Skip to content

[Elastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data #18941

Description

@cmacknz

Integration Name

Elastic Agent [packages/elastic_agent]

Dataset Name

No response

Integration Version

2.8.0

Agent Version

9.5.0

Agent Output Type

elasticsearch

Elasticsearch Version

9.5.0

OS Version and Architecture

MacOS

Software/API Version

No response

Error Message

No response

Event Original

No response

What did you do?

Followed the top level "Agent Info Metrics" link in the agents view in Fleet.

What did you see?

Image

What did you expect to see?

Populated agent graphs, without the filter that removes most data.

Anything else?

No response

Activity

  1. infra-vault-gh-plugin-prod commented on May 11, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

  2. cmacknz commented on May 11, 2026

    @cmacknz
    MemberAuthor

    Suspicion is that #18251 broke this accidentally FYI @mauri870 since you were the author of that PR.

  3. github-actions commented on May 11, 2026

    @github-actions
    Contributor

    tl;dr: The strongest evidence points to a package-side filter regression introduced in #18251: the Overview dashboard now defaults to host.os.type (existsSelected: true), which can exclude most docs for agents/data where host.os.type is not populated/mapped the way host.os.family was.

    Recommendation

    Treat this as a likely regression from the OS filter migration in #18251, and patch the Overview dashboard to avoid a hard default on host.os.type for entry navigation. The safest fix is to remove the default existsSelected constraint on the Platform control and update OS panels to support both legacy and new field/value shapes during transition.

    Findings
    1. #18251 explicitly changed Overview filters from host.os.family to host.os.type and darwin to macos.
    • packages/elastic_agent/changelog.yml:12-16
    • Commit diff in repo history: dc20b4c88
    • packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:32 now uses "fieldName": "host.os.type" with "existsSelected": true.
    1. The Overview dashboard has hard app-state filters that can narrow data significantly.
    • packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:393-419 (platform filters on host.os.type, values macos/windows)
    • ...:586-598 (host.os.type: macos)
    • ...:762-774 (host.os.type: windows)
    1. Package field definitions across data streams still consistently declare host.os.family in agent.yml, while no host.os.type declarations were found in package data stream field files.
    • Example: packages/elastic_agent/data_stream/elastic_agent_metrics/fields/agent.yml:51 (- name: os.family)
    • Same pattern appears broadly under packages/elastic_agent/data_stream/**/fields/agent.yml.
    1. Related but secondary: 2.8.0 also changed dashboard navigation links (#18410), so it is related context but not the strongest direct root-cause signal for this symptom.
    • packages/elastic_agent/changelog.yml:2-6
    Verification

    I validated the regression point and current asset state from repo history and package assets:

    $ git --no-pager log --oneline -- packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json | head -n 4
    e322c1ce1 Correct dashboard links (#18410)
    dc20b4c88 [elastic_agent] Fix OS type counts in Overview dashboard to use host.os.type (#18251)
    dcffec345 [elastic_agent] Add 10 remaining input dashboards (#14690)
    bc923e680 [CI] [Backports] Ensure all expected entries are removed in CODEOWNERS file (#14012)
    
    $ git --no-pager show --oneline dc20b4c88 -- packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json
    @@ -29,7 +29,7 @@
    - "fieldName": "host.os.family",
    + "fieldName": "host.os.type",
    @@
    - "host.os.family": "darwin"
    + "host.os.type": "macos"

    And current file inspection confirms host.os.type + default exists behavior in the shipped 2.8.0 asset.

    Detailed Action Plan
    1. Update packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json:
      • Remove default platform hard-filtering (existsSelected: true on host.os.type) so landing via Fleet doesn’t pre-hide data.
    2. Make OS panel filters backward-compatible:
      • Replace strict host.os.type-only filters with combined logic supporting both old/new shapes (e.g., host.os.type: macos OR host.os.family: darwin, similar for windows/linux derivation).
    3. Keep Fleet navigation behavior unchanged initially; validate by opening the same Fleet “Agent Info Metrics” path and confirming charts populate.
    4. Add a changelog.yml bugfix entry in packages/elastic_agent/changelog.yml referencing this issue.
    5. Backport as needed to supported branches where package versions include #18251 behavior.
    Related Items
    Type Link Relevance
    Issue #18941 Current triage target
    PR #18251 Introduced host.os.family → host.os.type dashboard filter changes
    PR #18410 2.8.0 navigation-link panel changes (related context)
    File packages/elastic_agent/kibana/dashboard/elastic_agent-a148dc70-6b3c-11ed-98de-67bdecd21824.json Primary dashboard filter logic
    File packages/elastic_agent/data_stream/elastic_agent_metrics/fields/agent.yml Shows os.family field usage in package field declarations
    File packages/elastic_agent/changelog.yml Version-level provenance of relevant changes

    Note

    🔒 Integrity filter blocked 4 items

    The following items were blocked because they don't meet the GitHub integrity level.

    • #11336 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #15278 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #15278 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • [elastic_agent]: Elastic Agent Overview Dashboard #15278 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

  4. added
    bugSomething isn't working, use only for issues
    on May 21, 2026
  5. Danouchka commented on May 21, 2026

    @Danouchka

    +1

  6. self-assigned this
    on May 21, 2026
  7. mauri870 commented on May 21, 2026

    @mauri870
    Member

    Apologies, missed this on my inbox. Very likely that #18251 broke it.

    Investigating.

  8. changed the title [-][IElastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data[/-] [+][Elastic Agent]: Navigation from the "Agent Info Metrics" link in Fleet applies filter that hides data[/+] on May 21, 2026
  9. elastic-vault-github-plugin-prod commented on May 21, 2026

    @elastic-vault-github-plugin-prod
    Contributor

    Package elastic_agent - 2.9.1 containing this change is available at https://epr.elastic.co/package/elastic_agent/2.9.1/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions