Skip to content

[Security Solution][Bug] Field browser does not distinguish data views with the same index patterns #234464

@christineweng

Description

@christineweng

Describe the bug:
When there are 2 data views of the same index patterns, adding run time fields in one data view does not in field browser

Kibana/Elasticsearch Stack version:
9.2/main

Functional Area (e.g. Endpoint management, timelines, resolver, etc.):
Field browser

Steps to reproduce:
This example has feature flag newDataViewPickerEnabled to have better access to the field editor, but the bug is more related to field browser

  1. Generate some alert and event data
  2. Go to Explore -> Host
  3. Go to data view picker and select security default
  4. Click on data view picker again and select Manage this data view
  5. Copy the index patterns
  6. Open data view picker and click create data view
  7. Paste the index patterns and save it as Security duplicate
  8. Add a run time field in Security duplicate
  9. Go to field browser, notice the new field is not present

Current behavior:
Field browser does not show run time fields properly

Expected behavior:
Field browser should show runtime field of the selected data view

Screenshots (if relevant):

Screen.Recording.2025-09-09.at.9.32.44.AM.mov

Metadata

Metadata

Assignees

No one assigned

    Labels

    Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations TeambugFixes for quality problems that affect the customer experience

    Type

    No fields configured for Bug.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions