-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] [Question] Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table. #94557
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
@manishgupta-qasource Please review!! |
Reviewed & Assigned to @MadameSheema |
Pinging @elastic/security-detections-response (Team:Detections and Resp) |
Pinging @elastic/security-threat-hunting (Team:Threat Hunting) |
@XavierM can you please help to prioritise this? Thanks :) |
yes, we know about it, we should have a PR this week |
@deepikakeshav-qasource can you please check if this is fixed already on 7.12.x branch? Thanks :) |
Hi @MadameSheema, We have validated this issue on 7.12.0, 7.12.1 SNAPSHOT and 7.13.0 SNAPSHOT build and Below are the observations: 7.12.0We observed that issue is still occurring on 7.12.0. Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table. 🔴 Build Details:
7.12.1 SNAPSHOTWe observed that issue is fixed on 7.12.1 SNAPSHOT. Correct result is displayed in show top host.name for "Raw events" under the detection alert table. 🟢 Build Details:
7.13.0 SNAPSHOTWe observed that issue is fixed on 7.13.0 SNAPSHOT. Correct result is displayed in show top host.name for "Raw events" under the detection alert table. 🟢 Build Details:
Hence, We will revalidate this ticket once 7.12.1 BC build available. Thanks!! |
Hi @MadameSheema, We have validated this issue on 7.12.1 BC1 and observed that issue is fixed. The correct result is displayed in show top host.name for "Raw events" under the detection alert table. Build Details:
Hence, We are closing this ticket. Thanks!! |
We tested this ticket & found that the issue exists on the 7.15.0-BC1 environment under count canvas. Please find below the testing details: Build Details:
Steps to Reproduce:
Screen-Recording: Alerts.-.Kibana.-.Google.Chrome.2021-08-24.16-54-05.mp4Hence, reopening the issue. Thanks!! |
@angorayc can you please take a look at this? Thanks :) |
We tested this ticket on the 7.15.0-BC4 environment & found that the 'Show Top' is removed from the count tab however, the issue still exist under alert table. Please find below the testing details: Build Details:
Screen-Recording: Alerts.-.Kibana.-.Google.Chrome.2021-09-03.13-55-40.mp4Screenshot: Let me know if you need more information on this. |
I checked 7.15 branch (71768bb) and I face the same behaviour. @machadoum any thoughts on this? Thanks :) |
I see one clear bug here, which is the inconsistent total number of events: But this issue seems to be related to the fact that it returns zero events when the user selects "Raw events".
The reason for that is that they query different indices. When "Detection alerts" is selected, it queries ".siem-signals-*", but when "raw events" is selected, it queries an index pattern like Isn't it the expected behavior? How should it work, though? |
As discussed with Xavier, displaying zero events for fields like |
This was to fix infinite popovers from topN chart, but to me I think it's fine to enable launching topN chart in the Count table, as users are not able to launch another topN chart again again from the existing topN. |
Hey @andrew-goldstein! Since you have more context about this issue, I would like to hear your opinion. Angela's comment does make sense to me, but are we missing something here?
|
@deepikakeshav-qasource @samratbhadra-qasource please validate on 7.15BC5 thanks Note that on the count table it is expected to don't be able to launch the |
Hi @MadameSheema, We have validated this ticket on 7.15.0 BC5 build and observed that issue is Fixed. Correct information is displayed for Raw events under Alerts table Build Details:
raw_events.mp4Hence, We are closing this ticket and marking as QA Validated Thanks!! |
Description
[Question] Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.
Build Details:
Browser Details:
All
Preconditions:
Steps to Reproduce:
Observation:
Impacted Test case:
N/A
Actual Result:
Same result is displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.
Expected Result:
Correct result should be displayed in show top host.name for "Raw events" and "Detection Alerts" under the detection alert table.
What's working:
N/A
What's not working:
N/A
Screenshot:
Detection Alerts
Raw events
The text was updated successfully, but these errors were encountered: