# Filter working in "Discover" field, but the same filter in Dashboard/lense does not

**URL:** <https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395>\
**Category:** Kibana\
**Created:** [January 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395 "2023-01-18T09:48:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![JCW](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcw/32/116068_2.png) [@JCW](https://discuss.elastic.co/u/JCW)\
**Post date:** [January 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/1 "2023-01-18T09:48:17Z")

</div>

I'm using a tags - is - snort filter, on the discover tab it shows 5 hits in the last hour.  
I have a visualisation, that used the _same_ index pattern etc, with the same filter and timeframe (tags - is - snort) which does **not** show any hits.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/faf48725e9a4b4065943b8765605312bb6a4f097.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/2/22f143b585763fbd537b764fb81b12b8c495a2e6.png)

Both filters use KQL and the index patterns are the same, there is no other filter by option within the visualization, just the tags: snort filter for the entire dashboard. (Putting it in filter by instead of as a tag does not work either) The "tags" field exists and is parsed (all 3 tags work within discover, just none in the dashboard itself)

Version 8.6

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [January 18, 2023, 10:35am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/2 "2023-01-18T10:35:28Z")

</div>

Hi @JCW

welcome to the Kibana community.

In Dashboard/Lens if you open the Inspect panel and check the request response, do you have any results?

---

<div class="post-metadata">

**Author:** ![JCW](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcw/32/116068_2.png) [@JCW](https://discuss.elastic.co/u/JCW)\
**Post date:** [January 19, 2023, 9:14am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/3 "2023-01-19T09:14:45Z")

</div>

I seem to have 1 request.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/7/17061b207af4081bb8c164b8eaab6d07af4175aa.png)

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [January 19, 2023, 10:17am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/4 "2023-01-19T10:17:59Z")

</div>

What does it say if you click on the `Response` tab?

---

<div class="post-metadata">

**Author:** ![JCW](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcw/32/116068_2.png) [@JCW](https://discuss.elastic.co/u/JCW)\
**Post date:** [January 20, 2023, 8:07am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/5 "2023-01-20T08:07:39Z")

</div>

```auto
{
  "id": "FnNRM0xqd2NwUkFlSEcyamRrLXRrVlEeN0dUQy1KOGFSeHkyN0R2UklDMGJTUTozODgzNTY3",
  "rawResponse": {
    "took": 5,
    "timed_out": false,
    "_shards": {
      "total": 5,
      "successful": 5,
      "skipped": 1,
      "failed": 0
    },
    "hits": {
      "total": 11814,
      "max_score": null,
      "hits": []
    },
    "aggregations": {
      "0": {
        "buckets": [
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T00:00:00.000+01:00",
            "key": 1673564400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T03:00:00.000+01:00",
            "key": 1673575200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T06:00:00.000+01:00",
            "key": 1673586000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T09:00:00.000+01:00",
            "key": 1673596800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T12:00:00.000+01:00",
            "key": 1673607600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T15:00:00.000+01:00",
            "key": 1673618400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T18:00:00.000+01:00",
            "key": 1673629200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-13T21:00:00.000+01:00",
            "key": 1673640000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T00:00:00.000+01:00",
            "key": 1673650800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T03:00:00.000+01:00",
            "key": 1673661600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T06:00:00.000+01:00",
            "key": 1673672400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T09:00:00.000+01:00",
            "key": 1673683200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T12:00:00.000+01:00",
            "key": 1673694000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T15:00:00.000+01:00",
            "key": 1673704800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T18:00:00.000+01:00",
            "key": 1673715600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-14T21:00:00.000+01:00",
            "key": 1673726400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T00:00:00.000+01:00",
            "key": 1673737200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T03:00:00.000+01:00",
            "key": 1673748000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T06:00:00.000+01:00",
            "key": 1673758800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T09:00:00.000+01:00",
            "key": 1673769600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T12:00:00.000+01:00",
            "key": 1673780400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T15:00:00.000+01:00",
            "key": 1673791200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T18:00:00.000+01:00",
            "key": 1673802000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-15T21:00:00.000+01:00",
            "key": 1673812800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T00:00:00.000+01:00",
            "key": 1673823600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T03:00:00.000+01:00",
            "key": 1673834400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T06:00:00.000+01:00",
            "key": 1673845200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T09:00:00.000+01:00",
            "key": 1673856000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T12:00:00.000+01:00",
            "key": 1673866800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T15:00:00.000+01:00",
            "key": 1673877600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T18:00:00.000+01:00",
            "key": 1673888400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-16T21:00:00.000+01:00",
            "key": 1673899200000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T00:00:00.000+01:00",
            "key": 1673910000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T03:00:00.000+01:00",
            "key": 1673920800000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T06:00:00.000+01:00",
            "key": 1673931600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T09:00:00.000+01:00",
            "key": 1673942400000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T12:00:00.000+01:00",
            "key": 1673953200000,
            "doc_count": 6
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T15:00:00.000+01:00",
            "key": 1673964000000,
            "doc_count": 4
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T18:00:00.000+01:00",
            "key": 1673974800000,
            "doc_count": 9
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-17T21:00:00.000+01:00",
            "key": 1673985600000,
            "doc_count": 1
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T00:00:00.000+01:00",
            "key": 1673996400000,
            "doc_count": 11646
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T03:00:00.000+01:00",
            "key": 1674007200000,
            "doc_count": 7
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T06:00:00.000+01:00",
            "key": 1674018000000,
            "doc_count": 8
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T09:00:00.000+01:00",
            "key": 1674028800000,
            "doc_count": 11
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T12:00:00.000+01:00",
            "key": 1674039600000,
            "doc_count": 1
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T15:00:00.000+01:00",
            "key": 1674050400000,
            "doc_count": 2
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T18:00:00.000+01:00",
            "key": 1674061200000,
            "doc_count": 3
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-18T21:00:00.000+01:00",
            "key": 1674072000000,
            "doc_count": 11
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T00:00:00.000+01:00",
            "key": 1674082800000,
            "doc_count": 3
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T03:00:00.000+01:00",
            "key": 1674093600000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T06:00:00.000+01:00",
            "key": 1674104400000,
            "doc_count": 3
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T09:00:00.000+01:00",
            "key": 1674115200000,
            "doc_count": 5
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T12:00:00.000+01:00",
            "key": 1674126000000,
            "doc_count": 63
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T15:00:00.000+01:00",
            "key": 1674136800000,
            "doc_count": 14
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T18:00:00.000+01:00",
            "key": 1674147600000,
            "doc_count": 7
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-19T21:00:00.000+01:00",
            "key": 1674158400000,
            "doc_count": 7
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-20T00:00:00.000+01:00",
            "key": 1674169200000,
            "doc_count": 1
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-20T03:00:00.000+01:00",
            "key": 1674180000000,
            "doc_count": 0
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-20T06:00:00.000+01:00",
            "key": 1674190800000,
            "doc_count": 2
          },
          {
            "1": {
              "doc_count_error_upper_bound": 0,
              "sum_other_doc_count": 0,
              "buckets": []
            },
            "key_as_string": "2023-01-20T09:00:00.000+01:00",
            "key": 1674201600000,
            "doc_count": 0
          }
        ]
      }
    }
  },
  "isPartial": false,
  "isRunning": false,
  "total": 5,
  "loaded": 5,
  "isRestored": false
}

```

---

<div class="post-metadata">

**Author:** ![JCW](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcw/32/116068_2.png) [@JCW](https://discuss.elastic.co/u/JCW)\
**Post date:** [January 25, 2023, 1:59pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/6 "2023-01-25T13:59:15Z")

</div>

bump  
@Marco_Liberati

---

<div class="post-metadata">

**Author:** ![Marco\_Liberati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marco_liberati/32/82953_2.png) [@Marco\_Liberati](https://discuss.elastic.co/u/Marco_Liberati)\
**Post date:** [January 26, 2023, 10:05am UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/7 "2023-01-26T10:05:46Z")

</div>

Can you share the visualization configuration in the Lens editor?

I see the response has some data, so I'm a bit surprised of the panel's result.

---

<div class="post-metadata">

**Author:** ![JCW](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcw/32/116068_2.png) [@JCW](https://discuss.elastic.co/u/JCW)\
**Post date:** [February 17, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/8 "2023-02-17T13:33:46Z")

</div>

the whole issue is that there is data; which shows under _discover_, but when using the /exact/ same filter in the dashboard/lense to visualise only that, it does not show anything.

It's not about the visualization, but the whole filter itself does not work on the dashboards page; while it does work on discover. The lense itself is configured correctly and works with all the regular data it should gain; I have also attempted to just filter by message: "snort" within count of records, this had no success either

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395/9 "2023-03-17T13:33:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
