Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] [Question] Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table. #94557

Closed
ghost opened this issue Mar 15, 2021 · 22 comments
Labels
bug Fixes for quality problems that affect the customer experience fixed impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.15.0 v7.16.0 v8.0.0

Comments

@ghost
Copy link

ghost commented Mar 15, 2021

Description
[Question] Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.

Build Details:

Version: 7.12.0-BC4
Platform: Production
Commit:99ac38d70e426f589bb61a034c96e602d759cfab
Build:39242
https://staging.elastic.co/7.12.0-336ff10d/summary-7.12.0.html

Browser Details:
All

Preconditions:

  1. 7.12.0 Kibana Environment should exist.
  2. Endpoint should be installed.
  3. Multiple alerts should be generated

Steps to Reproduce:

  1. Navigate to the detection tab of security.
  2. Hover on hostname under the host.name column of detection alert table
  3. Click on show top host.name icon
  4. Select the Raw events from drop-down and observe that same results are displaying for "Raw events" and "Detection Alerts"

Observation:

  1. Navigate to the External tab under the host tab.
  2. Hover on hostname under the host.name column
  3. Click on show top host.name icon
  4. Select the Raw events from drop-down and observe that correct results are displaying for "Raw events"
    external_alerts

Impacted Test case:
N/A

Actual Result:
Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.

Expected Result:
Correct result should be displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.

What's working:
N/A

What's not working:
N/A

Screenshot:
Detection Alerts
detection_alerts

Raw events
raw_events

@ghost ghost added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Mar 15, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@ghost ghost changed the title [Security Solution] [Security Solution] [Question] Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table. Mar 15, 2021
@ghost
Copy link
Author

ghost commented Mar 15, 2021

@manishgupta-qasource Please review!!

@manishgupta-qasource
Copy link

Reviewed & Assigned to @MadameSheema

@manishgupta-qasource manishgupta-qasource added bug Fixes for quality problems that affect the customer experience impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. labels Mar 15, 2021
@MindyRS MindyRS added the Team:Detections and Resp Security Detection Response Team label Mar 15, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@peluja1012 peluja1012 added Team:Threat Hunting Security Solution Threat Hunting Team and removed Team:Detections and Resp Security Detection Response Team labels Mar 15, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@MadameSheema
Copy link
Member

@XavierM can you please help to prioritise this? Thanks :)

@XavierM
Copy link
Contributor

XavierM commented Mar 16, 2021

yes, we know about it, we should have a PR this week

@MadameSheema
Copy link
Member

@deepikakeshav-qasource can you please check if this is fixed already on 7.12.x branch? Thanks :)

@ghost
Copy link
Author

ghost commented Apr 8, 2021

Hi @MadameSheema,

We have validated this issue on 7.12.0, 7.12.1 SNAPSHOT and 7.13.0 SNAPSHOT build and Below are the observations:

7.12.0

We observed that issue is still occurring on 7.12.0. Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table. 🔴

Build Details:

Version:7.12.0
Commit:b7f9a41f486a2910ef22a1274ec734219c35ca3e
Build:39309

Screenshot:
7_12_0_raw_events

7_12_0_detection_rule

7.12.1 SNAPSHOT

We observed that issue is fixed on 7.12.1 SNAPSHOT. Correct result is displayed in show top host.name for "Raw events" under the detection alert table. 🟢

Build Details:

Version:7.12.1 SNAPSHOT
Commit:e01b1c2af2c9b9d068c2829463b9c8dd42cbf099
Build:39401

Screenshot:
7_12_1_raw_events

7_12_1_detection_rule

7.13.0 SNAPSHOT

We observed that issue is fixed on 7.13.0 SNAPSHOT. Correct result is displayed in show top host.name for "Raw events" under the detection alert table. 🟢

Build Details:

Version:7.13.0 SNAPSHOT
Commit:6f0d093915d937453c617a63cff5aee00a12a4c6
Build:40112

Screenshot:
7_13_0_raw_events

7_13_0_detection_rule

Hence, We will revalidate this ticket once 7.12.1 BC build available.

Thanks!!

@ghost
Copy link
Author

ghost commented Apr 15, 2021

Hi @MadameSheema,

We have validated this issue on 7.12.1 BC1 and observed that issue is fixed. The correct result is displayed in show top host.name for "Raw events" under the detection alert table.

Build Details:

Version:7.12.1 BC1
Commit:bb662886fc93cd04030e66223bb1ffa8512e0705
Build:39445

Screenshot:
Detections_alert

Raw_events

Hence, We are closing this ticket.

Thanks!!

@ghost ghost added the QA:Validated Issue has been validated by QA label Apr 15, 2021
@ghost ghost closed this as completed Apr 15, 2021
@ghost
Copy link

ghost commented Aug 24, 2021

Hi @MadameSheema

We tested this ticket & found that the issue exists on the 7.15.0-BC1 environment under count canvas. Please find below the testing details:

Build Details:

VERSION:7.15.0-BC1
BUILD: 43636
COMMIT: d791226d9385122f33f4a5ca38fa5369012fbec3
ARTIFACT: https://staging.elastic.co/7.15.0-d9929120/summary-7.15.0.html

Steps to Reproduce:

  1. Navigate to the Detection tab under Security App.
  2. Go to the count tab.
  3. Select stack by signal.rule.risk_score , signal.rule.severity , signal.rule.name and signal.rule.type.
  4. Observe that for stack by signal.rule.risk_score , signal.rule.severity , signal.rule.name and signal.rule.type it doesn't show Raw events but shows Detection alerts.

Screen-Recording:

Alerts.-.Kibana.-.Google.Chrome.2021-08-24.16-54-05.mp4

Hence, reopening the issue.

Thanks!!

@ghost ghost reopened this Aug 24, 2021
@MadameSheema
Copy link
Member

@angorayc can you please take a look at this? Thanks :)

@angorayc angorayc assigned machadoum and unassigned angorayc Sep 2, 2021
@machadoum machadoum added v7.16.0 v8.0.0 and removed QA:Validated Issue has been validated by QA v7.12.1 labels Sep 3, 2021
@machadoum
Copy link
Member

I noticed that this bug doesn't happen on master because the user can't select the top event graph anymore. It doesn't show up as an option when hovering count table and trend graph items.

Screenshot 2021-09-03 at 09 48 02

Screenshot 2021-09-03 at 09 47 45

@machadoum machadoum added fixed and removed fixed labels Sep 3, 2021
@ghost
Copy link

ghost commented Sep 3, 2021

Hi @MadameSheema

We tested this ticket on the 7.15.0-BC4 environment & found that the 'Show Top' is removed from the count tab however, the issue still exist under alert table. Please find below the testing details:

Build Details:

VERSION:7.15.0-BC4
BUILD: 43886
COMMIT: 29a6969dc230abf16dc65a41c535cb534ae64fa7
ARTIFACT:https://staging.elastic.co/7.15.0-9e0972b3/summary-7.15.0.html

Screen-Recording:

Alerts.-.Kibana.-.Google.Chrome.2021-09-03.13-55-40.mp4

Screenshot:

image (5)

Let me know if you need more information on this.
Thanks!!

@MadameSheema
Copy link
Member

I checked 7.15 branch (71768bb) and I face the same behaviour.

@machadoum any thoughts on this? Thanks :)

@machadoum
Copy link
Member

machadoum commented Sep 3, 2021

I see one clear bug here, which is the inconsistent total number of events:

Screenshot 2021-09-03 at 15 02 12

But this issue seems to be related to the fact that it returns zero events when the user selects "Raw events".

it doesn't show Raw events but shows Detection alerts.

The reason for that is that they query different indices. When "Detection alerts" is selected, it queries ".siem-signals-*", but when "raw events" is selected, it queries an index pattern like packetbeat-*, which doesn't include alerts.

Isn't it the expected behavior? How should it work, though?

@MadameSheema
Copy link
Member

@XavierM @asnehalb can you please help us with our doubts? Thanks :)

@machadoum
Copy link
Member

As discussed with Xavier, displaying zero events for fields like signal.rule.name on Raw events is expected because these fields are not present on any raw event index. I am addressing the inconsistent total count bug here: #111256

@angorayc
Copy link
Contributor

angorayc commented Sep 6, 2021

I noticed that this bug doesn't happen on master because the user can't select the top event graph anymore. It doesn't show up as an option when hovering count table and trend graph items.

Screenshot 2021-09-03 at 09 48 02 Screenshot 2021-09-03 at 09 47 45

This was to fix infinite popovers from topN chart, but to me I think it's fine to enable launching topN chart in the Count table, as users are not able to launch another topN chart again again from the existing topN.
Kapture 2021-09-06 at 11 17 03

@machadoum
Copy link
Member

Hey @andrew-goldstein! Since you have more context about this issue, I would like to hear your opinion. Angela's comment does make sense to me, but are we missing something here?

This was to fix infinite popovers from topN chart, but to me I think it's fine to enable launching topN chart in the Count table, as users are not able to launch another topN chart again again from the existing topN.

@MadameSheema
Copy link
Member

@deepikakeshav-qasource @samratbhadra-qasource please validate on 7.15BC5 thanks

Note that on the count table it is expected to don't be able to launch the Top x behaviour

@MadameSheema MadameSheema assigned ghost and unassigned machadoum Sep 8, 2021
@ghost
Copy link
Author

ghost commented Sep 8, 2021

Hi @MadameSheema,

We have validated this ticket on 7.15.0 BC5 build and observed that issue is Fixed. Correct information is displayed for Raw events under Alerts table

Build Details:

Version:7.15.0 BC5
Commit:0239ff6864dd9930cfe9bcd9a679272f2b7465c2
Build:43957

Screenshot:
image

image

raw_events.mp4

Hence, We are closing this ticket and marking as QA Validated

Thanks!!

@ghost ghost added the QA:Validated Issue has been validated by QA label Sep 8, 2021
@ghost ghost closed this as completed Sep 8, 2021
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience fixed impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.15.0 v7.16.0 v8.0.0
Projects
None yet
Development

No branches or pull requests

8 participants