# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=85

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 86

---

## [How can I filter certain information from the logs?](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 7\
**Last updated:** [November 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293 "2023-11-08T07:41:48Z")

</div>

We work with ELK Stack and I have the task of creating meaningful visualizations from the log entries. I have logs in the following format: { "@timestamp": \[ "2023-08-08T00:00:11.2123" \], "xxxxx": \[ "yyyyy…

---

## [VegaLite Code Error: Cannot convert undefined or null to object](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656)

<div class="topic-metadata">

**Author:** [@rahuja23](https://discuss.elastic.co/u/rahuja23)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:02pm UTC](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656 "2023-11-07T21:02:35Z")

</div>

System Specifications: Kibana Version: 8.8.2 Elastic Search Version: 8.8.2 Environment: local (Mac OS arm64) I am new to vega. I am trying to create a Gantt chart visualisation using vega code but for some reason the…

---

## [How I can obtain an average from a normalization formula](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644)

<div class="topic-metadata">

**Author:** [@Silvy20](https://discuss.elastic.co/u/Silvy20)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644 "2023-11-07T14:15:04Z")

</div>

Hello, I've created a data histogram chart based in a formula where I'm expecting to analyze the amount of requests per device. However. I'd like to plot in the same chart a static line with the average around that day. …

---

## [Kibana custom labels missing from CSV export](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 12:00pm UTC](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616 "2023-11-07T12:00:52Z")

</div>

Hi. I have a Kibana report that utilises Custom Labels, but these labels do not get exported when using the Share option to CSV. Is it possible to export my report to CSV and retain the custom labels that I have set? Th…

---

## [Getting 401 first time and able to login in same session in second attempt](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 11:42am UTC](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524 "2023-11-07T11:42:53Z")

</div>

I am implementing SSO with elastic/Kibana. and using Wso2 credential to login. When i login first time, i see 401, below is the curl i can copy from browser. curl 'http://server1.local:5601/api/security/oidc/callback?c…

---

## [Kibana Timeseries or Area chart to split chart on two fileds value](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 3:43am UTC](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497 "2023-11-07T03:43:07Z")

</div>

Hello All, I have a requirement for below data and not sure which visual could achieve the requirement properly.Ideal requirement is of Timeseries using TSVB or someother visual also fine.Plz let know if this is possibl…

---

## [Kibana not working properly](https://discuss.elastic.co/t/kibana-not-working-properly/346028)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 7\
**Last updated:** [November 6, 2023, 9:56am UTC](https://discuss.elastic.co/t/kibana-not-working-properly/346028 "2023-11-06T09:56:03Z")

</div>

Hello, I'm running a dockerized elastic cluster composed of 3 master and 3 data nodes on AWS instances, using rsyslog and logstash, i collect and store syslog events on elasticsearch index. till now everything was good…

---

## [How to list top 5 IPs with their total usage in Mega Byte](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 5:54am UTC](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490 "2023-11-06T05:54:32Z")

</div>

Hi Users, I have setup fortigate firewall with logstash, Elasticsearch and Kibana. It woks fine. In kibana, Dashboard, How to list top 5 IPs with their total usage in Mega Byte. How can I achieve it? Hope to hear from…

---

## [Kibana-to-elastic: reason: unable to verify the first certificate](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480)

<div class="topic-metadata">

**Author:** [@agvsap1](https://discuss.elastic.co/u/agvsap1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 12:27am UTC](https://discuss.elastic.co/t/kibana-to-elastic-reason-unable-to-verify-the-first-certificate/346480 "2023-11-06T00:27:41Z")

</div>

Hi I have installed elasticsearch:8.5.1 and kibana:8.5.1 in gk1 with kubernetes 1.26. The kibana console when try to access elastic reports this error: We can’t establish a connection to Enterprise Search a…

---

## [Edit static lookup with API](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 10:24am UTC](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111 "2023-11-05T10:24:11Z")

</div>

I have the following problem. I have an X field in every document, but not in every document I have a Y field. I would like the information from field Y to appear in place of field X. Specifically, it is about the occurr…

---

## [Kibana Plugin](https://discuss.elastic.co/t/kibana-plugin/346245)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 1\
**Last updated:** [November 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-plugin/346245 "2023-11-04T12:49:09Z")

</div>

Hi! I wanted to create a custom plugin to add on to kibana. since i had Elasticsearch and kibana already set up and running, i started my plugin development in the 'plugin' of kibana. (system - win11) when i start kib…

---

## [Show only time with out date](https://discuss.elastic.co/t/show-only-time-with-out-date/345059)

<div class="topic-metadata">

**Author:** [@naveed786.shaik](https://discuss.elastic.co/u/naveed786.shaik)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 11:10pm UTC](https://discuss.elastic.co/t/show-only-time-with-out-date/345059 "2023-11-03T23:10:49Z")

</div>

Hi All, Need a help with Kibana dashboard , I could see the customization for date and time, in version 8.6.0 of the dashboard. I am trying to get indexed data with only time where need to exclude date. Please suggest …

---

## [API Key for Kibana Reporting](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 2:27pm UTC](https://discuss.elastic.co/t/api-key-for-kibana-reporting/345662 "2023-11-03T14:27:54Z")

</div>

I need to generate an API key which will allow a user to generate a report in Kibana and then download it, once it's generated. What permissions do I need to set? I haven't been able to determine this from the docs. Thx…

---

## [How do we customize the login page in latest version 8.10.2](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-we-customize-the-login-page-in-latest-version-8-10-2/346359 "2023-11-03T12:57:08Z")

</div>

Hi Team, How do we customize the login page in latest version of ELK 8.10.2 Observed that when compared to previous versions (8.5.2) here we find many changes in folder structure also. Requesting team to provide solut…

---

## [Visualize logs from two Suricata filebeat modules in one dashboard](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306)

<div class="topic-metadata">

**Author:** [@edpuig97](https://discuss.elastic.co/u/edpuig97)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:35pm UTC](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306 "2023-11-03T12:35:21Z")

</div>

Hi, I'm using Filebeat's suricata module from two suricata hosts, when I setup those, only the last of them is showed in the Kibana dashboards. Is any way to show both of them? Thanks in advance.

---

## [How to search these kind of texts without Synonyms](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362 "2023-11-03T11:55:42Z")

</div>

Hi, When I search with this query, { "match":{ "company":{ "query":"walmart" } } …

---

## [Take snapshot of only the global state and feature state in elasticsearch](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352)

<div class="topic-metadata">

**Author:** [@nishant27](https://discuss.elastic.co/u/nishant27)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 10:45am UTC](https://discuss.elastic.co/t/take-snapshot-of-only-the-global-state-and-feature-state-in-elasticsearch/346352 "2023-11-03T10:45:46Z")

</div>

I have created a policy in elasticsearch kibana for taking backup of only the "global state" and "feature state" of the cluster. But when i run the policy, it fails with "index\_not\_found\_exception". Is there any way to…

---

## [Creating a Tag Cloud](https://discuss.elastic.co/t/creating-a-tag-cloud/346289)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 8:55pm UTC](https://discuss.elastic.co/t/creating-a-tag-cloud/346289 "2023-11-02T20:55:35Z")

</div>

Hello all, I have a field that displays feedback. I was hoping to create a tag cloud of the most popular words from the feedback, to get a feel of what customers are saying. Does anyone know how I could do this?

---

## [Data view in Kibana with the latest timestamp version of a datastream](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 11\
**Last updated:** [November 2, 2023, 1:34pm UTC](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177 "2023-11-02T13:34:41Z")

</div>

Hello, I have a datastream that it is often being updated, for some graphs I use the full data stream for visualizations, for example, doing histograms with the @timestamp field. But for other cases I would like to do g…

---

## [Not able show field in table visualization](https://discuss.elastic.co/t/not-able-show-field-in-table-visualization/346288)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 12:24pm UTC](https://discuss.elastic.co/t/not-able-show-field-in-table-visualization/346288 "2023-11-02T12:24:01Z")

</div>

I have created a dashboard for endpoints which show how many parameters in particular endpoints. I have made two indexes and I have created a data view using that two index according to camma separated index-pattern. the…

---

## [Kibana lens based Area chart and Normal Area chart (Aggregation based) dosent follow opacity color correctly?](https://discuss.elastic.co/t/kibana-lens-based-area-chart-and-normal-area-chart-aggregation-based-dosent-follow-opacity-color-correctly/346276)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 10:30am UTC](https://discuss.elastic.co/t/kibana-lens-based-area-chart-and-normal-area-chart-aggregation-based-dosent-follow-opacity-color-correctly/346276 "2023-11-02T10:30:24Z")

</div>

Hello All, I tried making area chart using Lens based AREA CHART and also along with Normal Area chart. The reason to choose NORMAL Area chart over lens based is because I want to below which I am unable to do in lens…

