# Dashboards in ndjson format

**URL:** <https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [December 12, 2023, 9:50am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128 "2023-12-12T09:50:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jean\_BARBIER](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_barbier/32/129622_2.png) [@Jean\_BARBIER](https://discuss.elastic.co/u/Jean_BARBIER)\
**Post date:** [December 12, 2023, 9:50am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/1 "2023-12-12T09:50:41Z")

</div>

Hello,

In the package auditbeat-oss-8.11.2-linux-x86\_64, the dashboards can be found, but they are in json format.  
Since kibana 7.3 the import format is ndjson.  
Is there a way to find them in ndjson format ?

regards

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2023, 11:57am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/2 "2023-12-12T11:57:05Z")

</div>

Bonjour Jean 😉

Auditbeat can normally automatically create the dashboards. See [https://www.elastic.co/guide/en/beats/auditbeat/8.11/configuration-dashboards.html:](https://www.elastic.co/guide/en/beats/auditbeat/8.11/configuration-dashboards.html:)

> To load the dashboards, you can either enable dashboard loading in the `setup.dashboards` section of the `auditbeat.yml` config file, or you can run the `setup` command. Dashboard loading is disabled by default.

Why would you like to do that manually?

---

<div class="post-metadata">

**Author:** ![Jean\_BARBIER](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_barbier/32/129622_2.png) [@Jean\_BARBIER](https://discuss.elastic.co/u/Jean_BARBIER)\
**Post date:** [December 12, 2023, 1:17pm UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/3 "2023-12-12T13:17:36Z")

</div>

Hello David,  
Thanks for your reply.  
I saw that auditbeat can do it using API, but from my auditbeat agent, I have no access to API, auditbeat is not directly connected to elk, it sends to a logstash service which is sending to elk.  
That's why i'm searching a way to import dashboards manually.  
Regards

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [December 12, 2023, 1:25pm UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/4 "2023-12-12T13:25:37Z")

</div>

> [@Jean\_BARBIER](#):
>
> Hello David,  
> Thanks for your reply.  
> I saw that auditbeat can do it using API, but from my auditbeat agent, I have no access to API, auditbeat is not directly connected to elk, it sends to a logstash service which is sending to elk.  
> That's why i'm searching a way to import dashboards manually.  
> Regards

Hi,  
You would need to convert the JSON files to NDJSON format manually, this is a very basic way to convert and might not work for complex JSON objects. There are also online tools available that can convert JSON to NDJSON.

Once you have the NDJSON file, you can import it into Kibana manually.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 12, 2023, 10:39pm UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/5 "2023-12-12T22:39:47Z")

</div>

I see. Out of curiosity, what do you need Logstash for in that case?

---

<div class="post-metadata">

**Author:** ![Jean\_BARBIER](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_barbier/32/129622_2.png) [@Jean\_BARBIER](https://discuss.elastic.co/u/Jean_BARBIER)\
**Post date:** [December 14, 2023, 10:32am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/6 "2023-12-14T10:32:25Z")

</div>

Because, auditbeat agents (as others log providers) are not in the same network zone than elk.

---

<div class="post-metadata">

**Author:** ![Jean\_BARBIER](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_barbier/32/129622_2.png) [@Jean\_BARBIER](https://discuss.elastic.co/u/Jean_BARBIER)\
**Post date:** [January 8, 2024, 8:15am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/7 "2024-01-08T08:15:21Z")

</div>

I've created a temporary elk docker near the auditbeat agents, then import the dashboard with the setup command, and then I've been able to export/import in the ndjson format

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2024, 10:15am UTC](https://discuss.elastic.co/t/dashboards-in-ndjson-format/349128/8 "2024-02-05T10:15:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
