# Create Kibana dashboard has problems

**URL:** <https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015>\
**Category:** Kibana\
**Created:** [November 11, 2020, 7:43am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015 "2020-11-11T07:43:55Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 11, 2020, 7:43am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/1 "2020-11-11T07:43:55Z")

</div>

Hello [discuss.elastic.co](http://discuss.elastic.co),

My name is Bogdan Oproescu, and I am senior data architect for EasyDO Technologies in Bucharest. I am leading our Elastic projects and technology at EasyDO, and we currently have the following issue:

1. we create several DSL queries that we suit to our specific needs for reporting.
2. we then go to Kibana --\> create new dashboard, and we would like to create this new dashboard, on the basis of each of our DSL queries.  
... continued ...

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 11, 2020, 7:46am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/2 "2020-11-11T07:46:40Z")

</div>

1. however, what we find instead, is that the Kibana interface for creating dashboards, actually modifies the initial DSL queries that we need to use!  
3.1. what actually happens, is that on the right-side lower part of the page, Kibana still respects the Count aggregation by default, and there is no way that we know, to disable all of the aggregations in the Metrics block there, and let our DSL queries run the way that we wrote them!

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 11, 2020, 7:49am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/3 "2020-11-11T07:49:06Z")

</div>

3.2. so it appears that our initial DSL queries are always modified by this Kibana dashboard interface, even when we use the Lucene == Query DSL type, as is documented on your site!  
3.3. my question is therefore: how can we make Kibana not modify our DSL queries, with these default aggregation types, and just run our DSL queries as they are: please confirm this to us, this is an important issue that we need to resolve quickly!  
thanks in advance, Bogdan

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 11, 2020, 6:47pm UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/4 "2020-11-11T18:47:29Z")

</div>

Hi Bogdan- I am not sure I understand what your issue is. Kibana doesn't modify your DSL queries, but it does add a time filter when your Kibana index pattern has a "primary time field". Is the time filter the thing you are asking about?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [November 11, 2020, 11:18pm UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/5 "2020-11-11T23:18:31Z")

</div>

Hi Bogdan,  
Are you creating your DSL queries in Discover and saving those saved searches, and then adding those to a dashboard?

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 12, 2020, 1:24am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/6 "2020-11-12T01:24:46Z")

</div>

hi Wylie, thanks for taking the time to respond: OK good to know that Kibana doesn't modify our DSL queries, but from our experience it did modify them. For example, as I wrote earlier, what actually happens, is that on the right-side lower part of the page, Kibana still respects the Count aggregation by default, and there is no way that we know, to disable all of the aggregations in the Metrics block there, and let our DSL queries run the way that we wrote them!

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 12, 2020, 1:27am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/7 "2020-11-12T01:27:38Z")

</div>

and secondly Wylie, I don't know if our Kibana index pattern has a primary time field: I will post it to this reply so you can see for yourself if it has or not:  
indent preformatted text by 4 spaces  
' {  
"mappings": {  
"access\_log": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"accessdeniedreason": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"accesspermited": {  
"type": "boolean"  
},  
"accesstime": {  
"type": "date"  
},  
"controllerid": {  
"type": "long"  
},  
"direction": {  
"type": "long"  
},  
"employeeid": {  
"type": "long"  
},  
"employeetagid": {  
"type": "long"  
},  
"facecaptureid": {  
"type": "long"  
},  
"id": {  
"type": "long"  
},  
"tagcode": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"tagtype": {  
"type": "long"  
},  
"terminalid": {  
"type": "long"  
}  
}  
}  
}  
}  
'

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 12, 2020, 1:30am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/8 "2020-11-12T01:30:27Z")

</div>

hi Lee, thanks for responding: yes, we are creating our DSL queries in the Kibana dev\_tools console, and then trying to use these same DSQ queries (unmodified!) to create Kibana dashboards: good guess! But the point is, that something strange happens to our DSL queries in this process, and they get completely messed up!  
Once again, we need to create visualizations based 100% on our DSL queries!  
thanks, Bogdan

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 12, 2020, 4:31pm UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/9 "2020-11-12T16:31:55Z")

</div>

It sounds like your complaint is that you are getting **aggregated** data, not **individual documents**. Here are your options:

1. To see individual documents in a dashboard, you can save your Discover search and add it to a dashboard. You can add _filters only_.

2. To use the full query DSL by typing JSON, then you need to [use Vega](https://www.elastic.co/guide/en/kibana/7.10/vega-lite-tutorial-create-your-first-visualizations.html)

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 13, 2020, 8:21am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/10 "2020-11-13T08:21:53Z")

</div>

Hello Wylie,  
thanks for your reply: yes, I think the problem is that we are getting aggregated data, ad not individual documents.  
Can you please describe in more detail your points 1 and 2 below:

1. To see individual documents in a dashboard, you can save your Discover search and add it to a dashboard. You can add _filters only_ . **Bogdan:** can you provide an example of this, and what exactly do you mean by filters?
2. To use the full query DSL by typing JSON, then you need to [use Vega](https://www.elastic.co/guide/en/kibana/7.10/vega-lite-tutorial-create-your-first-visualizations.html) **Bogdan:** we have never used Vega until now, and from an article I read yesterday on this, it says this:

> When you first open the Vega editor in Kibana, you will see a pre-populated line chart which shows the total number of documents across all your indices within the time range.

but we cannot find this Vega editor in Kibana anywhere: do we need to install it separately? please confirm the above questions so we can progress further on this topic!  
thanks in advance, Bogdan

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [November 13, 2020, 3:34pm UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/11 "2020-11-13T15:34:45Z")

</div>

To read about how to use Discover, including saving a search from discover, you can read the docs. [https://www.elastic.co/guide/en/kibana/current/discover.html](https://www.elastic.co/guide/en/kibana/current/discover.html)

Vega is part of Visualize. It is GA in 7.10, but before this time it was hidden if you have changed the Kibana setting `visualize:enableLabs`.

---

<div class="post-metadata">

**Author:** ![bogdan.oproescu](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Post date:** [November 19, 2020, 8:50am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/12 "2020-11-19T08:50:29Z")

</div>

hi Wylie, thanks for your posts earlier on this issue: we have noted your points above, and therefore we will progress in 2 directions here:

1. To read about how to use Discover, including saving a search from discover, you can read the docs. [https://www.elastic.co/guide/en/kibana/current/discover.html](https://www.elastic.co/guide/en/kibana/current/discover.html) and:
2. we will also look at Vega, as you mentioned, to use the full query DSL by typing JSON.  
thanks again, and you can close this ticket now!  
greetings from Bucharest, Bogdan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2020, 8:50am UTC](https://discuss.elastic.co/t/create-kibana-dashboard-has-problems/255015/13 "2020-12-17T08:50:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
