[Discover] Skip docs with event.kind: alert or signal
in the log document profile heuristics
#196784
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:Discover
Discover Application
impact:high
Addressing this issue will have a high level of impact on the quality/strength of our product.
loe:small
Small Level of Effort
Project:OneDiscover
Enrich Discover with contextual awareness
Team:DataDiscovery
Discover, search (e.g. data plugin and KQL), data views, saved searches. For ES|QL, use Team:ES|QL.
Team:obs-ux-logs
Observability Logs User Experience Team
In the Discover log document profile provider, the heuristics we use categorize all docs with
data_stream.type: log
as log entries. This enables contextual features for these docs such as the log overview tab in the doc viewer flyout. The issue is that for some alerts (event.kind: alert or signal
), all of the source event fields are added to the resulting doc, which may include fields withdata_stream.type: log
. This causes Discover to treat the doc as a log when it should instead be treated as an alert. In order to avoid this issue, we should update the log document profile provider heuristics to ignore docs withevent.kind: alert or signal
.The text was updated successfully, but these errors were encountered: