-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] dns question name
field for DNS events are not displayed under highlighted fields section of alert flyout
#125491
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
We will soon fix this with #124941 |
Hi @MadameSheema , We have observed that this issue is also occurring after upgrade the build to 8.1.0. Build Details:
Thanks! |
This has been fixed and will be part of the next BC |
Hi @janmonschke , We have validated this issue on 8.1.0 BC3 build. and found that issue is still occurring. Looks like 8.1.0 backport PR is not merged. Build Details:
Thanks!! |
Thanks, I did not see that the backport failed |
The PR has been merged now |
Pinging @elastic/security-threat-hunting (Team:Threat Hunting) |
We have validated this issue on 8.1.0 BC4 and observed that issue is Still Occurring. 🔴 Please find below the testing details: Build Details:
Screenshot: Thanks !! |
Maybe the change wasn't included in the newest BC |
@janmonschke if these are the expected changes: 81f308c Then your changes were included on the BC: https://github.com/elastic/kibana/commits/015578b81c26a5843747ba53b2fd92d40f0453cb Can you please take a look? Thanks :) |
@deepikakeshav-qasource Could you provide the JSON of the alert please? Also, is this scenario testing the upgrade or new alerts? |
Hi @janmonschke ,
@janmonschke just new alerts and if you want we can check the upgrade scenario too Please find the below Alert JSON for DNS alerts. Please let us know if anything else is required from our end!! Thanks!! |
Hi @janmonschke , Additionally as there are multiple observations and all are different from each other so to keep things clear please find below matrix with current issue state
Thanks!! |
@deepikakeshav-qasource can you please check if this is still happening on the latest 8.1.0BC? Thanks :) |
We have validated this issue on 8.1.0 BC5 On-Prem and observed that issue is still occurring 🔴 Please find below the testing details: Alert Json Build Details:
Thanks !! |
@deepikakeshav-qasource can you please validate this on 8.1.0BC6? Thanks! |
We have validated this issue on 8.1.0 BC6 and Observed that issue is Fixed 🟢 Please find below the testing details: Build Details:
Hence, We closing this issue and marking as QA Validated. Thanks !! |
Describe the bug
dns question name
field for DNS events are not displayed under highlighted fields section of alert flyoutBuild Details:
Browser Details:
N/A
Preconditions
Steps to Reproduce
Actual Result
dns question name field for DNS events are not displayed under highlighted fields section of alert flyout
Expected Result
dns question name field for DNS events should be displayed under highlighted fields section of alert flyout
What's Working
What's Not Working
Screen-Shot
DNS Events rule
Dns rule.zip
DNS alert Json
dns events.txt
The text was updated successfully, but these errors were encountered: