[Security Solution] The agent.status
highlighted field should not have an Alert prevalence action
#132652
Labels
bug
Fixes for quality problems that affect the customer experience
duplicate
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Team:Threat Hunting:Investigations
Security Solution Investigations Team
[Security Solution] The
agent.status
highlighted field should not have an Alert prevalence actionThe
agent.status
highlighted field should not have an Alert prevalence action, because it's not possible to filter alerts viaagent.status
.Kibana/Elasticsearch Stack version:
main
v8.3.0
Steps to reproduce:
Navigate to Security > Alerts
Enter the following KQL in the search bar:
Expected result
Click the
View details
row action on an alertHover over the
Agent status
field in the flyoutExpected result
Investigate in Timeline
action for theAgent status
fieldActual results
Investigate in Timeline
action is displayed for theAgent status
field, per the screenshot below:agent.status: "<uuid>"
, e.g.agent.status: "f0b84e9e-5ff7-4a83-b8f3-8315d34d039b"
, which is not expected to match any results, per the screenshot below:The text was updated successfully, but these errors were encountered: