# Unable to download csv from kibana dashboard, "we couldn't generate your csv at this time"

**URL:** <https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991>\
**Category:** Kibana\
**Created:** [April 8, 2024, 3:40pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991 "2024-04-08T15:40:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![robocop](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@robocop](https://discuss.elastic.co/u/robocop)\
**Post date:** [April 8, 2024, 3:40pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/1 "2024-04-08T15:40:31Z")

</div>

Kibana 7.6.2 csv download failed we couldn't generate your csv at this time.

I checked kibana.yml but there is no xpack.reporting.csv.maxSizeBytes mentioned in the settings. Also, I checked with a very small sample too which only had 2 log lines and that too failed. I am attaching kibana.yml and kibana.log for reference.

**Kibana.yml:**  
_# Kibana is served by a back end server. This setting specifies the port to use._  
_#server.port: xxxx_

_# Specifies the address to which the Kibana server will bind. IP addresses and host names are both valid values._  
_# The default is 'localhost', which usually means remote machines will not be able to connect._  
_# To allow connections from remote users, set this parameter to a non-loopback address._  
_#server.host: "localhost"_  
_server.host: "x.x.x.x"_  
_# Enables you to specify a path to mount Kibana at if you are running behind a proxy._  
_# Use the `server.rewriteBasePath` setting to tell Kibana if it should remove the basePath_  
_# from requests it receives, and to prevent a deprecation warning at startup._  
_# This setting cannot end in a slash._  
_#server.basePath: ""_

_# Specifies whether Kibana should rewrite requests that are prefixed with_  
_# `server.basePath` or require that they are rewritten by your reverse proxy._  
_# This setting was effectively always `false` before Kibana 6.3 and will_  
_# default to `true` starting in Kibana 7.0._  
_#server.rewriteBasePath: false_

_# The maximum payload size in bytes for incoming server requests._  
_server.maxPayloadBytes: 10485760_

_# The Kibana server's name. This is used for display purposes._  
_#server.name: "your-hostname"_

_# The URLs of the Elasticsearch instances to use for all your queries._  
_#elasticsearch.hosts: ["xxxxx"]_  
_elasticsearch.hosts: ["xxxxx", "xxxxxx"]_  
_# When this setting's value is true Kibana uses the hostname specified in the server.host_  
_# setting. When the value of this setting is false, Kibana uses the hostname of the host_  
_# that connects to this Kibana instance._  
_#elasticsearch.preserveHost: true_

_# Kibana uses an index in Elasticsearch to store saved searches, visualizations and_  
_# dashboards. Kibana creates a new index if the index doesn't already exist._  
_#kibana.index: ".kibana"_  
_kibana.index: ".kibana-6"_

_# The default application to load._  
_#kibana.defaultAppId: "home"_  
_#kibana.defaultAppId: "dashboard/BaseFiltered"_  
_kibana.defaultAppId: "dashboard/"_  
_# If your Elasticsearch is protected with basic authentication, these settings provide_  
_# the username and password that the Kibana server uses to perform maintenance on the Kibana_  
_# index at startup. Your Kibana users still need to authenticate with Elasticsearch, which_  
_# is proxied through the Kibana server._  
_#elasticsearch.username: "xxxxx"_  
_#elasticsearch.password: "xxxx"_  
_elasticsearch.username: "xxxxxxxxxxxxxxx"_  
_elasticsearch.password: "xxxxxxxxxxxxxxx"_  
_# Enables SSL and paths to the PEM-format SSL certificate and SSL key files, respectively._  
_# These settings enable SSL for outgoing requests from the Kibana server to the browser._  
_xpack.security.enabled: false_  
_server.ssl.enabled: true_  
_elasticsearch.ssl.verificationMode: none_  
_#server.ssl.certificate: /path/to/your/server.crt_  
_server.ssl.key: /etc/kibana/sys.key_  
_#server.ssl.key: /path/to/your/server.key_  
_server.ssl.certificate: /etc/kibana/sys.cer_  
_#elasticsearch.ssl.verfication: false_  
_elasticsearch.ssl.certificateAuthorities: /etc/kibana/rootca.cer_  
_#######SearchGaurd#######_  
_#searchguard.basicauth.enabled:false_  
_searchguard.session.ttl: 2147483646_  
_searchguard.session.keepalive: true_  
_searchguard.cookie.ttl: 0_

_# Optional settings that provide the paths to the PEM-format SSL certificate and key files._  
_# These files are used to verify the identity of Kibana to Elasticsearch and are required when_  
_# xpack.security.http.ssl.client\_authentication in Elasticsearch is set to required._  
_#elasticsearch.ssl.certificate: /path/to/your/client.crt_  
_#elasticsearch.ssl.key: /path/to/your/client.key_

_# Optional setting that enables you to specify a path to the PEM file for the certificate_  
_# authority for your Elasticsearch instance._  
_#elasticsearch.ssl.certificateAuthorities: ["/path/to/your/CA.pem"]_

_# To disregard the validity of SSL certificates, change this setting's value to 'none'._  
_#elasticsearch.ssl.verificationMode: full_

_# Time in milliseconds to wait for Elasticsearch to respond to pings. Defaults to the value of_  
_# the elasticsearch.requestTimeout setting._  
_#elasticsearch.pingTimeout: 1500_

_# Time in milliseconds to wait for responses from the back end or Elasticsearch. This value_  
_# must be a positive integer._  
_#elasticsearch.requestTimeout: 30000_

_# List of Kibana client-side headers to send to Elasticsearch. To send no client-side_  
_# headers, set this value to [] (an empty list)._  
_#elasticsearch.requestHeadersWhitelist: [authorization]_

_# Header names and values that are sent to Elasticsearch. Any custom headers cannot be overwritten_  
_# by client-side headers, regardless of the elasticsearch.requestHeadersWhitelist configuration._  
_#elasticsearch.customHeaders: {}_

_# Time in milliseconds for Elasticsearch to wait for responses from shards. Set to 0 to disable._  
_#elasticsearch.shardTimeout: 30000_

_# Time in milliseconds to wait for Elasticsearch at Kibana startup before retrying._  
_#elasticsearch.startupTimeout: 5000_

_# Logs queries sent to Elasticsearch. Requires logging.verbose set to true._  
_#elasticsearch.logQueries: false_

_# Specifies the path where Kibana creates the process ID file._  
_#pid.file: /var/run/kibana.pid_

_# Enables you specify a file where Kibana stores log output._  
_#logging.dest: /var/log/kibana/kibana2.log_

_# Set the value of this setting to true to suppress all logging output._  
_#logging.silent: false_

_# Set the value of this setting to true to suppress all logging output other than error messages._  
_#logging.quiet: false_

_# Set the value of this setting to true to log all events, including system usage information_  
_# and all requests._  
_#logging.verbose: false_

_# Set the interval in milliseconds to sample system and process performance_  
_# metrics. Minimum is 100ms. Defaults to 5000._  
_#ops.interval: 5000_

_# Specifies locale to be used for all localizable strings, dates and number formats._  
_# Supported languages are the following: English - en , by default , Chinese - zh-CN ._  
_#i18n.locale: "en"_

**Kibana log:**  
\*_{"type":"log","@timestamp":"2024-04-08T14:23:46Z","tags":["reporting","csv\_from\_savedobject","execute-job","immediate","info"],"pid":1442,"message":"Executing job from immediate API"}_

\*{"type":"error","@timestamp":"2024-04-08T14:23:46Z","tags":["reporting","csv\_from\_savedobject","execute-job","immediate","error"],"pid":1442,"level":"error","error":{"message":"[parsing\_exception] [query\_string] \*  
\*query does not support [0], with { line=1 & col=226 }","name":"Error","stack":"Error: [parsing\_exception] [query\_string] query does not support [0], with { line=1 & col=226 }\n at respond \*  
\*(/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:349:15)\n at checkRespForFailure (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:306:7)\n at HttpConnector. \*  
\*(/usr/share/kibana/node\_modules/elasticsearch/src/lib/connectors/http.js:173:7)\n at IncomingMessage.wrapper (/usr/share/kibana/node\_modules/elasticsearch/node\_modules/lodash/lodash.js:4929:19)\n at IncomingMessage.emit \*  
\*(events.js:203:15)\n at endReadableNT (\_stream\_readable.js:1145:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19)"},"message":"[parsing\_exception] [query\_string] query does not support [0], with \*  
_{ line=1 & col=226 }"}_

