7.3 Dashboard Exporting, Reporting & Spaces Sharing
Key Takeaways
Kibana Reporting Service utilizes an asynchronous, headless Chromium browser architecture to generate pixel-perfect vector PDF and PNG visual reports from security dashboards.
Recurring reports can be automated by calling a report's POST URL from Watcher or an external scheduler, supporting daily SOC handovers and executive compliance documentation.
Lens and table panels download their aggregated rows as CSV in the browser, while Generate CSV reports from saved searches export matching documents server-side for offline audits.
Kibana Saved Objects (dashboards, data views, visualizations) are exported and imported as Newline Delimited JSON (NDJSON) files with deep dependency resolution, facilitating GitOps migrations.
Kibana Spaces provide multi-tenant organizational isolation and role-based access control (RBAC), enabling security teams to segregate Tier 1 triage, executive governance, and client environments.
Operational Delivery and Governance in Security Operations
A security dashboard's utility extends far beyond real-time browser sessions in the SOC. Security operations must routinely deliver intelligence to diverse stakeholders who do not operate within Kibana on a daily basis: chief information security officers requiring weekly posture summaries, external regulatory auditors demanding compliance evidence, incident response teams requiring raw CSV log extracts for external forensic tooling, and enterprise leadership requiring executive briefs. Furthermore, large enterprises and Managed Security Service Providers (MSSPs) must segregate operational environments across business units or external clients to enforce strict data governance.
Elastic Stack provides enterprise-grade reporting, export, saved object lifecycle management, and workspace partitioning mechanisms. Mastering these capabilities ensures that security intelligence is delivered accurately, securely, and in compliance with organizational access policies.
Kibana Reporting Service Architecture
Kibana Reporting allows users and automated systems to generate high-fidelity, printable PDF documents and PNG images directly from dashboards and visualizations. Understanding the underlying engine is essential for troubleshooting export failures and sizing cluster resources.
+-------------------------------------------------------------+
| 1. Report Triggered |
| (User Click, Scheduled Rule, or API Call) |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| 2. Job Queued in Elasticsearch |
| (Stored in an internal reporting index) |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| 3. Headless Chromium Worker |
| (Spawns sandbox, authenticates, opens URL) |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| 4. DOM Rendering & Query Wait |
| (Waits for all Elasticsearch panel queries to resolve) |
+-------------------------------------------------------------+
|
v
+-------------------------------------------------------------+
| 5. Document Assembly & Storage |
| (Generates vector PDF or PNG snapshot in index) |
+-------------------------------------------------------------+
The Headless Chromium Rendering Engine
Kibana Reporting relies on an embedded instance of Headless Chromium running directly on the Kibana operating system host. When a report is triggered, Kibana does not simply convert existing client-side HTML to a file; it initiates a completely asynchronous, server-side rendering pipeline:
- Job Enqueueing: The user's export request is written as a job document into Kibana's internal reporting index in Elasticsearch.
- Browser Worker Spawn: A background worker process on the Kibana server launches a headless Chromium browser instance in a secure sandbox.
- Session Handshake: Chromium navigates to a specialized internal Kibana URL representing the dashboard, passing an encrypted authentication token derived from the initiating user's credentials.
- Rendering & Query Settlement: Chromium renders the Document Object Model (DOM). It executes all underlying Elasticsearch queries for every panel, monitoring network activity until all visualizations indicate they have finished rendering and data loading has completed.
- Document Capture: Once the DOM settles, Chromium captures the canvas. For PDF reports, it generates a multi-page printable vector layout; for PNG reports, it takes an exact pixel snapshot.
- Storage and Delivery: The completed binary artifact is written back to the reporting index, where the user can download it via the Kibana UI, or a background connector can transmit it via email or webhook.
Performance Tuning and Troubleshooting
Because headless Chromium consumes substantial CPU and memory, administrators tune reporting settings in kibana.yml:
xpack.reporting.queue.timeout: How long each worker has to produce a report (default 4 minutes). If a job runs past this limit it is marked as failed and no download is available. Heavy dashboards over broad time ranges may need a longer value, such as 10 minutes.xpack.screenshotting.capture.timeouts.waitForElements(default 1 minute) andxpack.screenshotting.capture.timeouts.renderComplete(default 2 minutes): How long the headless browser waits for panels to appear and finish rendering. If these are exceeded, Reporting captures what it has and marks the download with a warning.xpack.reporting.csv.maxSizeBytes(default 250 MB): The size at which CSV exports are truncated.
