Skip to content

[9.4] [Obs AI Assistant] Skip log rate analysis and log categories when no entity filters are present (#290244) - #290485

Merged
kibanamachine merged 3 commits into
elastic:9.4from
kibanamachine:backport/9.4/pr-290244
Sep 13, 2026
Merged

[9.4] [Obs AI Assistant] Skip log rate analysis and log categories when no entity filters are present (#290244)#290485
kibanamachine merged 3 commits into
elastic:9.4from
kibanamachine:backport/9.4/pr-290244

Conversation

@kibanamachine

Copy link
Copy Markdown
Contributor

Backport

This will backport the following commits from main to 9.4:

Questions ?

Please refer to the Backport tool documentation

…entity filters are present (elastic#290244)

Closes Issue: elastic/sdh-kibana#6510

## Summary

Fixes a performance issue where clicking "Help me understand this alert"
on a `custom_threshold` alert that monitors a non-standard metric, one
that produces no `service.name`, `host.name`, `container.id`, or
`kubernetes.pod.name` in the alert document, causes the
`/internal/observability/assistant/alert_details_contextual_insights`
endpoint to hang indefinitely.

### Root cause
`getLogRateAnalysisForAlert` and `getLogCategories` were pushed to the
data-fetcher queue unconditionally, regardless of whether any entity
context was available. When all entity values are `undefined`,
`getShouldMatchOrNotExistFilter` returns an empty array, so the
resulting ES queries carry no entity-scoping filters and fan out across
**all** configured log sources.

### Fix
Added a `hasEntityFilters` flag (true when at least one of
`serviceName`, `hostName`, `containerId`, `kubernetesPodName` is
defined) and wrapped both log data fetchers with `if
(hasEntityFilters)`. When no entity context is present, running these
analyses has no meaningful scope and would scan all log data without
correlation to the triggering alert.

(cherry picked from commit 3843732)
@kibanamachine kibanamachine added the backport This PR is a backport of another PR label Sep 11, 2026
@botelastic botelastic Bot added the Team:obs-presentation Focus: APM UI, Infra UI, Hosts UI, Universal Profiling, Obs Overview and left Navigation label Sep 11, 2026
@kibanamachine
kibanamachine enabled auto-merge (squash) September 11, 2026 09:39
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

Pinging @elastic/obs-presentation-team (Team:obs-presentation)

@arturoliduena

Copy link
Copy Markdown
Contributor

/ci

@botelastic botelastic Bot added the ci:project-deploy-observability Create an Observability project label Sep 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🤖 GitHub comments

Expand to view the GitHub comments

Just comment with:

  • /oblt-deploy : Deploy a Kibana instance using the Observability test environments.
  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@kibanamachine

Copy link
Copy Markdown
Contributor Author

💚 Build Succeeded

Metrics [docs]

✅ unchanged

History

cc @arturoliduena

@kibanamachine
kibanamachine merged commit 95e4705 into elastic:9.4 Sep 13, 2026
64 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport This PR is a backport of another PR ci:project-deploy-observability Create an Observability project Team:obs-presentation Focus: APM UI, Infra UI, Hosts UI, Universal Profiling, Obs Overview and left Navigation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants