# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=90

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 91

---

## [Grok parser question (Invalid json string)](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730)

<div class="topic-metadata">

**Author:** [@superm0](https://discuss.elastic.co/u/superm0)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730 "2023-10-10T11:46:22Z")

</div>

Hi,please assit me with creating custom grok pattern . I've created custom pattern, it works perfectly in Grok Debugger. But i cant add this expression for parsing data: Error: Invalid Json string. %{SYSLOGTIMESTAMP:…

---

## [Wildcard not working](https://discuss.elastic.co/t/wildcard-not-working/344370)

<div class="topic-metadata">

**Author:** [@yash\_gehi](https://discuss.elastic.co/u/yash_gehi)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 11:24am UTC](https://discuss.elastic.co/t/wildcard-not-working/344370 "2023-10-10T11:24:22Z")

</div>

{ "query":{ "wildcard":{ "id": "C0\*" } } } I'm trying to run a get request through postman using this as a json body. there is around 44k entries with this id. But when I run it I cannot see any data in my resp…

---

## [OIDC configuration - Role mapping](https://discuss.elastic.co/t/oidc-configuration-role-mapping/344705)

<div class="topic-metadata">

**Author:** [@Sherwin\_R](https://discuss.elastic.co/u/Sherwin_R)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 7:59am UTC](https://discuss.elastic.co/t/oidc-configuration-role-mapping/344705 "2023-10-10T07:59:00Z")

</div>

I am trying to configure OIDC for signing into kibana. My OP provides a claim token after a successful authentication from which I am trying to map the value of a field called "roles" to kibana user roles. According to …

---

## [EUI Simple navigation with Side Nav](https://discuss.elastic.co/t/eui-simple-navigation-with-side-nav/343141)

<div class="topic-metadata">

**Author:** [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 5:58am UTC](https://discuss.elastic.co/t/eui-simple-navigation-with-side-nav/343141 "2023-10-10T05:58:18Z")

</div>

Hi there. I have some question about Elastic UI. I try create simple form with some navigation Can i get some examples of usage Side Nav with change EuiPageBody? Something like when i switch betweeen config Users an…

---

## [Index doesn't show up in the dashboard although the status of the index is green](https://discuss.elastic.co/t/index-doesnt-show-up-in-the-dashboard-although-the-status-of-the-index-is-green/344604)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 4\
**Last updated:** [October 10, 2023, 5:02am UTC](https://discuss.elastic.co/t/index-doesnt-show-up-in-the-dashboard-although-the-status-of-the-index-is-green/344604 "2023-10-10T05:02:07Z")

</div>

I have setup a filebeat input as follows to read the logs from an application that we are running on the server. The name of the input is the filebeat-2023.10.277. filebeat.inputs: - type: log id: gateway-elk enabl…

---

## [Kibana not available after license expiration](https://discuss.elastic.co/t/kibana-not-available-after-license-expiration/344641)

<div class="topic-metadata">

**Author:** [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Replies:** 4\
**Last updated:** [October 9, 2023, 7:12pm UTC](https://discuss.elastic.co/t/kibana-not-available-after-license-expiration/344641 "2023-10-09T19:12:00Z")

</div>

Hi, Within Kibana, I activated a 30 day trial license. To my surprise, I was "locked out" of Kibana when it expired, getting the "Kibana server is not ready yet" message. Kibana outputs the following: \[INFO \]\[savedobje…

---

## [API Key Minimum Permissions for Querying Kibana Fleet Agents](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093)

<div class="topic-metadata">

**Author:** [@groth](https://discuss.elastic.co/u/groth)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 4:09pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093 "2023-10-09T16:09:31Z")

</div>

I'm on Elastic Cloud 8.9.1 using the Kibana Fleet APIs to pull agent information. In trying to figure out the minimum permissions needed for /api/fleet/agents, I have created a user account with a custom role with permis…

---

## [create netflow filters in kibana dashboard](https://discuss.elastic.co/t/create-netflow-filters-in-kibana-dashboard/344666)

<div class="topic-metadata">

**Author:** [@Franciscofabion\_Nasc](https://discuss.elastic.co/u/Franciscofabion_Nasc)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:11pm UTC](https://discuss.elastic.co/t/create-netflow-filters-in-kibana-dashboard/344666 "2023-10-09T14:11:36Z")

</div>

Hello, I'm new to elasticsearch, and I installed elasticsearch here at work with kibana and netflow. I would like to create a filter that would give me the following information: all destination ports originating from b…

---

## [Use maps inside plugin](https://discuss.elastic.co/t/use-maps-inside-plugin/343503)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 7\
**Last updated:** [October 9, 2023, 1:13pm UTC](https://discuss.elastic.co/t/use-maps-inside-plugin/343503 "2023-10-09T13:13:32Z")

</div>

Hi, I am creating an external custom plugin inside Kibana 8.8.1 using React. I want to have a map visualization inside the plugin. I was referring to the example process https://github.com/elastic/kibana/tree/main/x-pa…

