[Security Solution] Unable to upgrade Threat Match prebuilt rules #203365
Labels
8.18 candidate
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules area
impact:high
Addressing this issue will have a high level of impact on the quality/strength of our product.
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Summary
It's not possible to upgrade Threat Match rules without customizations in any possible way.
Steps to reproduce:
Threat Intel URL Indicator Match)
Install rule
buttonExpected behavior: Rule upgrades successfully.
Actual behavior: Rule fails to upgrade.
Screenshots:
Setup the environment
prebuiltRulesCustomizationEnabled
feature flag is enabledserver.restrictInternalApis: false
tokibana.dev.yaml
security_detection_engine
Fleet packageThe text was updated successfully, but these errors were encountered: