Skip to content

[8.19] [Obs AI Assistant] Skip log rate analysis and log categories when no entity filters are present (#290244) - #290484

Merged
kibanamachine merged 3 commits into
elastic:8.19from
kibanamachine:backport/8.19/pr-290244
Sep 13, 2026
Merged

[8.19] [Obs AI Assistant] Skip log rate analysis and log categories when no entity filters are present (#290244)#290484
kibanamachine merged 3 commits into
elastic:8.19from
kibanamachine:backport/8.19/pr-290244

Conversation

@kibanamachine

Copy link
Copy Markdown
Contributor

Backport

This will backport the following commits from main to 8.19:

Questions ?

Please refer to the Backport tool documentation

…entity filters are present (elastic#290244)

Closes Issue: elastic/sdh-kibana#6510

## Summary

Fixes a performance issue where clicking "Help me understand this alert"
on a `custom_threshold` alert that monitors a non-standard metric, one
that produces no `service.name`, `host.name`, `container.id`, or
`kubernetes.pod.name` in the alert document, causes the
`/internal/observability/assistant/alert_details_contextual_insights`
endpoint to hang indefinitely.

### Root cause
`getLogRateAnalysisForAlert` and `getLogCategories` were pushed to the
data-fetcher queue unconditionally, regardless of whether any entity
context was available. When all entity values are `undefined`,
`getShouldMatchOrNotExistFilter` returns an empty array, so the
resulting ES queries carry no entity-scoping filters and fan out across
**all** configured log sources.

### Fix
Added a `hasEntityFilters` flag (true when at least one of
`serviceName`, `hostName`, `containerId`, `kubernetesPodName` is
defined) and wrapped both log data fetchers with `if
(hasEntityFilters)`. When no entity context is present, running these
analyses has no meaningful scope and would scan all log data without
correlation to the triggering alert.

(cherry picked from commit 3843732)
@kibanamachine kibanamachine added the backport This PR is a backport of another PR label Sep 11, 2026
@botelastic botelastic Bot added the Team:obs-presentation Focus: APM UI, Infra UI, Hosts UI, Universal Profiling, Obs Overview and left Navigation label Sep 11, 2026
@kibanamachine
kibanamachine enabled auto-merge (squash) September 11, 2026 09:38
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/obs-presentation-team (Team:obs-presentation)

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown
🤖 Jobs for this PR can be triggered through checkboxes. 🚧

ℹ️ To trigger the CI, please tick the checkbox below 👇

  • Click to trigger kibana-pull-request for this PR!
  • Click to trigger kibana-deploy-project-from-pr for this PR!
  • Click to trigger kibana-deploy-cloud-from-pr for this PR!
  • Click to trigger kibana-entity-store-performance-from-pr for this PR!
  • Click to trigger kibana-storybooks-from-pr for this PR!

@arturoliduena

Copy link
Copy Markdown
Contributor

/ci

@botelastic botelastic Bot added the ci:project-deploy-observability Create an Observability project label Sep 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🤖 GitHub comments

Expand to view the GitHub comments

Just comment with:

  • /oblt-deploy : Deploy a Kibana instance using the Observability test environments.
  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@kibanamachine

Copy link
Copy Markdown
Contributor Author

💚 Build Succeeded

Metrics [docs]

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
kbnUiSharedDeps-srcJs 3.6MB 3.6MB -127.0B

History

cc @arturoliduena

@kibanamachine
kibanamachine merged commit 806a8d4 into elastic:8.19 Sep 13, 2026
59 of 60 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR ci:project-deploy-observability Create an Observability project Team:obs-presentation Focus: APM UI, Infra UI, Hosts UI, Universal Profiling, Obs Overview and left Navigation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants