elasticsearch.yml is sufficent ? xpack.security.authc.realms.nativ…

---

## [Data Retention for a Data Stream showing 'Disabled' - Why?](https://discuss.elastic.co/t/data-retention-for-a-data-stream-showing-disabled-why/382520)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [October 9, 2025, 4:46am UTC](https://discuss.elastic.co/t/data-retention-for-a-data-stream-showing-disabled-why/382520 "2025-10-09T04:46:48Z")

</div>

Hi there, I was wonderig that the manual says this: A value in the data retention column indicates that the data stream is managed by a data stream lifecycle policy. This value is the time period for which your data i…

---

## [Kibana Install](https://discuss.elastic.co/t/kibana-install/382231)

<div class="topic-metadata">

**Author:** [@Edward\_Weller](https://discuss.elastic.co/u/Edward_Weller)\
**Replies:** 3\
**Last updated:** [October 7, 2025, 9:50pm UTC](https://discuss.elastic.co/t/kibana-install/382231 "2025-10-07T21:50:29Z")

</div>

I have been trying to upgrade our local service to 8.19.4 so that I may update to 9.0. I have not had an issue with elasticsearch, but kibana is giving me an issue. I have tried multiple downloads, and multiple install…

---

## [Kibana missing credentials ver 9.0.3](https://discuss.elastic.co/t/kibana-missing-credentials-ver-9-0-3/382032)

<div class="topic-metadata">

**Author:** [@Karol\_Niema](https://discuss.elastic.co/u/Karol_Niema)\
**Replies:** 4\
**Last updated:** [October 7, 2025, 2:46pm UTC](https://discuss.elastic.co/t/kibana-missing-credentials-ver-9-0-3/382032 "2025-10-07T14:46:34Z")

</div>

Hello, I receive errors in kibana logs {"@timestamp":"2025-09-17T17:57:36.157Z","event":{"provider":"alerting","action":"execute","kind":"alert","category":\\\["monitoring"\\\],"start":"2025-09-17T17:57:36.121Z","outcome":…

---

## [Why does this simple search in Kibana work?](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 3\
**Last updated:** [October 7, 2025, 6:56am UTC](https://discuss.elastic.co/t/why-does-this-simple-search-in-kibana-work/382435 "2025-10-07T06:56:58Z")

</div>

Hi there, I defined this simple test document: POST /logs-stefano/\_doc?pipeline=syslog\_deduplication { "@timestamp": "2025-10-06T09:00:00Z", "host": "SERVER-A", "message": "date=2025-05-02 time=10:38:00 devname=SER…

---

## [Rollover errors for .kibana-reporting datastream indexes](https://discuss.elastic.co/t/rollover-errors-for-kibana-reporting-datastream-indexes/382425)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [October 5, 2025, 7:59pm UTC](https://discuss.elastic.co/t/rollover-errors-for-kibana-reporting-datastream-indexes/382425 "2025-10-05T19:59:58Z")

</div>

8.18.3 indexes going back over a year for .kibana-reporting datastream have rollover errors: "setting \[index.lifecycle.rollover\_alias\] for index \[.reporting-2024-04-07\] is empty or not defined" { "policy": "kibana-r…

---

## [Log Anomaly Doesn't Work?](https://discuss.elastic.co/t/log-anomaly-doesnt-work/382329)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [October 4, 2025, 3:30am UTC](https://discuss.elastic.co/t/log-anomaly-doesnt-work/382329 "2025-10-04T03:30:18Z")

</div>

ES/Kibana 9.1.3 I get this error:

---

## [Heatmap visualization with ES|QL ignores/randomizes sorting on 2nd dimension](https://discuss.elastic.co/t/heatmap-visualization-with-es-ql-ignores-randomizes-sorting-on-2nd-dimension/382271)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 2\
**Last updated:** [October 3, 2025, 12:12pm UTC](https://discuss.elastic.co/t/heatmap-visualization-with-es-ql-ignores-randomizes-sorting-on-2nd-dimension/382271 "2025-10-03T12:12:20Z")

</div>

Hey, I have an ESQL query like this: FROM data | EVAL month\_of\_year = DATE\_EXTRACT("month\_of\_year", date), hour\_of\_day = DATE\_EXTRACT("HOUR\_OF\_DAY", date) | STATS AVG(value) BY month\_of\_year, hour\_of\_day | SORT h…

---

## [Dasboards and dataviews](https://discuss.elastic.co/t/dasboards-and-dataviews/382274)

<div class="topic-metadata">

**Author:** [@Buzz](https://discuss.elastic.co/u/Buzz)\
**Replies:** 2\
**Last updated:** [September 30, 2025, 1:26pm UTC](https://discuss.elastic.co/t/dasboards-and-dataviews/382274 "2025-09-30T13:26:45Z")

</div>

Hello, i have a question about dashboards delivered with Windows integration. I have created multiple new indexes and assign separate policies. example: agent-security-logs-yyyy.mm.dd - retention 365days agent-applic…

