# Log level highlighting in Discover

**URL:** <https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732>\
**Category:** Kibana\
**Tags:** discover\
**Created:** [April 3, 2025, 9:23am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732 "2025-04-03T09:23:32Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 3, 2025, 9:23am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/1 "2025-04-03T09:23:33Z")

</div>

I’d like to start this topic to understand how Kibana automatically highlights `log_level` fields with different background colors.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4cec9ab0d8b998890556c8193fbe2da55da73771.png)

In my case, when I set up Discover, the field in the index is called `log_level`. Kibana 8.16.0 initially applied very attractive background colors to this field automatically. However, at some point, this highlighting disappeared, and I haven’t been able to restore it.

Even after reverting everything to my original setup, the highlighting is no longer applied. I’m aware that you can manually set a color format for a field by defining background and foreground colors for different values, but the result doesn’t look as clean or visually appealing as the default formatting that was there initially.

I hope we can find an answer here so others can also benefit from improved log readability in Kibana.

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 4, 2025, 4:09pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/2 "2025-04-04T16:09:14Z")

</div>

Hi @Matt_Janda and welcome to the community!

We got some feedback that such UI changes are not always relevant to the displayed data set. Because of this the mentioned improvements are now scoped per solution type.

In the more recent versions there is a popover explaining how to enable more context-aware features:

 ![Screenshot 2025-04-04 at 18.02.14](https://us1.discourse-cdn.com/elastic/original/3X/6/8/681728d4b3c5a7552f37325acfb5c643ea220b13.png)

So to get logs related improvements for Discover, choose "Observability" in Space settings:

 ![Screenshot 2025-04-04 at 18.02.45](https://us1.discourse-cdn.com/elastic/original/3X/b/a/baa40fe159af18238a29315941b85f15b925c75d.jpeg)

Hope it helps! Thanks for your feedback!

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 4, 2025, 5:08pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/3 "2025-04-04T17:08:11Z")

</div>

> [@jughosta](#):
>
> ovements for Discover, choose "Observability" in S

Thank you for your reply. I did and do have it enabled, hence the confusion on my side. Under observability I can see "Logs"... and other. All of them are selected. Do I have to anything else ?

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 4, 2025, 6:09pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/4 "2025-04-04T18:09:51Z")

</div>

Okay! Let's find out what is missing.

What is your current version of Kibana?  
Did they disappear after an upgrade to a newer Kibana version or you stayed on the same version?  
Did they disappear on both Dashboard and Discover pages?

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 5, 2025, 12:11pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/5 "2025-04-05T12:11:10Z")

</div>

Now, I am running Kibana and Elasticsearch 8.17.4 from docker containers. I have recreated containers and volumes i.e. start everything from scratch. I have created How they disappeared is the mystery part. I have been using 8.16.0, when they disappeared without any upgrade. Yes, the highlight is not present in both, Discover and Lense created from discover. I tried again from scratch, creating the Data View like I did it the first time.

Note, that I have not never seen the "pop up" you mentioned about the Observability.  
The Observability is selected for all the sub options.

Here is my log index mapping:

```auto
{
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "app_campus": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "app_env": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "app_name": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "app_version": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "elapsed_time": {
        "type": "float"
      },
      "event_name": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "extended_properties": {
        "properties": {
          "Aurora": {
            "properties": {
              "Eca": {
                "properties": {
                  "ContentRoot": {
                    "type": "text",
                    "fields": {
                      "keyword": {
                        "type": "keyword",
                        "ignore_above": 256
                      }
                    }
                  },
                  "EnvName": {
                    "type": "text",
                    "fields": {
                      "keyword": {
                        "type": "keyword",
                        "ignore_above": 256
                      }
                    }
                  },
                  "Index": {
                    "properties": {
                      "ContentRoot": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "EnvName": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "Topic": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "address": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "eventName": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "topic": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      }
                    }
                  },
                  "KeyId": {
                    "type": "text",
                    "fields": {
                      "keyword": {
                        "type": "keyword",
                        "ignore_above": 256
                      }
                    }
                  },
                  "address": {
                    "type": "text",
                    "fields": {
                      "keyword": {
                        "type": "keyword",
                        "ignore_above": 256
                      }
                    }
                  },
                  "path": {
                    "type": "text",
                    "fields": {
                      "keyword": {
                        "type": "keyword",
                        "ignore_above": 256
                      }
                    }
                  }
                }
              },
              "Eci": {
                "properties": {
                  "Search": {
                    "properties": {
                      "ClientName": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "ContentRoot": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "DisposedCount": {
                        "type": "long"
                      },
                      "ElapsedMilliseconds": {
                        "type": "float"
                      },
                      "EnvName": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "HandlerLifetime": {
                        "type": "float"
                      },
                      "InitialCount": {
                        "type": "long"
                      },
                      "RemainingItems": {
                        "type": "long"
                      },
                      "address": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "eventName": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      },
                      "topic": {
                        "type": "text",
                        "fields": {
                          "keyword": {
                            "type": "keyword",
                            "ignore_above": 256
                          }
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }
      },
      "host": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "instance_id": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "log_level": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "message": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 7, 2025, 8:34am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/6 "2025-04-07T08:34:56Z")

</div>

Hi @Matt_Janda,

Can you please try adding `xpack.spaces.experimental.forceSolutionVisibility: true` to your `kibana.yml` and then create a new Space with Solution View "Observability"?

You can share your existing data views with this new space on Saved Objects page.

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 9, 2025, 3:02am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/7 "2025-04-09T03:02:53Z")

</div>

> [@jughosta](#):
>
> then create a new Space with Solution View "Observability"?

Will do it shortly. Quick question, I am passing all the parameters as environment variables in my compose file. How do I do this one ?

My kibana.yml inside the container is generated automatically:

```auto
#
# **THIS IS AN AUTO-GENERATED FILE**
#

# Default Kibana configuration for docker target
server.host: "0.0.0.0"
server.shutdownTimeout: "5s"
elasticsearch.hosts: ["http://elasticsearch:9200"]
monitoring.ui.container.elasticsearch.enabled: true

```

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 9, 2025, 6:31pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/8 "2025-04-09T18:31:42Z")

</div>

Hi Julia,

I've followed your hints, created new space and selected "Observability" as the solution view.

I create a view and went to discover. No luck, am afraid. I like the new solution view, yet it does not highlight the log levels.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ad197fc30e7bf6b4f893485652b1165e5678b24e.png)

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 11, 2025, 3:30pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/9 "2025-04-11T15:30:41Z")

</div>

What index pattern is configured for `central-logging` data view?

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 12, 2025, 11:57am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/10 "2025-04-12T11:57:42Z")

</div>

I will check but that might be the answer 🙂

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 12, 2025, 2:47pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/11 "2025-04-12T14:47:02Z")

</div>

> [@jughosta](#):
>
> We got some feedback that such UI changes are not always relevant to the displayed data set. Because of this the mentioned improvements are now scoped per solution type.

I'm curious on where we can provide this kind of feedback, we recently moved to Elastic Cloud and per default it uses Solution View, we tried to use it for a couple of weeks but the experience was making simple actions take a lot more time and clicks to be done so we reverted back to classic view.

Biggest issues were related to the management side of things, like Index Management, Data View, Dashboards, Visualizations etc.

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 13, 2025, 7:26pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/12 "2025-04-13T19:26:29Z")

</div>

Yes, it is called `central-logging` now. I was hoping that a "keyword" `logs` would have anything to do with the highlighting as when I started building the dashboard my index and data view was called `eca-logs`. I tried to revert it back, but no pretty highlighting . ☹

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 13, 2025, 7:28pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/13 "2025-04-13T19:28:02Z")

</div>

I know about the format setting where you can configure the colors, but it is not as pretty as the one I saw.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/5/850cf8435d2d9ec7fa10941a38f4cf50493935b1.png)

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 14, 2025, 8:16am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/14 "2025-04-14T08:16:37Z")

</div>

Hi @leandrojmp,

Thanks for your feedback! I passed it over to the team.

In general feedback regarding the navigation can be provided here per solution type:

- Search Navigation [Qualtrics Survey | Qualtrics Experience Management](https://ela.st/search-nav-feedback)
- Observability Navigation [Qualtrics Survey | Qualtrics Experience Management](https://ela.st/o11y-nav-feedback)
- Security Navigation [Qualtrics Survey | Qualtrics Experience Management](https://ela.st/security-nav-feedback)

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [April 14, 2025, 8:18am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/15 "2025-04-14T08:18:28Z")

</div>

The data view name should not make a difference but the index pattern might. Can you please open your data view in edit mode (on Stack Management \> Data View page for example) and check what index pattern is entered there?

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 14, 2025, 8:35am UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/16 "2025-04-14T08:35:09Z")

</div>

I think I was a bit lucky. 🍀 When I was demoing first version of the services, I left it running on original release. I will send you all the details. Here is what I learned so far:

1. I was running on Kibana 8.16.0 and the highlight works like a charm.
2. I only changed Kibana to 8.17.4 and the highlights are gone. I probably used NDJSON generated by 8.16.0
3. Going back to 8.16.0 and recreating containers and volumes, and the log level highlighting is back.

I will try to investigate further, see if running my latest version on 8.16.0 will work.

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![Matt\_Janda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_janda/32/140341_2.png) [@Matt\_Janda](https://discuss.elastic.co/u/Matt_Janda)\
**Post date:** [April 14, 2025, 5:42pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/18 "2025-04-14T17:42:58Z")

</div>

Hi Julia,

I have finally found this "easter egg" feature. I am calling it since it feels like one. Here are the conditions:

1. **Works only in Kibana 8.16.x.** I have tried 8.17.x with no luck. I did not try earlier versions.

2. The **Data View pattern MUST**  **contain the "log"** keyword. In my case it is `central_log*`. If I use `central_logging` the log level does not get highlighted.

The only wish would be to continue this feature. Right now for presentation value I'll stick to Kibana 8.16.6.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d23059de43323cf29acf56322ed0a9469e4761b.png)

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [April 21, 2025, 2:22pm UTC](https://discuss.elastic.co/t/log-level-highlighting-in-discover/376732/19 "2025-04-21T14:22:17Z")

</div>

Same here, were on 8.16. 0 and users loved the new colouring of log.level, Just upgraded to 8.18.0 and highlighting of our log.level fields seems gone even though my data views as well as the index pattern names are ended on the word: logs like these:

 ![Screenshot 2025-04-21 at 16.16.46](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e57e25a77923295576ce27aa1c13f39f866e84e9.png)

Any way to bring them back without changing to Observability Solution View mode?
