-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] Fields for Indicator alerts are not displayed under highlighted fields section of alert flyout #125473
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
Thanks @deepikakeshav-qasource!! :) Can you please attach the json of the alert and the json of the rule? moreover, which version of filebeat you were using to generate the alert? |
Sorry for the confusion @MadameSheema , Please find the attached json of Rule and alert Rule Alerts Json We are using filebeat 8.1.0 Thanks!! |
Hi @MadameSheema , We have observed that fields are displaying for indicator alert but with wrong fields under highlighted section after upgrade the build to 8.1.0. Build Details:
Alert Json Thanks! |
This just merged and should be part of the next BC |
Pinging @elastic/security-threat-hunting (Team:Threat Hunting) |
We have validated this issue on 8.1.0 BC4 and observed that issue is Still Occurring. 🔴 Please find below the testing details: Build Details:
Screenshot: Thanks !! |
@janmonschke can you please take a look at this? Thanks! |
@deepikakeshav-qasource Could you provide the JSON of the alert please? And could you confirm that this issue only occurs after an upgrade to 8.x? |
Hi @janmonschke ,
@janmonschke This is occurring only for new alerts. fields are displaying for indicator alerts after upgrade to 8.x #125473 (comment) Please find the below Alert JSON for Indicator alerts. Please let us know if anything else is required from our end!! Thanks!! |
@deepikakeshav-qasource can you please check if this is still happening on the latest 8.1.0BC? Thanks :) |
We have validated this issue on 8.1.0 BC5 On-Prem and observed that issue is still occurring 🔴 Please find below the testing details: Build Details:
Thanks !! |
Hey @deepikakeshav-qasource, could you share the alert's JSON here? Has this alert been migrated to 8.x? |
Hi @janmonschke , Please find the below alert JSON:
No, This is the fresh build 8.1.0 BC5 Please let us know if anything else is required from end!! Thanks!! |
@deepikakeshav-qasource can you please validate this on 8.1.0BC6? Thanks! |
We have validated this issue on 8.1.0 BC6 On-Prem and Observed that issue is Fixed 🟢 Please find below the testing details: Build Details:
Query : Field name Moreover, We will validate the upgrade scenario once the cloud build is available. Also, We have seen that the fields under highlighted fields for Indicator rule are not correctly formatted. We have open the issue for same here. Thanks !! |
@deepikakeshav-qasource yes, those are the correct names. Thanks for testing this again! |
We have validated this issue on 8.1.0 BC6 with Upgrade scenario and Observed that issue is Fixed 🟢 Please find below the testing details: Build Details:
Thanks!! |
Describe the bug
Fields for Indicator alerts are not displayed under highlighted fields section of alert flyout
Build Details:
Browser Details:
N/A
Preconditions
Steps to Reproduce
Actual Result
Fields for Indicator alerts are not displayed under highlighted fields section of alert flyout
Expected Result
indicator index pattern
andindicator index query
fields should be displayed under highlighted fields sectionWhat's Working
What's Not Working
Screen-Shot
The text was updated successfully, but these errors were encountered: