Observability field composition of Stream Logs message

Hi @b790718,

I agree this doesn't look perfect. What the UI attempts to do here is to interpolate the event.dataset field. This is part of the message reconstruction heuristics, which go astray sometimes.

If you're on a recent version of the Elastic Stack, you might want to try out Discover in a Kibana space configured for Observability: Explore logs in Discover | Elastic Docs

Nowadays Discover adapts its rendering to suit the use-case better when the data viewed are log entries.

1 Like