# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=87

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 88

---

## [Show complete xml content on mousehover in Kibana 8.3.2 table view](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 10:07am UTC](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619 "2023-10-26T10:07:10Z")

</div>

Hi, I added the fields from documents in Discover and save it. After that I visualized that saved table from library into dashboard. One of the field is having xml content but in table it's not showing complete content. …

---

## [ML CPU, Memory, of Host/Processes](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 8:26am UTC](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781 "2023-10-26T08:26:00Z")

</div>

Hi All Using Machine Learning Anomaly/data frame I want to find the root cause of high CPU and memory, concerning the host and processes. Moreover, if possible error logs and any APM are running, that data too. I need…

---

## [Trying to use sum\_bucket agg to summarize the last value per server into a total](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729)

<div class="topic-metadata">

**Author:** [@mekberg](https://discuss.elastic.co/u/mekberg)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 8:06am UTC](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729 "2023-10-26T08:06:44Z")

</div>

I'm trying to create a search (ultimately a visualization) that will give me the total number of Controller nodes in a cluster. Each node reports metrics every 15 seconds, and each document will contain the value for tha…

---

## [Superuser access in each Space](https://discuss.elastic.co/t/superuser-access-in-each-space/345405)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/superuser-access-in-each-space/345405 "2023-10-25T19:19:47Z")

</div>

How do you implement superuser access to every Space for any users that need that level of access? For example, in a deployment utilizing SAML for access a user has superuser privileges in one Space to manage everything…

---

## [Discover does not show any data for indices with \_source disabled](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 11\
**Last updated:** [October 25, 2023, 5:32pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652 "2023-10-25T17:32:38Z")

</div>

Hello, I disabled the \_source field on a couple of indices yesterday and today I noticed that I can not see anything from those indices on Discover. I can filter on values and fields, but everything is empty on Kibana …

---

## [Can we remove the date column from our reports?](https://discuss.elastic.co/t/can-we-remove-the-date-column-from-our-reports/344072)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 3:03pm UTC](https://discuss.elastic.co/t/can-we-remove-the-date-column-from-our-reports/344072 "2023-10-25T15:03:23Z")

</div>

I have seen topics about removing the date (time) column from the discover tableview and I understand it is not that easy. But maybe there is an easy way to prevent this column from being included in the CSV reports ?

---

## [Add alert exclusion for "grandfather" process](https://discuss.elastic.co/t/add-alert-exclusion-for-grandfather-process/344835)

<div class="topic-metadata">

**Author:** [@stenbot1](https://discuss.elastic.co/u/stenbot1)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 1:44pm UTC](https://discuss.elastic.co/t/add-alert-exclusion-for-grandfather-process/344835 "2023-10-25T13:44:53Z")

</div>

We have an agent on our Linux servers that will spawn a shell and then that shell will spawn a process that creates an alert. This agent is trusted software on the host, and I have added it to the whitelist. The problem …

---

## [Start of Kibana fails](https://discuss.elastic.co/t/start-of-kibana-fails/345627)

<div class="topic-metadata">

**Author:** [@JohannesKjellberg](https://discuss.elastic.co/u/JohannesKjellberg)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 12:55pm UTC](https://discuss.elastic.co/t/start-of-kibana-fails/345627 "2023-10-25T12:55:22Z")

</div>

Hello! I have installed Kibana 8.8.1 on Windows Server 2012 from the downloaded .zip file. I want to access Kibana via a reverse-proxy site in IIS. Therefore, I have created a scheduled task that runs kibana.bat. That t…

---

## [System Logs visiualizations is not showing in kibana dashboards](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728 "2023-10-25T12:53:14Z")

</div>

I have installed filebeat 8.10.2 and follow the doc to install, i have enabled nginx Apache and system modules. The nginx and apache data is showing in kibana discovery tab and also showing visualizations of these module…

---

## [Can't show distinct value in canvas](https://discuss.elastic.co/t/cant-show-distinct-value-in-canvas/345552)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 11:42am UTC](https://discuss.elastic.co/t/cant-show-distinct-value-in-canvas/345552 "2023-10-25T11:42:26Z")

</div>

Hi, I want to write a sql query to show distinct value in Markdown I got the value as a table but its duplicate so I want to show the distinct value only! I try to write SELECT DISTINCT "Field\_name" from "index\_name"…

---

## [Logs are not visible in Kibana via Elastic-Agent](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana-via-elastic-agent/345432)

<div class="topic-metadata">

**Author:** [@swapnil.pimpalkar](https://discuss.elastic.co/u/swapnil.pimpalkar)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 10:36am UTC](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana-via-elastic-agent/345432 "2023-10-25T10:36:41Z")

</div>

I have install elastic-agent on my one of the host and enabled the sophos module on TCP. I have receiving logs on elastic i have this with the help of tcpdump but not able to see in discovery and dashboard. Can someone …

---

## [Kibana Dashboards constantly showing 408 errors](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 9:48am UTC](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645 "2023-10-25T09:48:59Z")

</div>

Hello, We have a couple of dashboards with multiple visualizations, some of them have a automatic refresh of 5 or 10 minutes and we are stating to get the following error: \[layeredXyVis\] \> \[esaggs\] \> Check your networ…

---

## [Issue while upgrade kibana 7.16.2 to 7.17.0](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715)

<div class="topic-metadata">

**Author:** [@Dheerendra\_Singh\_Na1](https://discuss.elastic.co/u/Dheerendra_Singh_Na1)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715 "2023-10-25T09:45:52Z")

</div>

Getting error " \[info\]\[savedobjects-service\] \[.kibana\] WAIT\_FOR\_YELLOW\_SOURCE -\> WAIT\_FOR\_YELLOW\_SOURCE. took: 124084ms. " while upgrade kibana from 7.16.2 to 7.17.0

---

## [Canvas average values getting error](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660 "2023-10-25T07:20:59Z")

</div>

Hi , I'm using canvas and I have a field sensordata.value.numeric which is a field with many numbers I want to take the average in this field and show it as a % in Gauge visualization but I got an error while doing that …

---

## [Duplicate logs issue with elastic integration with Atlassian Jira](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 10:58pm UTC](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676 "2023-10-24T22:58:06Z")

</div>

Hello Everyone, Hope everyone is good. I am facing an issue, i am doing Elastic OOTB integration with Atlassian Jira using API. the integration is working fine, but i am seeing duplicate logs. Is there a way to get r…

---

## [\[WATCHER\] Failed to Transform payload - Keyword field](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 8:30pm UTC](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666 "2023-10-24T20:30:53Z")

</div>

Hi, I am trying to configure a Watcher of a machine learning job. The ML job is a population job that works with keyword fields. A cause of using the keyword field, watcher gives me this error: This is the search o…

---

## [Inline script not firing due to content security policy - dashboard URL link no longer loading](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 5:31pm UTC](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092 "2023-10-24T17:31:14Z")

</div>

After upgrading my version of kibana, I can no longer load a clickable hyperlink URL with parameters from my dashboard - it just loads indefinitely and throws exceptions. This is the URL I want to load: http://testserv…

---

## [Reporting on Saved Objects](https://discuss.elastic.co/t/reporting-on-saved-objects/344318)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 5:03pm UTC](https://discuss.elastic.co/t/reporting-on-saved-objects/344318 "2023-10-24T17:03:48Z")

</div>

Is there a system index anyone would recommend to use for reporting on Kibana Saved Objects?

---

## [Big issue on Request on Canva and kibana](https://discuss.elastic.co/t/big-issue-on-request-on-canva-and-kibana/344365)

<div class="topic-metadata">

**Author:** [@elteraxya](https://discuss.elastic.co/u/elteraxya)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 5:02pm UTC](https://discuss.elastic.co/t/big-issue-on-request-on-canva-and-kibana/344365 "2023-10-24T17:02:56Z")

</div>

Hello everyone, Recently I used canva to make automated reports however I noticed that esql queries on canva allow more things than kql queries on kibana. So I wanted to know if it's possible to make esql queries on ki…

---

## [Confusing about dashboard showing of AKS node memory](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150)

<div class="topic-metadata">

**Author:** [@John\_Vo](https://discuss.elastic.co/u/John_Vo)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 3:23am UTC](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150 "2023-10-17T03:23:36Z")

</div>

Hi everyone, Currently, I have a bit confuse about dashboard of Memory of AKS node. The Memory usage by Node \[Metrics Kubernetes\] is about 80% The Memory Usage in Infrastructure/Inventory is about 25% Host Ove…

---

## [Kibana logstash pipelines editing multi line](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:42pm UTC](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103 "2023-10-24T16:42:53Z")

</div>

Hi, anyone noticed the UI change when editing logstash pipelines? Not only the font (size) has changed (way too large in my opinion), but also the behavior. You can duplicate lines with shift+alt+arrow key, moving lin…

---

## [Kibana's "average" aggregation display time is showing the time wrong](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333)

<div class="topic-metadata">

**Author:** [@Skimifil](https://discuss.elastic.co/u/Skimifil)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:19pm UTC](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333 "2023-10-24T16:19:46Z")

</div>

I have a pipeline that processes a field, whose value comes in the format "HH:MM:SS", and transforms it into seconds: ruby { code =\> " duration\_parts = event.get('format\_hh\_mm\_ss').split(':').map{|str| str…

---

## [Dashboard-to-dashboard drilldown in Markdowns](https://discuss.elastic.co/t/dashboard-to-dashboard-drilldown-in-markdowns/344167)

<div class="topic-metadata">

**Author:** [@sacalata](https://discuss.elastic.co/u/sacalata)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 3:24pm UTC](https://discuss.elastic.co/t/dashboard-to-dashboard-drilldown-in-markdowns/344167 "2023-10-24T15:24:25Z")

</div>

Is it possible to have "Go to Dashboard" drilldowns in Markdown?, sure we can manually place the link of the dashboard, but that won't keep the current applied filters the same way the drilldown in Lens does.

---

## [How to collect the Infra logs using ELK bitnami Image](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096)

<div class="topic-metadata">

**Author:** [@Saidi\_Reddy\_Morthala](https://discuss.elastic.co/u/Saidi_Reddy_Morthala)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:53pm UTC](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096 "2023-10-24T14:53:23Z")

</div>

Hi. I have installed the ELK VM using bitnami image from Azure Market place and I can able to connect to the ELK home page but unable to find the right article to integrate the Azure VM for logging purpose. Kindly help m…

---

## [Auth kibana through jwt](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384 "2023-10-24T14:14:07Z")

</div>

Hello! I need auth in kibana through jwt. I find documenation for elastic settings. I use id\_token, current config xpack.security.authc.realms.jwt.jwt1: order: 3 token\_type: id\_token client\_authentication.type: s…

---

## [Pass filters dynamic](https://discuss.elastic.co/t/pass-filters-dynamic/344651)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:01pm UTC](https://discuss.elastic.co/t/pass-filters-dynamic/344651 "2023-10-24T14:01:08Z")

</div>

I have marked Hostip in the above screenshot. Here I have hardcoded the hostip and I want to change this hostip from filter to dynamic. I have attached the filter screenshot below

---

## [Difference regarding custom Namespace Setting via Fleet Policy Setting or Integrations itself?](https://discuss.elastic.co/t/difference-regarding-custom-namespace-setting-via-fleet-policy-setting-or-integrations-itself/345290)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 4\
**Last updated:** [October 24, 2023, 1:35pm UTC](https://discuss.elastic.co/t/difference-regarding-custom-namespace-setting-via-fleet-policy-setting-or-integrations-itself/345290 "2023-10-24T13:35:40Z")

</div>

Hello there, hope you're doing fine! My question: For configure any custom Namespace to separate ingested Data in its own/specific Data Streams i've seen two different places to do this. One is via the Fleet Policy it…

---

## [Kibana Lens - Line Type - How to show the percentage of each terms](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 1:46pm UTC](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321 "2023-10-23T13:46:27Z")

</div>

Hi all, I would like to create a visualization of Line type using Lens that display the percentage of each terms. The challange here is: in some documents, I have a field of type array with different values So, as exa…

---

## [Foilebeat IIS Module Config](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 4\
**Last updated:** [October 23, 2023, 12:08pm UTC](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325 "2023-10-23T12:08:57Z")

</div>

I am working on version 8.10.2 of Elastic, Kibana and Filebeat. I am trying to get IIS.YML to work but I am running into a some errors. I am running this command: .\\filebeat.exe -e -c D:\\Filebeat\\modules.d\\iis.yml and…

---

## [Can anyone please explain me the time difference between the json view and the table view?](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 6:46am UTC](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906 "2023-10-23T06:46:17Z")

</div>

Hi Team, I am using an elastic cloud account. My application is sending the data with timestamp in Sydney timezone. I have configured the same in kibana as well. I am almost seeing 11 hours difference between time stamp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=86)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=88)
