Category "kibana"

AWS OpenSearch running in vpc behind Nginx dont show the tenants

I have an opensearch instance which is in a VPC behind an nginx proxy I cannot see the tenantes in Opensearch, I can create them but not see them. And when I wa

FileBeat not sending data to ElasticSearch Kibana

I'm unable to receive data in the Kibana dashboard from the Filebeat agent. I'm using self-managed ELK with AWS EC2 server. Below is my filebeat.yml filebeat.in

Elasticsearch - Match all arraylist field

I have few documents with array "items" , i want to only pick those documents where "items.name" is equal to "red". If there is any document with one red and an

Elasticsearch: Alert on New IP Address

I've been stuck in a problem for 3 days now..I am trying to alert on new IP address but the format of log file is not helping me so I've used a pipeline to par

In Kibana, querying, how to search for responses of successful bruteforce attack on a password for an account and port scanning of a webserver? Thanks

I would like to learn more about using Kibana in querying/ searching indications of certain attack events, such as bruteforcing an account, scanning/enumerating

Customize Kibana 7.16 logo or inject custome css or js

I'm having a hard time to find the scripts where the logo is defined (navbar logo, startup, login logo ...). I've been looking around for ways to change the log

Launching Elastic Kibana - internal server 500 error - [illegal_argument_exception] application privileges must refer to at least one resource"}

I launched Kibana in my Elastic Cloud account and see this message. Why can I not log in to my Kibana account? I restarted my deployment and see the same error.

How to configure kibana for elastic search?

Currently from my application server (linux) the below is the format of the command that I use to connect to Elastic search which runs on a different server (li

Can I use a single elasticsearch/kibana for multiple k8 clusters?

Do you know of any gotcha's or requirements that would not allow using a single ES/kibana as a target for fluentd in multiple k8 clusters? We are engineering r

How to get sum of field1 for unique values of field2 in Kibana

I have index pattern in kibana. I want to get SUM of one field based on UNIQUE values of second field. How can I get this in kibana visualization. As example :

default username in Elastic cloud (kibana) and how to find a password

I'm trying out the Elastic Cloud 14 days free trial. I deployed Elastic cloud following the video tutorial. I set my password. However, I don't remember putti

Draw tree Layout chart in vega

I want to have a tree chart of my data using vega in kibana 7.9.0, but I don't know how to write the query for that. the below code is an example of tree chart

aws open search not able to insert data

i have given all the required permission from the aws. this error occurs when i tried to create an index. Error response: ResponseError: security_exception: [se

Logging to elastic search with serilog and ILogger

I have written a function to return an ILogger instance. This way I can get consistent logging in all my code. My problem is that when called from different typ

What is the best practice using KQL to filter desired attack signature over (web)logs?

Recently I'm experimenting with logstach and Kibana on top of elastic over (web-)server logs. I tried to extract some attack signature like XSS & SQL inject

Run ingress nginx as a reverse proxy for kibana with appid oauth2 provider

I've read a number of similar questions on here and blogs online, I've tried a number of configuration changes but cannot seem to get anything to work. I'm usin

Elasticsearch-Kibana docker-compose - Value of "elastic" is forbidden

I want to run elasticsearch and kibana with docker-compose. This is my docker-compose.yml which I run with docker-compose --env-file dev.env up Docker Compose v

Wildcard search in Kibana for string text in message field

I have the following plain text string in the message field in Kibana message: Request result. Request: amount=58289.540000, name=Raj, so on..... In Kibana in L

Unable to access Kibana behind NginX reverse proxy on Docker

I have a Docker Compose setup with NginX, ElasticSearch and Kibana like the following: web: build: context: . dockerfile: ./system/docker/develo

Kibana server is not ready yet - [security_exception] unable to authenticate user [elastic]

What happen is I tried to add user for ElasticSearch and Kibana. For ElasticSearch, I added xpack.security.enabled: true at elasticsearch.yml and elasticsearch.