Currently the default value for observability:logSources is logs-*-*, logs-*, filebeat-*, kibana_sample_data_logs*.
As it's used as the default data source in Logs explorer and it's possible to carry this value over to ESQL, it's very easy to run into the following case:
While there is a good reason for keeping filebeat as a default value in there (lots of users have data in this set of index patterns), it should be very rare that users actually want to query kibana_sample_data_logs - the inclusion has mostly historical reasons because the synthetic sample data used to be a much more prominent feature in Kibana.
As it's adding to the noise and the risk of breaking actual use cases is extremely small, it should be removed from the default value.
Currently the default value for
observability:logSources
islogs-*-*, logs-*, filebeat-*, kibana_sample_data_logs*
.As it's used as the default data source in Logs explorer and it's possible to carry this value over to ESQL, it's very easy to run into the following case:
While there is a good reason for keeping filebeat as a default value in there (lots of users have data in this set of index patterns), it should be very rare that users actually want to query
kibana_sample_data_logs
- the inclusion has mostly historical reasons because the synthetic sample data used to be a much more prominent feature in Kibana.As it's adding to the noise and the risk of breaking actual use cases is extremely small, it should be removed from the default value.