_{"type":"log","@timestamp":"2024-04-08T14:23:46Z","tags":["reporting","csv\_from\_savedobject","execute-job","immediate","error"],"pid":14,"message":"Generate CSV Error! [parsing\_exception] [query\_string] query does not support \*  
 [0], with { line=1 & col=226 } :: {"path":"/logstash-/\_search","query":{"scroll":"30s","size":500},"body":"{\"source\":{\"includes\":[\"@timestamp\",\"EventTime\",\"Hostname\",\*  
\*"SyslogSeverity\",\"SourceName\",\"Message\"]},\"docvalue\_fields\":[\"@timestamp\",{\"field\":\"@timestamp\",\"format\":\"date\_time\"}],\"query\":{\"bool\":{\"must\":[{\*  
 "query\_string\":{\"0\":\"{\",\"1\":\" \",\"2\":\"\\\"\",\"3\":\"a\",\"4\":\"n\",\"5\":\"a\",\"6\":\"l\",\"7\":\"y\",\"8\":\"z\",\"9\":\"e\",  
\*\"10\":\"\",\"11\":\"w\",\"12\":\"i\",\"13\":\"l\",\"14\":\"d\",\"15\":\"c\",\"16\":\"a\",\"17\":\"r\",\"18\":\"d\",\"19\":\"\\\"\",\"20\":_  
_\":\",\"21\":\" \",\"22\":\"t\",\"23\":\"r\",\"24\":\"u\",\"25\":\"e\",\"26\":\" \",\"27\":\"}\",\"query\":\"_\",\"analyze\_wildcard\":true,\"time\_zone\"\*  
_:\"America/Toronto\"}}],\"filter\":[{\"range\":{\"@timestamp\":{\"format\":\"strict\_date\_time\",\"gte\":\"2024-04-07T20:00:00-04:00\",\"lte\":\"2024-04-07T20:30:00-04:00\"}}},{\"bool\"_  
_:{\"must\":[{\"query\_string\":{\"query\":\"_\",\"analyze\_wildcard\":true,\"time\_zone\":\"America/Toronto\"}},{\"match\_all\":{}}],\"filter\":[{\"match\_phrase\":{\"SyslogSeverity.keyword\*  
\*":\"ERR\"}},{\"match\_phrase\":{\"SourceName\":\"DistTransfer\"}},{\"range\":{\"@timestamp\":{\"gte\":\"2024-04-08T00:00:00.000Z\",\"lte\":\"2024-04-08T00:30:00.000Z\",\"format\":\*  
_"strict\_date\_optional\_time\"}}}],\"should\":[],\"must\_not\":[{\"match\_phrase\":{\"SyslogSeverity\":{\"query\":\"DEBUG\"}}},{\"match\_phrase\":{\"SyslogSeverity\":{\"query\":\"INFO\"}}},_  
\*{\"match\_phrase\":{\"Message\":\"is expired since\"}},{\"match\_phrase\":{\"Location\":\"Alpha\"}},{\"match\_phrase\":{\"Message\":\"ui\_log\_type=error\"}},{\"match\_phrase\":{\*  
\*"SourceName\":\"Collector\"}},{\"match\_phrase\":{\"SourceName\":\"Processing\"}},{\"match\_phrase\":{\"SourceName\":\"Other\"}}]}}],\"should\":,\"must\_not\":}},\"script\_fields\":{},\*  
\*"sort\":[{\"@timestamp\":{\"order\":\"desc\",\"unmapped\_type\":\"boolean\"}},{\"@timestamp\":{\"order\":\"desc\"}}]}","statusCode":400,"response":"{\"error\":{\"root\_cause\":[{\*  
_"type\":\"parsing\_exception\",\"reason\":\"[query\_string] query does not support [0]\",\"line\":1,\"col\":226}],\"type\":\"parsing\_exception\",\"reason\":\"[query\_string] query does not support_

- [0]\",\"line\":1,\"col\":226},\"status\":400}"}"}\*

- 
  - 

- 
  - 

- 
  - 

_{"type":"error","@timestamp":"2024-04-08T14:23:46Z","tags":[],"pid":144,"level":"error","error":{"message":"[parsing\_exception] [query\_string] query does not support [0], with { line=1 & col=226 }","name":"Error","stack":_  
\*"Error: [parsing\_exception] [query\_string] query does not support [0], with { line=1 & col=226 }\n at respond (/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:349:15)\n at checkRespForFailure \*  
\*(/usr/share/kibana/node\_modules/elasticsearch/src/lib/transport.js:306:7)\n at HttpConnector. (/usr/share/kibana/node\_modules/elasticsearch/src/lib/connectors/http.js:173:7)\n at IncomingMessage.wrapper \*  
\*(/usr/share/kibana/node\_modules/elasticsearch/node\_modules/lodash/lodash.js:4929:19)\n at IncomingMessage.emit (events.js:203:15)\n at endReadableNT (\_stream\_readable.js:1145:12)\n at process.\_tickCallback \*  
_(internal/process/next\_tick.js:63:19)"},"url":{"protocol":null,"slashes":null,"auth":null,"host":null,"port":null,"hostname":null,"hash":null,"search":null,"query":{},"pathname":"/api/reporting/v1/generate/immediate/csv/_  
\*saved-object/search:logstash2","path":"/api/reporting/v1/generate/immediate/csv/saved-object/search:logstash2","href":"/api/reporting/v1/generate/immediate/csv/saved-object/search:logstash2"},"message":"[parsing\_exception] \*  
_[query\_string] query does not support [0], with { line=1 & col=226 }"}_

_{"type":"response","@timestamp":"2024-04-08T14:23:46Z","tags":["api"],"pid":1442,"method":"post","statusCode":500,"req":{"url":"/api/reporting/v1/generate/immediate/csv/saved-object/search:logstash2","method":"post","headers":_  
_{"host":"xxxxxxx","connection":"keep-alive","content-length":"1021","sec-ch-ua":"" Not;A Brand";v="99", "Google Chrome";v="91", "Chromium";v="91"","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Windows NT 10.0_  
_; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36","kbn-version":"7.6.2","content-type":"application/json","accept":"_/_","origin":"xxxx","sec-fetch-site":"same-origin",_  
_"sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"xxxxxx/","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"x.x.x.x","userAgent":"x.x.x.x",_  
_"referer":"xxxxx"},"res":{"statusCode":500,"responseTime":214,"contentLength":9},"message":"POST /api/reporting/v1/generate/immediate/csv/saved-object/search:logstash2 500 214ms - 9.0B"}_

_{"type":"response","@timestamp":"2024-04-08T14:23:46Z","tags":[],"pid":1442,"method":"get","statusCode":304,"req":{"url":"/bundles/kbn-ui-shared-deps/icon.alert-js.js","method":"get","headers":{"host":"xxxxx","connection":_  
_"keep-alive","sec-ch-ua":"" Not;A Brand";v="99", "Google Chrome";v="91", "Chromium";v="91"","sec-ch-ua-mobile":"?0","user-agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) \*  
 Chrome/ Safari/","accept":"/_","sec-fetch-site":"same-origin","sec-fetch-mode":"no-cors","sec-fetch-dest":"script","referer":"xxxxx","accept-encoding":"gzip, deflate, br",\*  
_"accept-language":"en-US,en;q=0.9","if-none-match":""fasdfasdgasge-/bundles/kbn-ui-shared-deps/-gzip""},"remoteAddress":"x.x.x.x","userAgent":"x.x.x.x","referer":"xxxxx"}_  
_,"res":{"statusCode":304,"responseTime":4,"contentLength":9},"message":"GET /bundles/kbn-ui-shared-deps/icon.alert-js.js 304 4ms - 9.0B"}_

---

<div class="post-metadata">

**Author:** ![Dzmitry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dzmitry/32/65026_2.png) [@Dzmitry](https://discuss.elastic.co/u/Dzmitry)\
**Post date:** [April 12, 2024, 7:10pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/2 "2024-04-12T19:10:34Z")

</div>

Hi @robocop ,

There is a reporting [troubleshoot guide](https://www.elastic.co/guide/en/kibana/7.6/reporting-troubleshooting.html) available, I suggest go and check it.

You can also try to generate it for the different dashboard, that uses different data view.

Best, Dima

---

<div class="post-metadata">

**Author:** ![robocop](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@robocop](https://discuss.elastic.co/u/robocop)\
**Post date:** [April 16, 2024, 2:31pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/3 "2024-04-16T14:31:17Z")

</div>

@tsullivan and @timroes, any input regarding this?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [April 16, 2024, 3:59pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/4 "2024-04-16T15:59:04Z")

</div>

Hi,

- Please use some formatting in your message so the log message is shown more clearly.
- It looks like an error was logged, `query does not support [0], with { line=1 & col=226 }`. Maybe try regenerating the query used for the search
- This could be due to a bug in Kibana 7.6 and could be remedied by upgrading.
- Check to make sure your license is valid

---

<div class="post-metadata">

**Author:** ![robocop](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@robocop](https://discuss.elastic.co/u/robocop)\
**Post date:** [April 16, 2024, 4:08pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/5 "2024-04-16T16:08:39Z")

</div>

Thanks for the reply, It does say Search Guard license expired, does that disable the ability to generate CSV?

---

<div class="post-metadata">

**Author:** ![robocop](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@robocop](https://discuss.elastic.co/u/robocop)\
**Post date:** [April 18, 2024, 5:55pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/6 "2024-04-18T17:55:37Z")

</div>

@tsullivan I see it works from discover page but not from any dashboard that we created.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [April 18, 2024, 10:40pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/7 "2024-04-18T22:40:26Z")

</div>

> [@robocop](#):
>
> Thanks for the reply, It does say Search Guard license expired, does that disable the ability to generate CSV?

This wouldn't affect CSV exports. I was referring to the validity of your Elastic license: CSV exports require a Basic license or higher.

> [@robocop](#):
>
> @tsullivan I see it works from discover page but not from any dashboard that we created.

This sounds like a bug. I recommend upgrading to at least 7.17 and see if the problem is resolved.

---

<div class="post-metadata">

**Author:** ![robocop](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@robocop](https://discuss.elastic.co/u/robocop)\
**Post date:** [April 19, 2024, 2:44pm UTC](https://discuss.elastic.co/t/unable-to-download-csv-from-kibana-dashboard-we-couldnt-generate-your-csv-at-this-time/356991/8 "2024-04-19T14:44:21Z")

</div>

Thanks much appreciated!
