You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What is the bug?
When creating a correlation, if an index pattern or alias is selected as a data source, the index pattern's fields are not visible in the data filter dropdown. There is no problem if the selected index is a concrete index.
How can one reproduce the bug?
Steps to reproduce the behavior:
Have an index alias or multiple indices that follow a pattern
Go to Security Analytics -> Correlations -> Correlation rules -> Create correlation rule
In Correlation queries, under any Data source, select an index alias or pattern.
Under Data filter, select the Field dropdown menu, there will be no index fields.
What is the expected behavior?
When an index pattern or alias is selected, fields should be displayed the same way they are displayed in the Security Analytics Detector creation UI when mapping log type fields to index fields, or in Alerting monitor creation, when using index fields to add data filters as part of the Monitor query.
What is your host/environment?
OS: [e.g. iOS]
Version [e.g. 22]
Plugins
Do you have any screenshots?
Here, an index alias is selected:
Do you have any additional context?
Add any other context about the problem.
The text was updated successfully, but these errors were encountered:
What is the bug?
When creating a correlation, if an index pattern or alias is selected as a data source, the index pattern's fields are not visible in the data filter dropdown. There is no problem if the selected index is a concrete index.
How can one reproduce the bug?
Steps to reproduce the behavior:
What is the expected behavior?
When an index pattern or alias is selected, fields should be displayed the same way they are displayed in the Security Analytics Detector creation UI when mapping log type fields to index fields, or in Alerting monitor creation, when using index fields to add data filters as part of the Monitor query.
What is your host/environment?
Do you have any screenshots?
Here, an index alias is selected:
Do you have any additional context?
Add any other context about the problem.
The text was updated successfully, but these errors were encountered: