[Elastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data #18941
Description
Activity
- addedTeam:Elastic-Agent-Data-PlaneAgent Data Plane team [elastic/elastic-agent-data-plane]Agent Data Plane team [elastic/elastic-agent-data-plane]
on May 11, 2026 infra-vault-gh-plugin-prod commented
on May 11, 2026 More actionsPinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)
github-actions commented
on May 11, 2026 on May 11, 2026 – with GitHub ActionsContributorMore actionstl;dr: The strongest evidence points to a package-side filter regression introduced in
#18251: the Overview dashboard now defaults tohost.os.type(existsSelected: true), which can exclude most docs for agents/data wherehost.os.typeis not populated/mapped the wayhost.os.familywas.Recommendation
Treat this as a likely regression from the OS filter migration in
#18251, and patch the Overview dashboard to avoid a hard default onhost.os.typefor entry navigation. The safest fix is to remove the defaultexistsSelectedconstraint on the Platform control and update OS panels to support both legacy and new field/value shapes during transition.Findings
#18251explicitly changed Overview filters fromhost.os.familytohost.os.typeanddarwintomacos.
packages/elastic_agent/changelog.yml:12-16- Commit diff in repo history:
dc20b4c88 packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:32now uses"fieldName": "host.os.type"with"existsSelected": true.
- The Overview dashboard has hard app-state filters that can narrow data significantly.
packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:393-419(platform filters onhost.os.type, valuesmacos/windows)...:586-598(host.os.type: macos)...:762-774(host.os.type: windows)
- Package field definitions across data streams still consistently declare
host.os.familyinagent.yml, while nohost.os.typedeclarations were found in package data stream field files.
- Example:
packages/elastic_agent/data_stream/elastic_agent_metrics/fields/agent.yml:51(- name: os.family) - Same pattern appears broadly under
packages/elastic_agent/data_stream/**/fields/agent.yml.
- Related but secondary: 2.8.0 also changed dashboard navigation links (
#18410), so it is related context but not the strongest direct root-cause signal for this symptom.
packages/elastic_agent/changelog.yml:2-6
Verification
I validated the regression point and current asset state from repo history and package assets:
$ git --no-pager log --oneline -- packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json | head -n 4 e322c1ce1 Correct dashboard links (#18410) dc20b4c88 [elastic_agent] Fix OS type counts in Overview dashboard to use host.os.type (#18251) dcffec345 [elastic_agent] Add 10 remaining input dashboards (#14690) bc923e680 [CI] [Backports] Ensure all expected entries are removed in CODEOWNERS file (#14012) $ git --no-pager show --oneline dc20b4c88 -- packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json @@ -29,7 +29,7 @@ - "fieldName": "host.os.family", + "fieldName": "host.os.type", @@ - "host.os.family": "darwin" + "host.os.type": "macos"
And current file inspection confirms
host.os.type+ default exists behavior in the shipped 2.8.0 asset.Detailed Action Plan
- Update
packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:- Remove default platform hard-filtering (
existsSelected: trueonhost.os.type) so landing via Fleet doesn’t pre-hide data.
- Remove default platform hard-filtering (
- Make OS panel filters backward-compatible:
- Replace strict
host.os.type-only filters with combined logic supporting both old/new shapes (e.g.,host.os.type: macos OR host.os.family: darwin, similar for windows/linux derivation).
- Replace strict
- Keep Fleet navigation behavior unchanged initially; validate by opening the same Fleet “Agent Info Metrics” path and confirming charts populate.
- Add a
changelog.ymlbugfix entry inpackages/elastic_agent/changelog.ymlreferencing this issue. - Backport as needed to supported branches where package versions include
#18251behavior.
Related Items
Type Link Relevance Issue #18941 Current triage target PR #18251 Introduced host.os.family→host.os.typedashboard filter changesPR #18410 2.8.0 navigation-link panel changes (related context) File packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.jsonPrimary dashboard filter logic File packages/elastic_agent/data_stream/elastic_agent_metrics/fields/agent.ymlShows os.familyfield usage in package field declarationsFile packages/elastic_agent/changelog.ymlVersion-level provenance of relevant changes Note
🔒 Integrity filter blocked 4 items
The following items were blocked because they don't meet the GitHub integrity level.
- #11336
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #15278
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #15278
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - [elastic_agent]: Elastic Agent Overview Dashboard #15278
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower
min-integrityin your GitHub frontmatter:tools: github: min-integrity: approved # merged | approved | unapproved | none
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
- addedbugSomething isn't working, use only for issuesSomething isn't working, use only for issues
on May 21, 2026 +1
Apologies, missed this on my inbox. Very likely that #18251 broke it.
Investigating.
- changed the title
[-][IElastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data[/-][+][Elastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data[/+]on May 21, 2026 elastic-vault-github-plugin-prod commented
on May 21, 2026 ContributorMore actionsPackage elastic_agent - 2.9.1 containing this change is available at https://epr.elastic.co/package/elastic_agent/2.9.1/
Integration Name
Elastic Agent [packages/elastic_agent]
Dataset Name
No response
Integration Version
2.8.0
Agent Version
9.5.0
Agent Output Type
elasticsearch
Elasticsearch Version
9.5.0
OS Version and Architecture
MacOS
Software/API Version
No response
Error Message
No response
Event Original
No response
What did you do?
Followed the top level "Agent Info Metrics" link in the agents view in Fleet.
What did you see?
What did you expect to see?
Populated agent graphs, without the filter that removes most data.
Anything else?
No response