---

## [Iframe dasboard keep reload every 5 seconds](https://discuss.elastic.co/t/iframe-dasboard-keep-reload-every-5-seconds/344526)

<div class="topic-metadata">

**Author:** [@ThaoNguyen](https://discuss.elastic.co/u/ThaoNguyen)\
**Replies:** 4\
**Last updated:** [October 9, 2023, 1:26am UTC](https://discuss.elastic.co/t/iframe-dasboard-keep-reload-every-5-seconds/344526 "2023-10-09T01:26:47Z")

</div>

I embed dashboard in my webapp and dashboard keep reload every 5 seconds with a pink loading bar at the top of frame, every time dashboard get reload all the filters I picked before are removed like timestamp (reverted …

---

## [Centralized Kibana to fetch logstash data from multiple DC](https://discuss.elastic.co/t/centralized-kibana-to-fetch-logstash-data-from-multiple-dc/343571)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 39\
**Last updated:** [October 7, 2023, 9:46pm UTC](https://discuss.elastic.co/t/centralized-kibana-to-fetch-logstash-data-from-multiple-dc/343571 "2023-10-07T21:46:49Z")

</div>

Hi everyone : I got 3 data centers where each one got its own kibana, logstash, and ES cluster with 3 ES nodes.Each DC got its own CA and certiticates which are distributed to all ES nodes. So ourl goal is to get centr…

---

## [Sharepoint sites storage reports (o365 module)](https://discuss.elastic.co/t/sharepoint-sites-storage-reports-o365-module/344600)

<div class="topic-metadata">

**Author:** [@Fabiano\_Vieira](https://discuss.elastic.co/u/Fabiano_Vieira)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 1:07pm UTC](https://discuss.elastic.co/t/sharepoint-sites-storage-reports-o365-module/344600 "2023-10-08T13:07:13Z")

</div>

Hello, I recently added the o365 integration on ELK server with my tenant(Microsoft 365 Services). It works perfeclty but I wanted to monitor the storage of my sites on Sharepoint, I didn't find any field(o365.audit\*) t…

---

## [How Can I Open Document Explorer Graph?](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565)

<div class="topic-metadata">

**Author:** [@newx](https://discuss.elastic.co/u/newx)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565 "2023-10-07T14:02:42Z")

</div>

Hi, I created one node elastic cluster with one rollover index. This stage works very well. BUT, there is no default green counter graph with time selector(you can see from their original documents: https://www.elastic…

---

## [Date Maths in Kibana Query Language](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:25am UTC](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556 "2023-10-07T02:25:40Z")

</div>

I am trying to use date math in my query without success. When I paste a KQL query on the web explorer's address bar I got a successful result with an example like this: base url + time:(from:'2023-10-06T20:44:13.558Z…

---

## [How to give specific disk threshold for specific node in a Elastic cluster](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 5\
**Last updated:** [October 6, 2023, 7:00pm UTC](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247 "2023-10-06T19:00:03Z")

</div>

Hi, I have a multi-node cluster. I want to allocate only 100 shards to a specific node in the elastic cluster. (But other nodes should be allocated more than 100 shards.) I have one node that has less disk space than …

---

## [Documented options to disable xpack plugins in kibana not working as expected and cause container fail to start](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 3:55pm UTC](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529 "2023-10-06T15:55:24Z")

</div>

We are trying kibana 8.9.0 container as a standalone server for the first time and we are trying to disable certain xpack packages using kibana.yml We wanted to disable the below plugins and we are following elastic doc…

---

## [Auth0 integration issues](https://discuss.elastic.co/t/auth0-integration-issues/344392)

<div class="topic-metadata">

**Author:** [@Srinivasan\_Rajagopal](https://discuss.elastic.co/u/Srinivasan_Rajagopal)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 1:13pm UTC](https://discuss.elastic.co/t/auth0-integration-issues/344392 "2023-10-06T13:13:37Z")

</div>

Hey , I am working with a client who is interested in using ELK as log solution and asked to do POC on integration feasibility between Auth0 & Elastic. I have signed up for a elastic cloud trial tenant. I am following t…

---

## [Change Log format](https://discuss.elastic.co/t/change-log-format/344476)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 12:35pm UTC](https://discuss.elastic.co/t/change-log-format/344476 "2023-10-06T12:35:17Z")

</div>

Hello! I want to change format of below mentioned log. I am new to Elk any help will be much appreciated. Thanks \[Mon Oct 02 13:14:00.967345 2023\] \[security2:error\] \[pid 186:tid 140439170467520\] \[client 192.168.76.181:…

---

## [Upload CSV File to Kibana Dashboard](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 25\
**Last updated:** [October 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821 "2023-10-06T10:53:19Z")

</div>

Hi Team, I need help on below two points while uploading csv file through kibana dashboard. How to upload a csv file size of more than 100MB through the kibana dashboard. How to upload multiple csv files to same indic…

---

## [Kibana: Getting "missing authentication credentials for REST request" after creating plugin](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514)

<div class="topic-metadata">

**Author:** [@Akshay\_Kumar\_Gupta](https://discuss.elastic.co/u/Akshay_Kumar_Gupta)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:55am UTC](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514 "2023-10-06T02:55:26Z")

</div>

Hi, I am trying to create a new kibana plugin. whenever I create a new plugin using node scripts/generate\_plugin new\_pl command and start the kibana using yarn start --oss then I get the below error on browser. { "statu…

---

## [Filebeat logging MSSQL ERROR log, but not able to search on Message field in Kibana](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428)

<div class="topic-metadata">

**Author:** [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428 "2023-10-05T22:26:19Z")

</div>

I have Filebeat using the MSSQL module running on a Windows SQL Server exporting logs to an Elasticsearch server. I can view the Filebeat logs in Kibana. But I can't (seem) to search on the Message field. For example,…

---

## [How to display node hostname in Kibana stack monitoring?](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 8:10pm UTC](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504 "2023-10-05T20:10:03Z")

</div>

Hi All, Hostname is set in Elasticsearch and Kibana configurations , but still Kibana stack monitoring is showing only IP address of nodes. Is there any way to show host name also of nodes in stack monitoring in Kibana…

---

## [Run time fields in Kibana VIsualizations](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 9\
**Last updated:** [October 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567 "2023-10-05T15:43:35Z")

</div>

Hello, I have a couple of run time fields defined in the index mappings which calculates the difference between two time stamps in days. It works fine, and I can see the data in Kibana discover. However, if I attempt t…

---

## [How do we write painless script for scripted fields](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467 "2023-10-05T11:49:06Z")

</div>

Hi Team, am trying to write painless script for the below scenario.. i have department numbers like 1100,1200,1300... so, instead of department numbers am expecting short name as IND, USA, UK....by using scripted fiel…

---

## [View SAML Users](https://discuss.elastic.co/t/view-saml-users/344462)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:20am UTC](https://discuss.elastic.co/t/view-saml-users/344462 "2023-10-05T09:20:13Z")

</div>

Hi, does anybody know why I can't see users that login with SAML even though I am an admin? It is necessary to view all users to change their roles otherwise all SAML users have the same role, which I dont want... Any su…

---

## [Import Objects API for Rules/Connectors](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 5:38pm UTC](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409 "2023-10-04T17:38:36Z")

</div>

Hello, Elastic! I'm currently using a curl command to push an Alert Rule. Currently the rule gets created but is created in a 'disabled' state (see warnings.message): { "successCount": 1, "success": true, "warnin…

---

## [Full-text queries with date filter](https://discuss.elastic.co/t/full-text-queries-with-date-filter/344391)

<div class="topic-metadata">

**Author:** [@combbbbinator](https://discuss.elastic.co/u/combbbbinator)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 2:17pm UTC](https://discuss.elastic.co/t/full-text-queries-with-date-filter/344391 "2023-10-04T14:17:51Z")

</div>

Hello. I'm trying to understand whether it is possible to make a full-text request and specify a time filter in the request, for example, for the last 15 minutes? A request that I would like to improve : { "query": { …

---

## [Port 80 is already in use. Another instance of Kibana may be running](https://discuss.elastic.co/t/port-80-is-already-in-use-another-instance-of-kibana-may-be-running/343939)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 11\
**Last updated:** [October 4, 2023, 12:35pm UTC](https://discuss.elastic.co/t/port-80-is-already-in-use-another-instance-of-kibana-may-be-running/343939 "2023-10-04T12:35:11Z")

</div>

Hi team, I'm having problems with kibana Currently I have kibana configured with port 80 and displaying the web interface normally. But when I change to kibana's default port, I get an error and no longer display the w…

---

## [Migrating Saved Objects from Kibana 5.5 to 8.1](https://discuss.elastic.co/t/migrating-saved-objects-from-kibana-5-5-to-8-1/344117)

<div class="topic-metadata">

**Author:** [@Divyanshu\_Raj](https://discuss.elastic.co/u/Divyanshu_Raj)\
**Replies:** 6\
**Last updated:** [October 4, 2023, 11:51am UTC](https://discuss.elastic.co/t/migrating-saved-objects-from-kibana-5-5-to-8-1/344117 "2023-10-04T11:51:40Z")

</div>

Hello Community, we are trying to export our saved objects ( visualizations, dashboards ..) from Kibana 5.5 to Kibana 8.1. The challenge is that exported saved objects from Kibana are in .json format and the expected f…

---

## [How to enable "Continue as Guest" on Kibana?](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 12:05am UTC](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713 "2023-10-04T00:05:37Z")

</div>

I would like to enable "Continue as Guest" on Kibana and have followed the elastic docs but it did not work. My setup is a Kibana container running on Kubernetes that connects to a backend Elasticsearch. Kibana can star…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=89)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=91)
