# Unable to filter on data\_stream.namespace via Log Stream in Dashboard

**URL:** <https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736>\
**Category:** Kibana\
**Created:** [March 3, 2022, 11:55am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736 "2022-03-03T11:55:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh\_G](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Post date:** [March 3, 2022, 11:55am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/1 "2022-03-03T11:55:38Z")

</div>

When selecting Log Stream when creating a Dashboard there are no available data stream or namespace fields to filter on only event.dataset and we'd rather not have to use unique datasets (due to the additional indicies this creates) for each integration in order to filter here.

Please let me know if there is a way to do this or I misunderstanding something.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [March 8, 2022, 11:25am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/2 "2022-03-08T11:25:26Z")

</div>

Sorry, it's not clear to me if you are referring to the Stream interface to review logs in the Observability solution like this screenshot:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d752b773c6c698808d8e4c13df943c83a1e962ff.png)

Or are you talking about a regular Dashboard, or a predefined one set up by a beat maybe?

---

<div class="post-metadata">

**Author:** ![Josh\_G](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Post date:** [March 9, 2022, 10:03am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/3 "2022-03-09T10:03:25Z")

</div>

Hi Jorge,

Thanks for the response. I've actually just realised when trying to obtain some screenshots that it isn't specific to the Log Stream type under Dashboards but missing from the Filters in Dashboards entirely, so apologises for the confusion.

I'm referring to the data\_stream.namespace field filter which is available under Discover and Create Visualisations:

 ![Namspace_filter](https://us1.discourse-cdn.com/elastic/original/3X/0/8/08a49aa4672b3dc137c6634825575a60d1b8b858.png)

But doesn't appear available under Dashboards itself:

 ![Dashboard_filter](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f91d8894faa64128fefa42ee4aaf87523e188c3f.png)

My colleague has created a Dashboard with a Log Stream and is having to use event.dataset to filter it rather than the data\_stream.namespace which would be ideal (imo) as we were considering consolidating some of the dataset names as we don't need separate indices for a lot of them.

I hope this makes sense. I am very new to this so it is very possible I completely misunderstanding how this works so please let me know if so!

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [March 9, 2022, 2:35pm UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/4 "2022-03-09T14:35:56Z")

</div>

For Dashboard to suggest the correct field names you need to add first at least one visualization that refers to the index pattern (or Data View if you are in 8.x). By default it will suggest the fields from your default index pattern. Once the dashboard knows that you are working with a given index pattern you should be able to see it in the search bar suggestions.

Check the following screen recording. When creating the dashboard the default fields are from an index pattern that has nothing to do with `metricbeat`. Once I add a visualization with the count of records from `metricbeat`, the search bar will suggest fields from that index pattern.

![Peek 2022-03-09 15-33](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aaf8e780b004edeb51a130452b3d25350bc30e93.gif)

Hope it helps!

---

<div class="post-metadata">

**Author:** ![Josh\_G](https://avatars.discourse-cdn.com/v4/letter/j/c2a13f/32.png) [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Post date:** [March 10, 2022, 9:11am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/5 "2022-03-10T09:11:49Z")

</div>

Perfect! That's done it.

Thanks a lot for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2022, 9:12am UTC](https://discuss.elastic.co/t/unable-to-filter-on-data-stream-namespace-via-log-stream-in-dashboard/298736/6 "2022-04-07T09:12:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
