[Security Solution][Alerts] EQL Sequence "shell" alert is missing kibana.alert.uuid #125885
Labels
Team:Detection Alerts
Security Detection Alerts Area Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.0.1
As a result, subsequent rule runs will attempt to write duplicate alerts. The duplicates won't be created, which is good, but they cause errors to be logged such as
We should populate
kibana.alert.uuid
in the EQL sequence shell alerts the same way we populate the field for EQL sequence building block alerts and alerts from other rule types.This bug also highlights the importance of having a reliable static type system for alerts, which could have caught the missing field easily.
The text was updated successfully, but these errors were encountered: