# Kibana - API key search results broken

**URL:** <https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128>\
**Category:** Kibana\
**Created:** [December 16, 2025, 4:27pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128 "2025-12-16T16:27:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave\_Houser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dave_houser/32/72517_2.png) [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Post date:** [December 16, 2025, 4:27pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/1 "2025-12-16T16:27:55Z")

</div>

In Kibana go to Stack management \> Security \> API keys.  
Type into search some letters or a word for an API key name.  
Nothing is returned, even if the API key names include letters or words you typed.  
If you type the whole name of the apikey exactly then that API key is filtered.

This was not the same behavior in 8.13. We could type any word or letter in an API key, and the results would be filtered down to results that included the word. The search seems pointless if we have to type the apikey name exactly.

Note if I go to any other search bar in Kibana this problem does not happen. For instance Stack management \> Security \> Roles, I am able to filter just fine. The above problem does not happen. In fact, it seems its only the Api keys.

Is this expected? Is there a patch that fixes this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2025, 4:31pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/2 "2025-12-16T16:31:43Z")

</div>

@Dave_Houser Uhhh What version do you see this? 🙂

---

<div class="post-metadata">

**Author:** ![Dave\_Houser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dave_houser/32/72517_2.png) [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Post date:** [December 16, 2025, 4:36pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/3 "2025-12-16T16:36:26Z")

</div>

8.18.0 and 8.18.6

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2025, 4:37pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/4 "2025-12-16T16:37:29Z")

</div>

I am sure it is a bug 8.19.7 Works

 ![Screenshot 2025-12-16 at 8.37.06 AM](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11bbcaac87121d545e452298ddded9614377d180.png)

You don't have the filter on right?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 16, 2025, 4:38pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/5 "2025-12-16T16:38:25Z")

</div>

I'm on 8.19.2 and have a similar behavior.

I need to use a wildcard.

For example, if I have an API Key named _Secops Automation API_ and type _Secops_ only, nothing will be returned, but if I use _Secops\*_, then it will show up.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2025, 4:40pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/6 "2025-12-16T16:40:02Z")

</div>

So that narrows it down... fix is somewhere between 8.19.3 and 8.19.7

Asssuming what you see @leandrojmp on my screen shot solves the issue I don't have spaces in mine I could try that but you see it finding `otel` in the middle of names

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 16, 2025, 4:41pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/7 "2025-12-16T16:41:22Z")

</div>

Spaces / Case Insensitive seems to work

 ![Screenshot 2025-12-16 at 8.40.50 AM](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8ba284d53ca69d26c24447a52ce2e3d2afa992c5.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [December 16, 2025, 4:43pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/8 "2025-12-16T16:43:58Z")

</div>

> [@stephenb](#):
>
> So that narrows it down... fix is somewhere between 8.19.3 and 8.19.7

I think it was added here: [Adding API Key Wildcard Search by Eamonn-OL · Pull Request #221959 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/221959)

On versions: 8.18.8, 8.19.5, 9.0.8, 9.1.6, 9.2.0

---

<div class="post-metadata">

**Author:** ![Dave\_Houser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dave_houser/32/72517_2.png) [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Post date:** [December 16, 2025, 6:27pm UTC](https://discuss.elastic.co/t/kibana-api-key-search-results-broken/384128/9 "2025-12-16T18:27:35Z")

</div>

I upgraded to 8.19.5, the problem is gone and it works as 8.13 worked.  
Thanks everyone for the recommendations.
