# Kibana deletes data view from another data view?

**URL:** https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454
**Category:** Kibana
**Created:** [March 5, 2025, 11:56am UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454 "2025-03-05T11:56:25Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![rara01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rara01/32/141824_2.png) [@rara01](https://discuss.elastic.co/u/rara01)
#### Post date: [March 5, 2025, 11:56am UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/1 "2025-03-05T11:56:25Z")

</div>

Hi,

Yesterday, i deleted one of my newly created test dataviews, where i added two index patterns/datastreams - pd-serilog\* and pd1-service\*. One of them (pd-serilog\*) was named same as data view (which may be the problem). When i checked what i needed, i decided to delete this new test dataview, but what i think i encoutered was bug from which my heart almost dropped. All my rules started to fail, and were showing that they are not able to see data view with some ID. I quickly started to search and try to repair this issue, because it would be big problem for our company. Luckily i saw that pd-serilog\* DATAVIEW was not in discovery tab, so i quickly created that dataview with same ID that error gave me, and luckily, all rules recovered.  
But what i wanted to ask is if this was some kind of bug, or intended behaviour? Beucase pd1-service\* was not deleted, and i'm really sure i did not delete pd-serilog\* dataview.  
Thanks

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [March 5, 2025, 1:03pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/2 "2025-03-05T13:03:07Z")

</div>

Hello and welcome,

Without any evidence of what you had and what was deleted, it is impossible to know if this was a bug.

But from your description it does not seem like.

If you deleted a dataview and them your rules started to fail saying that they weren't able to find the data view, this suggests that your rules were using the deleted data view.

And after recreating the data view with the failing data view ID the rules starting working again confirms that the data view used by the rules was indeed deleted.

---

<div class="post-metadata">

### Author: ![rara01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rara01/32/141824_2.png) [@rara01](https://discuss.elastic.co/u/rara01)
#### Post date: [March 5, 2025, 1:48pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/3 "2025-03-05T13:48:11Z")

</div>

No - i created new, testing data view TEST23. This dataview consisted of two index patterns (pd-serilog\*, pd1-service\*). This dataview was not connected to anything, was meant only for seeing number of documents. I then deleted this testing dataview TEST23. Then Rules started to fail. I found out that independent dataview "pd-serilog\*" was missing in discovery, therefore somehow deleted. I then created this dataview pd-serilog\* again, and rules were working again. I am sure that i did not delete "pd-serilog\*" dataview nor index pattern, only TEST23 data view was deleted.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [March 5, 2025, 1:54pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/4 "2025-03-05T13:54:54Z")

</div>

> [@rara01](#):
>
> I found out that independent dataview "pd-serilog\*" was missing in discovery, therefore somehow deleted. I then created this dataview pd-serilog\* again, and rules were working again. I am sure that i did not delete "pd-serilog\*" dataview nor index pattern, only TEST23 data view was deleted.

Do you have any evidence of this? Can you replicate?

If the rules starting failing and complaing about a missing data view ID, then the rules where using a data view that was deleted, somehow the data view that they used was deleted.

But without evidence of this there is not much else to do.

Can you try to replicate what you did and get evidence?

---

<div class="post-metadata">

### Author: ![rara01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rara01/32/141824_2.png) [@rara01](https://discuss.elastic.co/u/rara01)
#### Post date: [March 6, 2025, 11:13am UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/5 "2025-03-06T11:13:49Z")

</div>

I can try, but how should i get the evidence? Should i record whole session?

---

<div class="post-metadata">

### Author: ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)
#### Post date: [March 6, 2025, 11:34am UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/6 "2025-03-06T11:34:37Z")

</div>

What do you (now) expect to achieve with this thread? I mean, what's your "best case scenario" now?

It's fine to open the thread and ask questions. It's what it's for. You can even vent a little. But the question has IMHO been answered as best the people on this forum _could_ answer, in these circumstances.

My suggestion:

- If you have a support contract, open a support case
- If not, and you want to pursue it, open a bug report - [GitHub · Where software is built](https://github.com/elastic/kibana/issues)

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [March 6, 2025, 1:29pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/7 "2025-03-06T13:29:03Z")

</div>

> [@rara01](#):
>
> I can try, but how should i get the evidence? Should i record whole session?

Get screenshots.

For example, get a screenshot of some rules showing the data view that they are using, then show a screenshots of the data view that you have.

Create the test data view and remove it, get another screenshot that shows that the data view for the rules was also deleted and the rules is failing.

Get the screenshot of the rules failing, things like that.

---

<div class="post-metadata">

### Author: ![rara01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rara01/32/141824_2.png) [@rara01](https://discuss.elastic.co/u/rara01)
#### Post date: [March 6, 2025, 2:50pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/8 "2025-03-06T14:50:22Z")

</div>

Yes, I'm sorry, question is answered, relatively. I still want to find out if this is bug, or some kind of expected behaviour. But i might open bug report. Thank you

---

<div class="post-metadata">

### Author: ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)
#### Post date: [March 6, 2025, 4:04pm UTC](https://discuss.elastic.co/t/kibana-deletes-data-view-from-another-data-view/375454/9 "2025-03-06T16:04:06Z")

</div>

Good luck.

If you don't know already, you can always query the current set of defined dataviews in kibana DevTools via:

GET kbn:/api/data\_views

> **[Get all data views | Kibana API documentation (v8)](https://www.elastic.co/docs/api/doc/kibana/v8/operation/operation-getalldataviewsdefault)**
>
> The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
> The API calls are stateless.
> Each request that you mak...

(I didn't know about the kbn: prefix thing until recently)