Automated Scheduled Reporting & SOC Handover Workflows
While on-demand exports satisfy ad-hoc requests, operational excellence in the SOC relies on automated, scheduled reporting.
Daily SOC Shift Handover Briefs
At the conclusion of each 8-hour or 12-hour analyst shift, incoming and outgoing shift commanders require an objective summary of operational health:
- Total alerts triaged versus escalated.
- Active Severity 1 and Severity 2 incidents still undergoing containment.
- Sensor health status and ingestion anomalies across perimeter firewalls and endpoint agents.
In 8.x, recurring reports are automated by copying the report's POST URL (from the dashboard's Share → PDF Reports menu) into a Watcher watch or an external scheduler. The scheduler calls the Reporting API on a schedule, for example daily at shift change, and the watch can email the resulting PDF to the SecOps distribution list.
Executive Compliance Documentation
Regulatory mandates (e.g., ISO 27001, PCI-DSS Requirement 10, HIPAA) require verifiable audit trails demonstrating that security telemetry is actively reviewed. Scheduled monthly PDF reports of Executive Posture Dashboards serve as immutable compliance records, stored in long-term archive repositories to satisfy external auditor requirements without granting auditors direct access to production Elasticsearch clusters.
Tabular Telemetry Exporting: Lens and Data Tables to CSV
Security investigations often require extracting raw or aggregated event telemetry for offline statistical analysis, submission to external legal counsel, or ingestion into specialized machine learning tools (e.g., Python pandas or Jupyter notebooks).
Formatted vs. Raw Telemetry Streaming
Kibana allows analysts to export data directly from Lens data tables and classic data tables via two distinct modes:
| Export Mode | Underlying Mechanism | Data Content | Size Limit |
|---|---|---|---|
| Download CSV (Lens and table panels) | Client-side export of the visualization's table data | The aggregated rows and values the visualization already holds | Only the rows loaded for that visualization |
| Generate CSV report (saved searches from Discover, or saved-search panels) | Server-side Reporting job that pages through Elasticsearch results | Field values of the matching documents | Truncated at xpack.reporting.csv.maxSizeBytes (default 250 MB) |
Server-Side CSV Streaming Pipeline
For forensic log extractions, analysts should always select Generate CSV via the Reporting service. Unlike browser-side copy actions that crash when handling large datasets, server-side reporting uses Elasticsearch scroll/search-after cursors to stream records asynchronously through the reporting worker, writing the resulting CSV file to disk without exhausting Kibana browser memory.
Saved Object Lifecycle: NDJSON Export and Staging Migrations
In mature enterprise environments, security dashboards and detection rules are not created directly on production clusters. They are engineered, tested, and validated in development and staging environments before promotion to production. Kibana manages this lifecycle through Saved Object Export and Import.
+-------------------------------------------------------------+
| Development / Staging Space |
| Dashboard Definition + Linked Lens Visualizations |
+-------------------------------------------------------------+
|
v (Export with Dependencies)
+-------------------------------------------------------------+
| Exported NDJSON File Package |
| Line 1: Dashboard Metadata |
| Line 2: Lens Visualization A |
| Line 3: Lens Visualization B |
| Line 4: Data View Definition (References Deep) |
+-------------------------------------------------------------+
|
v (CI/CD Pipeline / GitOps)
+-------------------------------------------------------------+
| Production Kibana Space |
| (Conflict Resolution & Data View Remap) |
+-------------------------------------------------------------+
The Newline Delimited JSON (NDJSON) Standard
Kibana serializes saved objects into NDJSON files, where each line represents an independent JSON object containing object attributes, metadata, and relational references:
- Line 1: The dashboard layout, grid positions, and panel configurations.
- Line 2–5: The individual Lens visualizations embedded by reference.
- Line 6: The security data view (
logs-*) specifying field formatting and runtime field definitions.
Deep Dependency Resolution (includeReferencesDeep)
When exporting a dashboard, administrators must ensure that Export related objects (includeReferencesDeep: true) is selected. If an analyst exports only the top-level dashboard object without its dependencies, importing the file into a new cluster results in broken "orphan" panels that display errors because the underlying Lens visualizations and data views do not exist.
Handling Conflicts and Data View Remapping During Import
When importing NDJSON files into production:
- Object ID Collisions: If an object with the same ID already exists, Kibana prompts the administrator to either overwrite the existing object, create a new object with a generated UUID, or cancel.
- Index Pattern / Data View Remapping: In staging, a data view might point to
stage-logs-*, while production usesprod-logs-*. Kibana's import wizard detects mismatched data view IDs and allows the administrator to remap visualizations to the appropriate production data view seamlessly. - GitOps Integration: The Kibana Saved Objects API (
POST /api/saved_objects/_import) allows SecOps engineers to automate dashboard deployments via CI/CD pipelines (e.g., GitHub Actions or GitLab CI), version-controlling dashboard definitions directly in Git alongside detection rules.
Kibana Spaces: Multi-Tenancy and Operational Segregation
Kibana Spaces provide logical partitioning within a single Kibana instance, sharing the same underlying Elasticsearch cluster while isolating dashboards, visualizations, data views, and security alerts.
SOC Operational Segmentation Models
Enterprise security teams implement Spaces to solve three fundamental operational challenges:
- Role-Based Operational Segregation:
- Tier 1 SOC Space: Configured with live operational triage dashboards, alert queues, and direct links to ticketing systems. Clutter from experimental threat hunting queries is excluded.
- Threat Hunting Space: Configured with broad data views, experimental ES|QL hunting workbenches, and ad-hoc visualizations.
- Executive & Compliance Space: Restricted space containing only sanitized CISO dashboards and SLA metric cards, hiding raw operational logs and alert triage noise.
- MSSP and Multi-Tenant Segregation:
- Managed service providers maintain segregated spaces for individual clients (e.g.,
Space: Client-Alpha,Space: Client-Beta). Each space contains client-branded dashboards and data views bound exclusively to that client's indices (logs-client-alpha-*).
- Managed service providers maintain segregated spaces for individual clients (e.g.,
- Feature Privilege Lockdown:
- Administrators can customize feature visibility per space. In an Executive Space, the Security App, Dev Tools, and Stack Management tabs can be completely hidden from the sidebar, presenting users with a streamlined dashboard portal.
Combining Spaces with Elasticsearch Role-Based Access Control (RBAC)
Spaces alone provide visual and organizational isolation; they do not enforce backend data security. True multi-tenancy requires combining Kibana Space Privileges with Elasticsearch Index Privileges:
- An MSSP client user assigned to
Role: client-alpha-useris granted Read-Only access toSpace: Client-Alphawithin Kibana. - Simultaneously, their backend Elasticsearch role restricts index privileges to
indices: ["logs-client-alpha-*"]. - Even if a malicious user attempts to forge a query or hijack an API call, Elasticsearch blocks access to any other tenant's underlying telemetry at the shard level.
External Embedding, Public Wall Displays, and Kiosk Modes
Many enterprise SOCs display operational dashboards on large video walls or embed telemetry views into internal analyst intranets.
iFrame Embedding
Kibana provides an Embed code feature that generates an HTML iframe snippet pointing directly to a dashboard snapshot. However, embedding dashboards securely requires configuring key settings in kibana.yml:
xpack.security.sameSiteCookies: Must be configured appropriately (e.g.,Nonewith HTTPS) if the parent portal resides on a different domain.csp.frame_ancestors: Kibana sends Content Security Policy (CSP) headers. Administrators must allow the external portal's origin in theframe-ancestorsdirective (e.g.,csp.frame_ancestors: ["'self'", "https://portal.corp.internal"]).
SOC Wall Display / Kiosk Mode
For unmanned video walls, dashboards should be shown in the dashboard's Full screen mode, which hides the top navigation bar and side menus so panels fill the display. When combined with auto-refresh and browser-level tab rotation extensions, video walls can cycle seamlessly between Network Perimeter Health, Endpoint Threat Activity, and Cloud Authentication Dashboards throughout the 24/7 watch.
Export, Sharing, and Governance Reference Table
The following table details the technical mechanisms, underlying engines, RBAC requirements, and operational considerations across Kibana sharing options:
| Sharing / Export Method | Output Format | Underlying Engine | Minimum Required Privileges | SecOps Operational Use Case | Performance & Sizing Considerations |
|---|---|---|---|---|---|
| PDF Executive Report | Vector / Raster PDF | Headless Chromium Server Worker | Kibana: reporting privilege + space read; ES: read on indices | Scheduled weekly CISO briefings and regulatory audit proof | Heavy RAM/CPU usage; bound by queue.timeout (default 4m) |
| PNG Visual Snapshot | Raster Image (PNG) | Headless Chromium Server Worker | Kibana: reporting privilege + space read; ES: read on indices | Automated Slack/Teams webhook alerts for critical P1 incidents | Fast render time; lower memory footprint than multi-page PDFs |
| CSV Data Export (Server) | Delimited Text (CSV) | Asynchronous Elasticsearch Scroll/Search-After | Kibana: reporting privilege; ES: read on target indices | Extracting 10,000+ raw telemetry events for offline forensic audit | Streams directly to disk; respects csv.maxSizeBytes limits |
| CSV Data Export (Client) | Delimited Text (CSV) | Browser DOM JavaScript Serializer | Kibana: Space Read; ES: read on target indices | Quick export of aggregated summary tables for immediate analysis | Limited to records currently rendered in browser DOM |
| Saved Object NDJSON | Newline Delimited JSON | Kibana Saved Objects Management API | Kibana: Stack Management > Saved Objects (Admin) | GitOps CI/CD promotions from staging to production clusters | Extremely lightweight; requires includeReferencesDeep: true |
| Kibana Spaces Isolation | Logical Workspace Partition | Kibana Spaces Architecture & ES RBAC | Kibana: Space Management; ES: Role mapping | Segregating Tier 1 SOC operations from CISO views and MSSP clients | Purely logical; requires backend index-level security for data isolation |
| iFrame Portal Embedding | Embedded HTML Canvas | Browser Web Rendering + Kibana CSP | Kibana: Space Read / Anonymous Access; ES: read | Embedding live alert queues onto SOC intranet portals | Requires csp.frame_ancestors and sameSiteCookies configuration |
A SOC engineer creates an automated scheduled job to generate a 12-page executive PDF report of a complex multi-index security dashboard every Monday morning. However, the report consistently fails with a timeout error indicating that rendering was terminated before completion. Investigation reveals the Elasticsearch cluster was experiencing heavy query load during the scheduled run. Which configuration adjustment in 'kibana.yml' will directly address this issue?
Increase 'elasticsearch.shardAllocationFactor' to force faster multi-search aggregations.
Set 'xpack.reporting.csv.maxSizeBytes' to 0 to disable size checks during PDF rendering.
Set 'xpack.security.sameSiteCookies: Strict' to prevent session termination during page navigation.
Increase 'xpack.reporting.queue.timeout' from its 4-minute default to a longer value, such as 10 minutes, so the headless browser has time for every panel query to finish.
A security engineering team has developed and tested a specialized 'Ransomware Outbreak Triage' dashboard in their staging environment. When migrating this dashboard into the production cluster using the Kibana Saved Objects Management UI, which option must be enabled during export to ensure that the dashboard does not render broken visualization panels upon import?
Export related objects (includeReferencesDeep: true) to bundle all referenced Lens visualizations, saved searches, and data views into the NDJSON file.
Export as unformatted client-side CSV to preserve table schemas across clusters.
Export only the top-level dashboard JSON without dependencies to avoid object ID collisions in production.
Convert the dashboard into an encrypted HTML iFrame embed snippet before exporting.
A Managed Security Service Provider (MSSP) hosts a shared Elastic Stack cluster monitoring 10 different enterprise clients. The MSSP wants each client's security team to have access to their own customized operational dashboards and alert views, while strictly guaranteeing that Client A cannot view, query, or discover telemetry belonging to Client B. Which architecture correctly satisfies both operational and security requirements?
Create a single public dashboard with a dynamic drop-down control filtering on 'client.name' and distribute the URL to all clients.
Provision separate Kibana Spaces for each client, relying solely on space-level feature controls to prevent unauthorized access across tenants.
Implement dedicated Kibana Spaces for each client combined with backend Elasticsearch Role-Based Access Control (RBAC) that restricts index-level read privileges to each client's specific data streams.
Deploy 10 independent Kibana physical servers connected to a single unauthenticated Elasticsearch master node.
Sections you finish are checked off in the contents.