---

## [How to reference another column value in metricFont expression?](https://discuss.elastic.co/t/how-to-reference-another-column-value-in-metricfont-expression/382077)

<div class="topic-metadata">

**Author:** [@JensHaglof](https://discuss.elastic.co/u/JensHaglof)\
**Replies:** 4\
**Last updated:** [September 26, 2025, 2:14pm UTC](https://discuss.elastic.co/t/how-to-reference-another-column-value-in-metricfont-expression/382077 "2025-09-26T14:14:25Z")

</div>

Hi, I have a table that returns only one row with two columns: carrier and sum\_orders. I'm currently displaying sum\_orders in a metric element. I would like to change the font color of the number based on the value in …

---

## [What is the Setup Guides in Kibana privileges?](https://discuss.elastic.co/t/what-is-the-setup-guides-in-kibana-privileges/381948)

<div class="topic-metadata">

**Author:** [@josh\_tran](https://discuss.elastic.co/u/josh_tran)\
**Replies:** 7\
**Last updated:** [September 26, 2025, 8:54am UTC](https://discuss.elastic.co/t/what-is-the-setup-guides-in-kibana-privileges/381948 "2025-09-26T08:54:02Z")

</div>

Hi all, I am setting up the RBAC for users in my self-managed Elastic stack. I see there is an option in Kibana Privileges - Management, that is Setup Guides. I am unable to find the document explaining it. What is …

---

## [Learn Expression syntax and tiny math, where?](https://discuss.elastic.co/t/learn-expression-syntax-and-tiny-math-where/381953)

<div class="topic-metadata">

**Author:** [@JensHaglof](https://discuss.elastic.co/u/JensHaglof)\
**Replies:** 5\
**Last updated:** [September 25, 2025, 5:48pm UTC](https://discuss.elastic.co/t/learn-expression-syntax-and-tiny-math-where/381953 "2025-09-25T17:48:41Z")

</div>

Hi! Is there an online course that teaches this? I struggle to understand the syntax and how to use it to change things in the Canvas. The expression syntax, is that unique to Kibana, or is it a “real” language used ou…

---

## [Tilte Style plugin in v9.0.2](https://discuss.elastic.co/t/tilte-style-plugin-in-v9-0-2/381973)

<div class="topic-metadata">

**Author:** [@Mayuri\_Jaiswal](https://discuss.elastic.co/u/Mayuri_Jaiswal)\
**Replies:** 6\
**Last updated:** [September 25, 2025, 4:43pm UTC](https://discuss.elastic.co/t/tilte-style-plugin-in-v9-0-2/381973 "2025-09-25T16:43:00Z")

</div>

As generated plugin which is for styling title of visualisation suppose table or any other visual having title so have to customise setting like title font size,its colour its background colour alignment etc just like MS…

---

## [Adding new field to an existing index/dataview](https://discuss.elastic.co/t/adding-new-field-to-an-existing-index-dataview/382142)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [September 23, 2025, 11:37pm UTC](https://discuss.elastic.co/t/adding-new-field-to-an-existing-index-dataview/382142 "2025-09-23T23:37:29Z")

</div>

version 8.18.3 I found a field in one datastream where the name in the index template did not match the one that was used in the ingested data. I have added the ‘used’ name into the index template and rotated the data…

---

## [Importing data without a timezone is not UTC](https://discuss.elastic.co/t/importing-data-without-a-timezone-is-not-utc/382076)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 2\
**Last updated:** [September 23, 2025, 9:57am UTC](https://discuss.elastic.co/t/importing-data-without-a-timezone-is-not-utc/382076 "2025-09-23T09:57:38Z")

</div>

Hey, I am using the CSV upload to import a data file with roughly 300k entries. Import works fine, but I have some questions about time zones. I have a field looking like this 2022-11-04 00:09:09 that does not contain …

---

## [Creating an API Key for KIBANA](https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931)

<div class="topic-metadata">

**Author:** [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Replies:** 1\
**Last updated:** [September 23, 2025, 8:31am UTC](https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931 "2025-09-23T08:31:16Z")

</div>

Hello everyone, I am trying to create an API key that has permissions to query the /api/fleet/agents endpoint. It is important for me to minimize its permissions as much as possible. Which permissions do I need to pro…

---

## [Elasticsearch - Track new Geolocation an IP shows up in](https://discuss.elastic.co/t/elasticsearch-track-new-geolocation-an-ip-shows-up-in/382130)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [September 23, 2025, 6:02am UTC](https://discuss.elastic.co/t/elasticsearch-track-new-geolocation-an-ip-shows-up-in/382130 "2025-09-23T06:02:46Z")

</div>

What function in Elasticsearch / kibana can we use to track if any IP shows up in a new GEOlocation Or a new IP Address shows up that isnt already there

---

## [Unable to authenticate user \[\<unauthenticated-saml-user\>](https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124)

<div class="topic-metadata">

**Author:** [@madhavsankarg](https://discuss.elastic.co/u/madhavsankarg)\
**Replies:** 1\
**Last updated:** [September 22, 2025, 2:22pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-unauthenticated-saml-user/382124 "2025-09-22T14:22:23Z")

</div>

Hi All, I have Updated the Elasticstack from 8.14.1 to 8.18.1. Currently encountering error of SAML login. In our setup we are using SSO of Azure to login to Kibana. Error I am getting in kibana logs {"event":{"acti…

---

## [Passing Values From Links to Controls](https://discuss.elastic.co/t/passing-values-from-links-to-controls/372169)

<div class="topic-metadata">

**Author:** [@msavitski](https://discuss.elastic.co/u/msavitski)\
**Replies:** 1\
**Last updated:** [September 22, 2025, 8:06am UTC](https://discuss.elastic.co/t/passing-values-from-links-to-controls/372169 "2025-09-22T08:06:15Z")

</div>

Hi there! I have a question related to the link panel. Thanks for functionality, I have successfully integrated it into the dashboard. On the first dashboard, I have controls, and when I navigate to another dashboard, …

---

## [Kibana 8.13.4 Fails to Authenticate to Elasticsearch 8.13.4 with Service Account Token (security\_exception)](https://discuss.elastic.co/t/kibana-8-13-4-fails-to-authenticate-to-elasticsearch-8-13-4-with-service-account-token-security-exception/382086)

<div class="topic-metadata">

**Author:** [@Himanshu\_Sharma1](https://discuss.elastic.co/u/Himanshu_Sharma1)\
**Replies:** 1\
**Last updated:** [September 19, 2025, 2:55pm UTC](https://discuss.elastic.co/t/kibana-8-13-4-fails-to-authenticate-to-elasticsearch-8-13-4-with-service-account-token-security-exception/382086 "2025-09-19T14:55:45Z")

</div>

Description: I am running Elasticsearch and Kibana, both version 8.13.4, on Kubernetes. Kibana is configured to use a service account token (generated for elastic/kibana) mounted as a file and referenced in kibana.yml. …

---

## [Kibana 8.9.14 build fails](https://discuss.elastic.co/t/kibana-8-9-14-build-fails/382066)

<div class="topic-metadata">

**Author:** [@Amit\_Kaplan](https://discuss.elastic.co/u/Amit_Kaplan)\
**Replies:** 0\
**Last updated:** [September 18, 2025, 6:03pm UTC](https://discuss.elastic.co/t/kibana-8-9-14-build-fails/382066 "2025-09-18T18:03:40Z")

</div>

I’m trying to build kibana 8.9.14 using the same build instructions that I used to build 8.9.13 but it fails with an error related to moon usage It fails on “yarn kbn bootstrap --offline --allow-root” any help?

---

## [Custom plugin of title styling in v9.0.2](https://discuss.elastic.co/t/custom-plugin-of-title-styling-in-v9-0-2/381974)

<div class="topic-metadata">

**Author:** [@Mayuri\_Jaiswal](https://discuss.elastic.co/u/Mayuri_Jaiswal)\
**Replies:** 1\
**Last updated:** [September 18, 2025, 12:02am UTC](https://discuss.elastic.co/t/custom-plugin-of-title-styling-in-v9-0-2/381974 "2025-09-18T00:02:49Z")

</div>

As generated plugin which is for styling title of visualisation suppose table or any other visual having title so have to customise setting like title font size,its colour its background colour alignment etc just like MS…

---

## [Can I restrict some fleet users to a subset of agents?](https://discuss.elastic.co/t/can-i-restrict-some-fleet-users-to-a-subset-of-agents/382034)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 1\
**Last updated:** [September 17, 2025, 10:26pm UTC](https://discuss.elastic.co/t/can-i-restrict-some-fleet-users-to-a-subset-of-agents/382034 "2025-09-17T22:26:58Z")

</div>

I have been asked to allow some server admins access to fleet. I only want to allow them to break their subset of agents, not all. Is this possible? It’s a cloud hosted, latest version stack. Thanks

---

## [Dashboard variables set dynamically from a query](https://discuss.elastic.co/t/dashboard-variables-set-dynamically-from-a-query/379507)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 14\
**Last updated:** [September 17, 2025, 10:13am UTC](https://discuss.elastic.co/t/dashboard-variables-set-dynamically-from-a-query/379507 "2025-09-17T10:13:39Z")

</div>

Hi! I'm looking for a feature that I don't think is possible to do now, but I hope it will come in the future. We are using Kibana dashboards to get insights into our sales performance. I want to be able set a variable …

---

## [Blank in Kibana Tables](https://discuss.elastic.co/t/blank-in-kibana-tables/381901)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 3\
**Last updated:** [September 16, 2025, 1:08pm UTC](https://discuss.elastic.co/t/blank-in-kibana-tables/381901 "2025-09-16T13:08:18Z")

</div>

Hello, colleagues! A client has asked me to remove the hyphens (-) from the tables and leave a blank space. Does anyone know if this is feasible without affecting the fact that it is a numeric field used for averages? …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=7)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=9)
