• Kibana Guide: other versions:
  • What is Kibana?
  • What’s new in 7.8
  • Get started
    • Explore Kibana using sample data
    • Build your own dashboard
      • Define your index patterns
      • Discover your data
      • Visualize your data
      • Add the visualizations to a dashboard
  • Set up Kibana
    • Install Kibana
      • Install from archive on Linux or macOS
      • Install on Windows
      • Install with Debian package
      • Install with RPM
      • Install with Docker
      • Install on macOS with Homebrew
    • Configure Kibana
      • Alerting and action settings
      • APM settings
      • Development tools settings
      • Graph settings
      • Ingest Manager settings
      • i18n settings
      • Logs settings
      • Metrics settings
      • Machine learning settings
      • Monitoring settings
      • Reporting settings
      • Secure settings
      • Security settings
      • Spaces settings
      • Telemetry settings
    • Start and stop Kibana
    • Access Kibana
    • Add data to Kibana
    • Use Kibana in a production environment
    • Upgrade Kibana
      • Standard upgrade
      • Upgrade migrations
    • Configure monitoring
      • Collect monitoring data with Metricbeat
      • View monitoring data
      • Legacy collection methods
    • Configure security
      • Authentication
      • Encrypt communications
      • Mutual TLS with Elasticsearch
      • Audit logs
      • Access agreement
  • Discover
    • Create an index pattern
    • Set the time filter
    • Search data
      • Kibana Query Language
      • Lucene query syntax
      • Save a search
      • Save a query
    • Filter by field
    • View document data
    • View a document in context
    • View field data statistics
  • Dashboard
    • Create a dashboard
    • Use drilldowns for dashboard actions
    • Share the dashboard
  • Canvas
    • Canvas tutorial
    • Create a workpad
      • Add elements
      • Present your workpad
      • Share your workpad
    • Canvas expression lifecycle
      • Expressions always start with a function
      • Function arguments
      • Aliases and unnamed arguments
      • Change your expression, change your output
      • Fetch and manipulate data
      • Compose functions with sub-expressions
      • Handling context and argument types
    • Canvas function reference
      • TinyMath functions
  • Maps
    • Get started
      • Create a map
      • Add a choropleth layer
      • Add layers for the Elasticsearch data
      • Save the map
      • Add the map to a dashboard
    • Heat map layer
    • Tile layer
    • Vector layer
      • Vector styling
      • Vector style properties
      • Vector tooltips
    • Plot big data
      • Grid aggregation
      • Top hits per entity
      • Point to point
      • Term join
    • Search geographic data
      • Create filters from a map
      • Filter a single layer
      • Search across multiple indices
    • Configure map settings
    • Connect to Elastic Maps Service
    • Upload GeoJSON data
      • Tutorial: Index GeoJSON data
    • Troubleshoot
  • Machine learning
    • Anomaly detection
    • Data frame analytics
  • Graph
    • Create a graph
    • Configure Graph
    • Troubleshoot
    • Limitations
  • Visualize
    • Supported aggregations
    • Lens
    • Most frequently used visualizations
    • TSVB
    • Timelion
    • Heat map
    • Dashboard tools
    • Vega
      • Query Elasticsearch
      • Access Elastic Map Service files
      • Debugging Vega
      • Resources and examples
  • Logs
  • Metrics
  • APM
    • Set up
    • Get started
      • Services overview
      • Traces overview
      • Transaction overview
      • Span timeline
      • Errors overview
      • Metrics overview
      • Service maps
    • How-to guides
      • Configure APM agents with central config
      • Create an alert
      • Create custom links
      • Enable error reports
      • Filter data
      • Integrate with machine learning
      • Query your data
      • Track deployments with annotations
    • Users and privileges
      • Create an APM reader user
      • Create an annotation user
      • Create a central config user
      • Create an API user
    • Settings
    • REST API
      • Agent Configuration API
      • Annotation API
      • Kibana API
    • Troubleshooting
  • Uptime
  • SIEM
    • Using the SIEM UI
    • Anomaly Detection with Machine Learning
  • Dev Tools
    • Console
    • Profiling queries and aggregations
      • Getting Started
      • Profiling a more complicated query