---

## [Kibana Default Index pattern is changing automatically after being set for Multiple times](https://discuss.elastic.co/t/kibana-default-index-pattern-is-changing-automatically-after-being-set-for-multiple-times/346274)

<div class="topic-metadata">

**Author:** [@Vijay\_Varma](https://discuss.elastic.co/u/Vijay_Varma)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 9:46am UTC](https://discuss.elastic.co/t/kibana-default-index-pattern-is-changing-automatically-after-being-set-for-multiple-times/346274 "2023-11-02T09:46:20Z")

</div>

Initially observed there Duplicate index patterns are present in Kibana and it is due to the import of objects which are using different IDs for same Index pattern name. So we changed the Index pattern ID to an unique ID…

---

## [CSV Export from a lens - No date is shown in the CSV document](https://discuss.elastic.co/t/csv-export-from-a-lens-no-date-is-shown-in-the-csv-document/346192)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [November 2, 2023, 9:36am UTC](https://discuss.elastic.co/t/csv-export-from-a-lens-no-date-is-shown-in-the-csv-document/346192 "2023-11-02T09:36:39Z")

</div>

Hi! I have some problem with the CSV export from a lends trend. If i choose the Minimum Interval under 1 hour, in my export is only shown the time and not the Date + time. If the Minimun Intervall is above one ho…

---

## [Kibana 8.8.2 is not able to connect to elastic](https://discuss.elastic.co/t/kibana-8-8-2-is-not-able-to-connect-to-elastic/346257)

<div class="topic-metadata">

**Author:** [@juhigupta](https://discuss.elastic.co/u/juhigupta)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:17am UTC](https://discuss.elastic.co/t/kibana-8-8-2-is-not-able-to-connect-to-elastic/346257 "2023-11-02T03:17:44Z")

</div>

I m trying to move from 7.17.9 to kibana 8.8.2 but kibana is rejecting to connect with elastic with cert not configured error. Those certificates are working in 7.17.9 but kibana 8.8.2 doesn't recognise. Any suggestions…

---

## [Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/346233)

<div class="topic-metadata">

**Author:** [@juhigupta](https://discuss.elastic.co/u/juhigupta)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 6:08pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/346233 "2023-11-01T18:08:33Z")

</div>

When I upgrade to 8.8.2 from 7.17.9. I get below error in kibana. Same certificates are working for 7.17.9 in kibana , but same are failing for 8.8.2, Any suggestion please. Below is the error Unable to retrieve versi…

---

## [Kibana - Visualization aggregation not working on large values of a field](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213)

<div class="topic-metadata">

**Author:** [@sunildate](https://discuss.elastic.co/u/sunildate)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 3:47pm UTC](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213 "2023-11-01T15:47:42Z")

</div>

I have aggregated field values with characters length 850. In Visualization after applying aggregation on term not returning field value. I have also updated ignore\_above to 1024. Can you please help me.

---

## [Is it possible to create a aggregated runtime field and compare them?](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205)

<div class="topic-metadata">

**Author:** [@turbo23](https://discuss.elastic.co/u/turbo23)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205 "2023-11-01T14:24:21Z")

</div>

Hello, I want to create a dashboard that shows OK if my data\_stream distinct counted hostnames equals to my distinct counted hostnames in the cmdb index or shows NOK if it no longer equals both values. My idea: Compare…

---

## [Kibana search fails to find string](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163)

<div class="topic-metadata">

**Author:** [@ChazJaz](https://discuss.elastic.co/u/ChazJaz)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163 "2023-11-01T14:02:51Z")

</div>

When I try a simple KQL search for the character pattern: message: "}\]}}}" it finds no results even though I can see that string pattern in some entries of an unfiltered query of my data stream. According to the KQL do…

---

## [Use time filter on auto-interval date histogram](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:49am UTC](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964 "2023-11-01T08:49:14Z")

</div>

Hello, I'm using version 8.6.0 of elastic cloud. I'm trying to develop a chart similar to the TSVB time series, but the way my data is loaded I need to do it in Vega. I'm using auto-interval date histogram to separate …

---

## [How can I format a column in Lens so it can operate as a sum of time?](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:41am UTC](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151 "2023-11-01T08:41:58Z")

</div>

Basically, I have a column in my index that returns the total of time a device is down like this: But as I go further in time range it turns into something like this: I need to format this into the right amount of …

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=84)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=86)
