7.3 Dashboard Exporting, Reporting & Spaces Sharing

Key Takeaways

  • Kibana Reporting Service utilizes an asynchronous, headless Chromium browser architecture to generate pixel-perfect vector PDF and PNG visual reports from security dashboards.

  • Recurring reports can be automated by calling a report's POST URL from Watcher or an external scheduler, supporting daily SOC handovers and executive compliance documentation.

  • Lens and table panels download their aggregated rows as CSV in the browser, while Generate CSV reports from saved searches export matching documents server-side for offline audits.

  • Kibana Saved Objects (dashboards, data views, visualizations) are exported and imported as Newline Delimited JSON (NDJSON) files with deep dependency resolution, facilitating GitOps migrations.

  • Kibana Spaces provide multi-tenant organizational isolation and role-based access control (RBAC), enabling security teams to segregate Tier 1 triage, executive governance, and client environments.

Last updated: September 2026

Operational Delivery and Governance in Security Operations

A security dashboard's utility extends far beyond real-time browser sessions in the SOC. Security operations must routinely deliver intelligence to diverse stakeholders who do not operate within Kibana on a daily basis: chief information security officers requiring weekly posture summaries, external regulatory auditors demanding compliance evidence, incident response teams requiring raw CSV log extracts for external forensic tooling, and enterprise leadership requiring executive briefs. Furthermore, large enterprises and Managed Security Service Providers (MSSPs) must segregate operational environments across business units or external clients to enforce strict data governance.

Elastic Stack provides enterprise-grade reporting, export, saved object lifecycle management, and workspace partitioning mechanisms. Mastering these capabilities ensures that security intelligence is delivered accurately, securely, and in compliance with organizational access policies.


Kibana Reporting Service Architecture

Kibana Reporting allows users and automated systems to generate high-fidelity, printable PDF documents and PNG images directly from dashboards and visualizations. Understanding the underlying engine is essential for troubleshooting export failures and sizing cluster resources.

+-------------------------------------------------------------+
|               1. Report Triggered                           |
|       (User Click, Scheduled Rule, or API Call)             |
+-------------------------------------------------------------+
                               |
                               v
+-------------------------------------------------------------+
|               2. Job Queued in Elasticsearch                |
|              (Stored in an internal reporting index)        |
+-------------------------------------------------------------+
                               |
                               v
+-------------------------------------------------------------+
|               3. Headless Chromium Worker                   |
|        (Spawns sandbox, authenticates, opens URL)           |
+-------------------------------------------------------------+
                               |
                               v
+-------------------------------------------------------------+
|               4. DOM Rendering & Query Wait                 |
|     (Waits for all Elasticsearch panel queries to resolve)  |
+-------------------------------------------------------------+
                               |
                               v
+-------------------------------------------------------------+
|               5. Document Assembly & Storage                |
|       (Generates vector PDF or PNG snapshot in index)       |
+-------------------------------------------------------------+

The Headless Chromium Rendering Engine

Kibana Reporting relies on an embedded instance of Headless Chromium running directly on the Kibana operating system host. When a report is triggered, Kibana does not simply convert existing client-side HTML to a file; it initiates a completely asynchronous, server-side rendering pipeline:

  1. Job Enqueueing: The user's export request is written as a job document into Kibana's internal reporting index in Elasticsearch.
  2. Browser Worker Spawn: A background worker process on the Kibana server launches a headless Chromium browser instance in a secure sandbox.
  3. Session Handshake: Chromium navigates to a specialized internal Kibana URL representing the dashboard, passing an encrypted authentication token derived from the initiating user's credentials.
  4. Rendering & Query Settlement: Chromium renders the Document Object Model (DOM). It executes all underlying Elasticsearch queries for every panel, monitoring network activity until all visualizations indicate they have finished rendering and data loading has completed.
  5. Document Capture: Once the DOM settles, Chromium captures the canvas. For PDF reports, it generates a multi-page printable vector layout; for PNG reports, it takes an exact pixel snapshot.
  6. Storage and Delivery: The completed binary artifact is written back to the reporting index, where the user can download it via the Kibana UI, or a background connector can transmit it via email or webhook.

Performance Tuning and Troubleshooting

Because headless Chromium consumes substantial CPU and memory, administrators tune reporting settings in kibana.yml:

  • xpack.reporting.queue.timeout: How long each worker has to produce a report (default 4 minutes). If a job runs past this limit it is marked as failed and no download is available. Heavy dashboards over broad time ranges may need a longer value, such as 10 minutes.
  • xpack.screenshotting.capture.timeouts.waitForElements (default 1 minute) and xpack.screenshotting.capture.timeouts.renderComplete (default 2 minutes): How long the headless browser waits for panels to appear and finish rendering. If these are exceeded, Reporting captures what it has and marks the download with a warning.
  • xpack.reporting.csv.maxSizeBytes (default 250 MB): The size at which CSV exports are truncated.

Automated Scheduled Reporting & SOC Handover Workflows

While on-demand exports satisfy ad-hoc requests, operational excellence in the SOC relies on automated, scheduled reporting.

Daily SOC Shift Handover Briefs

At the conclusion of each 8-hour or 12-hour analyst shift, incoming and outgoing shift commanders require an objective summary of operational health:

  • Total alerts triaged versus escalated.
  • Active Severity 1 and Severity 2 incidents still undergoing containment.
  • Sensor health status and ingestion anomalies across perimeter firewalls and endpoint agents.

In 8.x, recurring reports are automated by copying the report's POST URL (from the dashboard's Share → PDF Reports menu) into a Watcher watch or an external scheduler. The scheduler calls the Reporting API on a schedule, for example daily at shift change, and the watch can email the resulting PDF to the SecOps distribution list.

Executive Compliance Documentation

Regulatory mandates (e.g., ISO 27001, PCI-DSS Requirement 10, HIPAA) require verifiable audit trails demonstrating that security telemetry is actively reviewed. Scheduled monthly PDF reports of Executive Posture Dashboards serve as immutable compliance records, stored in long-term archive repositories to satisfy external auditor requirements without granting auditors direct access to production Elasticsearch clusters.


Tabular Telemetry Exporting: Lens and Data Tables to CSV

Security investigations often require extracting raw or aggregated event telemetry for offline statistical analysis, submission to external legal counsel, or ingestion into specialized machine learning tools (e.g., Python pandas or Jupyter notebooks).

Formatted vs. Raw Telemetry Streaming

Kibana allows analysts to export data directly from Lens data tables and classic data tables via two distinct modes:

Export ModeUnderlying MechanismData ContentSize Limit
Download CSV (Lens and table panels)Client-side export of the visualization's table dataThe aggregated rows and values the visualization already holdsOnly the rows loaded for that visualization
Generate CSV report (saved searches from Discover, or saved-search panels)Server-side Reporting job that pages through Elasticsearch resultsField values of the matching documentsTruncated at xpack.reporting.csv.maxSizeBytes (default 250 MB)

Server-Side CSV Streaming Pipeline

For forensic log extractions, analysts should always select Generate CSV via the Reporting service. Unlike browser-side copy actions that crash when handling large datasets, server-side reporting uses Elasticsearch scroll/search-after cursors to stream records asynchronously through the reporting worker, writing the resulting CSV file to disk without exhausting Kibana browser memory.


Saved Object Lifecycle: NDJSON Export and Staging Migrations

In mature enterprise environments, security dashboards and detection rules are not created directly on production clusters. They are engineered, tested, and validated in development and staging environments before promotion to production. Kibana manages this lifecycle through Saved Object Export and Import.

+-------------------------------------------------------------+
|               Development / Staging Space                   |
|     Dashboard Definition + Linked Lens Visualizations       |
+-------------------------------------------------------------+
                               |
                               v  (Export with Dependencies)
+-------------------------------------------------------------+
|               Exported NDJSON File Package                  |
|  Line 1: Dashboard Metadata                                 |
|  Line 2: Lens Visualization A                               |
|  Line 3: Lens Visualization B                               |
|  Line 4: Data View Definition (References Deep)             |
+-------------------------------------------------------------+
                               |
                               v  (CI/CD Pipeline / GitOps)
+-------------------------------------------------------------+
|                 Production Kibana Space                     |
|           (Conflict Resolution & Data View Remap)           |
+-------------------------------------------------------------+

The Newline Delimited JSON (NDJSON) Standard

Kibana serializes saved objects into NDJSON files, where each line represents an independent JSON object containing object attributes, metadata, and relational references:

  • Line 1: The dashboard layout, grid positions, and panel configurations.
  • Line 2–5: The individual Lens visualizations embedded by reference.
  • Line 6: The security data view (logs-*) specifying field formatting and runtime field definitions.

Deep Dependency Resolution (includeReferencesDeep)

When exporting a dashboard, administrators must ensure that Export related objects (includeReferencesDeep: true) is selected. If an analyst exports only the top-level dashboard object without its dependencies, importing the file into a new cluster results in broken "orphan" panels that display errors because the underlying Lens visualizations and data views do not exist.

Handling Conflicts and Data View Remapping During Import

When importing NDJSON files into production:

  1. Object ID Collisions: If an object with the same ID already exists, Kibana prompts the administrator to either overwrite the existing object, create a new object with a generated UUID, or cancel.
  2. Index Pattern / Data View Remapping: In staging, a data view might point to stage-logs-*, while production uses prod-logs-*. Kibana's import wizard detects mismatched data view IDs and allows the administrator to remap visualizations to the appropriate production data view seamlessly.
  3. GitOps Integration: The Kibana Saved Objects API (POST /api/saved_objects/_import) allows SecOps engineers to automate dashboard deployments via CI/CD pipelines (e.g., GitHub Actions or GitLab CI), version-controlling dashboard definitions directly in Git alongside detection rules.

Kibana Spaces: Multi-Tenancy and Operational Segregation

Kibana Spaces provide logical partitioning within a single Kibana instance, sharing the same underlying Elasticsearch cluster while isolating dashboards, visualizations, data views, and security alerts.

SOC Operational Segmentation Models

Enterprise security teams implement Spaces to solve three fundamental operational challenges:

  1. Role-Based Operational Segregation:
    • Tier 1 SOC Space: Configured with live operational triage dashboards, alert queues, and direct links to ticketing systems. Clutter from experimental threat hunting queries is excluded.
    • Threat Hunting Space: Configured with broad data views, experimental ES|QL hunting workbenches, and ad-hoc visualizations.
    • Executive & Compliance Space: Restricted space containing only sanitized CISO dashboards and SLA metric cards, hiding raw operational logs and alert triage noise.
  2. MSSP and Multi-Tenant Segregation:
    • Managed service providers maintain segregated spaces for individual clients (e.g., Space: Client-Alpha, Space: Client-Beta). Each space contains client-branded dashboards and data views bound exclusively to that client's indices (logs-client-alpha-*).
  3. Feature Privilege Lockdown:
    • Administrators can customize feature visibility per space. In an Executive Space, the Security App, Dev Tools, and Stack Management tabs can be completely hidden from the sidebar, presenting users with a streamlined dashboard portal.

Combining Spaces with Elasticsearch Role-Based Access Control (RBAC)

Spaces alone provide visual and organizational isolation; they do not enforce backend data security. True multi-tenancy requires combining Kibana Space Privileges with Elasticsearch Index Privileges:

  • An MSSP client user assigned to Role: client-alpha-user is granted Read-Only access to Space: Client-Alpha within Kibana.
  • Simultaneously, their backend Elasticsearch role restricts index privileges to indices: ["logs-client-alpha-*"].
  • Even if a malicious user attempts to forge a query or hijack an API call, Elasticsearch blocks access to any other tenant's underlying telemetry at the shard level.

External Embedding, Public Wall Displays, and Kiosk Modes

Many enterprise SOCs display operational dashboards on large video walls or embed telemetry views into internal analyst intranets.

iFrame Embedding

Kibana provides an Embed code feature that generates an HTML iframe snippet pointing directly to a dashboard snapshot. However, embedding dashboards securely requires configuring key settings in kibana.yml:

  • xpack.security.sameSiteCookies: Must be configured appropriately (e.g., None with HTTPS) if the parent portal resides on a different domain.
  • csp.frame_ancestors: Kibana sends Content Security Policy (CSP) headers. Administrators must allow the external portal's origin in the frame-ancestors directive (e.g., csp.frame_ancestors: ["'self'", "https://portal.corp.internal"]).

SOC Wall Display / Kiosk Mode

For unmanned video walls, dashboards should be shown in the dashboard's Full screen mode, which hides the top navigation bar and side menus so panels fill the display. When combined with auto-refresh and browser-level tab rotation extensions, video walls can cycle seamlessly between Network Perimeter Health, Endpoint Threat Activity, and Cloud Authentication Dashboards throughout the 24/7 watch.


Export, Sharing, and Governance Reference Table

The following table details the technical mechanisms, underlying engines, RBAC requirements, and operational considerations across Kibana sharing options:

Sharing / Export MethodOutput FormatUnderlying EngineMinimum Required PrivilegesSecOps Operational Use CasePerformance & Sizing Considerations
PDF Executive ReportVector / Raster PDFHeadless Chromium Server WorkerKibana: reporting privilege + space read; ES: read on indicesScheduled weekly CISO briefings and regulatory audit proofHeavy RAM/CPU usage; bound by queue.timeout (default 4m)
PNG Visual SnapshotRaster Image (PNG)Headless Chromium Server WorkerKibana: reporting privilege + space read; ES: read on indicesAutomated Slack/Teams webhook alerts for critical P1 incidentsFast render time; lower memory footprint than multi-page PDFs
CSV Data Export (Server)Delimited Text (CSV)Asynchronous Elasticsearch Scroll/Search-AfterKibana: reporting privilege; ES: read on target indicesExtracting 10,000+ raw telemetry events for offline forensic auditStreams directly to disk; respects csv.maxSizeBytes limits
CSV Data Export (Client)Delimited Text (CSV)Browser DOM JavaScript SerializerKibana: Space Read; ES: read on target indicesQuick export of aggregated summary tables for immediate analysisLimited to records currently rendered in browser DOM
Saved Object NDJSONNewline Delimited JSONKibana Saved Objects Management APIKibana: Stack Management > Saved Objects (Admin)GitOps CI/CD promotions from staging to production clustersExtremely lightweight; requires includeReferencesDeep: true
Kibana Spaces IsolationLogical Workspace PartitionKibana Spaces Architecture & ES RBACKibana: Space Management; ES: Role mappingSegregating Tier 1 SOC operations from CISO views and MSSP clientsPurely logical; requires backend index-level security for data isolation
iFrame Portal EmbeddingEmbedded HTML CanvasBrowser Web Rendering + Kibana CSPKibana: Space Read / Anonymous Access; ES: readEmbedding live alert queues onto SOC intranet portalsRequires csp.frame_ancestors and sameSiteCookies configuration
Test Your Knowledge

A SOC engineer creates an automated scheduled job to generate a 12-page executive PDF report of a complex multi-index security dashboard every Monday morning. However, the report consistently fails with a timeout error indicating that rendering was terminated before completion. Investigation reveals the Elasticsearch cluster was experiencing heavy query load during the scheduled run. Which configuration adjustment in 'kibana.yml' will directly address this issue?

A

Increase 'elasticsearch.shardAllocationFactor' to force faster multi-search aggregations.

B

Set 'xpack.reporting.csv.maxSizeBytes' to 0 to disable size checks during PDF rendering.

C

Set 'xpack.security.sameSiteCookies: Strict' to prevent session termination during page navigation.

D

Increase 'xpack.reporting.queue.timeout' from its 4-minute default to a longer value, such as 10 minutes, so the headless browser has time for every panel query to finish.

Test Your Knowledge

A security engineering team has developed and tested a specialized 'Ransomware Outbreak Triage' dashboard in their staging environment. When migrating this dashboard into the production cluster using the Kibana Saved Objects Management UI, which option must be enabled during export to ensure that the dashboard does not render broken visualization panels upon import?

A

Export related objects (includeReferencesDeep: true) to bundle all referenced Lens visualizations, saved searches, and data views into the NDJSON file.

B

Export as unformatted client-side CSV to preserve table schemas across clusters.

C

Export only the top-level dashboard JSON without dependencies to avoid object ID collisions in production.

D

Convert the dashboard into an encrypted HTML iFrame embed snippet before exporting.

Test Your Knowledge

A Managed Security Service Provider (MSSP) hosts a shared Elastic Stack cluster monitoring 10 different enterprise clients. The MSSP wants each client's security team to have access to their own customized operational dashboards and alert views, while strictly guaranteeing that Client A cannot view, query, or discover telemetry belonging to Client B. Which architecture correctly satisfies both operational and security requirements?

A

Create a single public dashboard with a dynamic drop-down control filtering on 'client.name' and distribute the URL to all clients.

B

Provision separate Kibana Spaces for each client, relying solely on space-level feature controls to prevent unauthorized access across tenants.

C

Implement dedicated Kibana Spaces for each client combined with backend Elasticsearch Role-Based Access Control (RBAC) that restricts index-level read privileges to each client's specific data streams.

D

Deploy 10 independent Kibana physical servers connected to a single unauthenticated Elasticsearch master node.

Sections you finish are checked off in the contents.