Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Fields not accessible in correlations creation UI when index pattern is selected #1049

Open
toepkerd opened this issue Jun 18, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@toepkerd
Copy link

What is the bug?
When creating a correlation, if an index pattern or alias is selected as a data source, the index pattern's fields are not visible in the data filter dropdown. There is no problem if the selected index is a concrete index.

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Have an index alias or multiple indices that follow a pattern
  2. Go to Security Analytics -> Correlations -> Correlation rules -> Create correlation rule
  3. In Correlation queries, under any Data source, select an index alias or pattern.
  4. Under Data filter, select the Field dropdown menu, there will be no index fields.

What is the expected behavior?
When an index pattern or alias is selected, fields should be displayed the same way they are displayed in the Security Analytics Detector creation UI when mapping log type fields to index fields, or in Alerting monitor creation, when using index fields to add data filters as part of the Monitor query.

What is your host/environment?

  • OS: [e.g. iOS]
  • Version [e.g. 22]
  • Plugins

Do you have any screenshots?
Here, an index alias is selected:
Screenshot 2024-06-18 at 2 15 58 PM

Do you have any additional context?
Add any other context about the problem.

@toepkerd toepkerd added bug Something isn't working untriaged labels Jun 18, 2024
@dblock
Copy link
Member

dblock commented Jul 8, 2024

[Catch All Triage, attendees 1, 2, 3, 4, 5, 6, 7]

@dblock dblock removed the untriaged label Jul 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants