# Remove or Hide Kibana and Signal fields in Elastic Security

**URL:** <https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804>\
**Category:** Endpoint Security\
**Created:** [January 19, 2022, 11:37am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804 "2022-01-19T11:37:58Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [January 19, 2022, 11:37am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/1 "2022-01-19T11:37:58Z")

</div>

**Version** : 7.16.3

Hi, everyone

I would like to know whether it is possible to remove or hide **Kibana and Signal fields** in **Elastic Security**. When an alert is triggered, you can look over it, here you are a screenshot:

 ![elastic-security](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6dd2e9f6ead0542d61f28e06adc33130bbabcb76.png)

I understand that this information is **useful** , however, in the case of being **agile** , from my point of view, having many fields you can’t see the wood for the trees 🌲 .

Thanks in advance 🖖 ,

Rodrigo

---

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [January 21, 2022, 8:40am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/3 "2022-01-21T08:40:55Z")

</div>

Hi Rodrigo,

Have you already experimented with **Timeline Templates**? I've found that creating a **Timeline Template** with the desired set of fields and using that in a rule populates the _Overview_ tab option with the key context I'm looking for. I see it as a workaround to your request, but was wondering what your experience might be.

Kind Regards,

Matt

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [January 24, 2022, 7:32am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/4 "2022-01-24T07:32:10Z")

</div>

Hi, @elkn00b

I have created a **template** in order to set a **generic fields** :

 ![templates](https://us1.discourse-cdn.com/elastic/original/3X/8/3/8367e16e83076692dfbd9b41ad46a0929785a6b7.png)

Then, I have modified **rule** in order to use that **template** :

 ![suricata-rule](https://us1.discourse-cdn.com/elastic/original/3X/8/0/8096eff266d7d6bfd4c94d188177cc935c7ba310.png)

However, when **alert** is **triggered** , it does not show **template fields** :

 ![suricata-overview](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a3ecee204aac91988903fb53f51cbebc8ebbe1e2.png)

Thanks in advance,

Regards

---

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [January 25, 2022, 10:48am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/5 "2022-01-25T10:48:29Z")

</div>

Hi Rodrigo,

I checked my timeline template to see what I might be doing differently, and I don't have any template fields defined for the filter criteria. The fields I toggle in the table below for column visibility seem to be the fields that show up in the Overview table.

I suggest removing the timeline template fields from the search criteria, but ensuring the target fields are toggled into the column view below, and then re-testing.

Kind Regards,

Matt

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [January 25, 2022, 11:08am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/6 "2022-01-25T11:08:31Z")

</div>

Hi, @elkn00b

Here you are a new screenshot about modified timeline:

 ![suricata-new-template](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a7379710d1ee0c5b61aa47006f25b1872acfdbcd.png)

Thanks in advance,

Regards

---

<div class="post-metadata">

**Author:** ![elkn00b](https://avatars.discourse-cdn.com/v4/letter/e/b9bd4f/32.png) [@elkn00b](https://discuss.elastic.co/u/elkn00b)\
**Post date:** [January 26, 2022, 9:23am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/7 "2022-01-26T09:23:11Z")

</div>

Hi Rodrigo,

That's what I've got. Does it populate your Overview tab in the SIEM alerts results when tested?

Kind Regards,

Matt

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [January 26, 2022, 11:47am UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/8 "2022-01-26T11:47:46Z")

</div>

Hi, @elkn00b

It does not populate Overview tab ☹ .

Thanks for your support 😃.

Regards

---

<div class="post-metadata">

**Author:** ![Michael\_Olorunnisola](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_olorunnisola/32/88980_2.png) [@Michael\_Olorunnisola](https://discuss.elastic.co/u/Michael_Olorunnisola)\
**Post date:** [January 26, 2022, 5:53pm UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/9 "2022-01-26T17:53:55Z")

</div>

Hi @RdrgPorto - Thanks for reaching out here, and thank you @elknoob for working with him to debug. Currently, there isn't actually a direct relationship between the document summary of the fly-out and the template fields. The fields shown in the document summary are based on some fields on the underlying event such as `event.category`. The fact that there's a match for @elknoob is coincidental. I'll make a note of this feedback!

For now, one thing you can do is create a timeline template and configure the default columns there.

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [January 26, 2022, 6:44pm UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/10 "2022-01-26T18:44:45Z")

</div>

Hi, @Michael_Olorunnisola

Thanks for your answer 😃 .

Have a nice week,

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2022, 6:45pm UTC](https://discuss.elastic.co/t/remove-or-hide-kibana-and-signal-fields-in-elastic-security/294804/11 "2022-02-23T18:45:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