      • Rendering pre-captured profiler JSON
    • Debugging grok expressions
    • Painless Lab
  • Stack Monitoring
    • Beats Metrics
    • Cluster Alerts
    • Elasticsearch Metrics
    • Kibana Metrics
    • Logstash Metrics
    • Troubleshooting
  • Management
    • Advanced Settings
    • Alerts and Actions
      • Managing Alerts
      • Alert details
      • Managing Connectors
    • Beats Central Management
    • Cross-Cluster Replication
    • Index Lifecycle Policies
      • Creating an index lifecycle policy
      • Managing index lifecycle policies
      • Adding a policy to an index
    • Index Management
    • Ingest Node Pipelines
    • Index patterns and fields
      • String field formatters
      • Date field formatters
      • Geographic point field formatters
      • Numeric field formatters
      • Scripted fields
    • License Management
    • Numeral Formatting
    • Remote Clusters
    • Rollup Jobs
    • Saved Objects
    • Security
      • Granting access to Kibana
      • Kibana role management
      • Kibana privileges
      • API Keys
      • Role mappings
      • Tutorial: Use role-based access control to customize Kibana spaces
    • Snapshot and Restore
      • Tutorial: Snapshot and Restore
    • Spaces
    • Upgrade Assistant
    • Watcher
  • Ingest Manager
  • Reporting
    • Automating report generation
    • Reporting configuration
      • Reporting and security
      • Secure the reporting endpoints
      • Restrict requests with a Reporting network policy
      • Chromium sandbox
    • Troubleshooting
    • Reporting integration
  • Alerting and Actions
    • Defining alerts
    • Action and connector types
      • Email action
      • Index action
      • PagerDuty action
      • Server log action
      • Slack action
      • Webhook action
      • Preconfigured connectors and action types
    • Alert types
    • Scale and performance
  • REST API
    • Using the APIs
    • Get features API
    • Kibana spaces APIs
      • Create space
      • Update space
      • Get space
      • Get all spaces
      • Delete space
      • Copy saved objects to space
      • Resolve copy to space conflicts
    • Kibana role management APIs
      • Create or update role
      • Get specific role
      • Get all roles
      • Delete role
    • Saved objects APIs
      • Get object
      • Bulk get objects
      • Find objects
      • Create saved objects
      • Bulk create saved objects
      • Update object
      • Delete object
      • Export objects
      • Import objects
      • Resolve import errors
    • Import and export dashboard APIs
      • Import dashboard
      • Export dashboard
    • Logstash configuration management APIs
      • Delete pipeline
      • List pipeline
      • Create Logstash pipeline
      • Retrieve pipeline
    • Shorten URL
    • Upgrade assistant APIs
      • Upgrade readiness status
      • Start or resume reindex
      • Batch start or resume reindex
      • Batch reindex queue
      • Add default field
      • Check reindex status
      • Cancel reindex
  • Kibana plugins
    • Install plugins
    • Update and remove plugins
    • Disable plugins
    • Configure the plugin manager
    • Known Plugins
  • Accessibility
  • Limitations
  • Breaking Changes
    • 7.8
    • 7.7
    • 7.6
    • 7.5
    • 7.4
    • 7.3
    • 7.2
    • 7.1
    • 7.0
  • Release Notes
    • Kibana 7.8.1
    • Kibana 7.8.0
    • Kibana 7.7.1
    • Kibana 7.7.0
    • Kibana 7.6.2
    • Kibana 7.6.1
    • Kibana 7.6.0
    • Kibana 7.5.2
    • Kibana 7.5.1
    • Kibana 7.5.0
    • Kibana 7.4.2
    • Kibana 7.4.1
    • Kibana 7.4.0
    • Kibana 7.3.2
    • Kibana 7.3.1
    • Kibana 7.3.0
    • Kibana 7.2.1
    • Kibana 7.2.0
    • Kibana 7.1.1
    • Kibana 7.1.0
    • Kibana 7.0.1
    • Kibana 7.0.0
    • Kibana 7.0.0-rc2
    • Kibana 7.0.0-rc1
    • Kibana 7.0.0-beta1
    • Kibana 7.0.0-alpha2
    • Kibana 7.0.0-alpha1
  • Developer guide
    • Core Development
      • Considerations for basePath
      • Managing Dependencies
      • Modules and Autoloading
      • Communicating with Elasticsearch
      • Unit Testing
      • Functional Testing
      • Daily Elasticsearch Snapshots
    • Plugin Development
      • Plugin Resources
      • UI Exports
      • Plugin feature registration
      • Functional Tests for Plugins
      • Localization for plugins
    • Developing Visualizations
    • Add Data Guide
    • Security
      • Role-based access control
    • Pull request review guidelines
    • Interpreting CI Failures