[Security Solution] Recommended Endpoint exceptions cannot close all alerts by default but should #199707
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:Rule Exceptions
Security Solution Detection Rule Exceptions area
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
Team:Detection Engine
Security Solution Detection Engine Area
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
triage_needed
Describe the bug:
By default recommended Endpoint Exceptions for Malicious Behavior alerts have a grayed out checkbox for
Close all alerts that match this exception and were generated by this rule (Lists and non-ECS fields are not supported)
even though they can be closed and there is a simple workaround to make that happen.Kibana/Elasticsearch Stack version: 8.15.3
Server OS version: N/A
Browser and Browser OS versions: Firefox 132.0.1
Elastic Endpoint version: N/A
Original install method (e.g. download page, yum, from source, etc.): ECH
Functional Area (e.g. Endpoint management, timelines, resolver, etc.): Endpoint Exceptions
Steps to reproduce:
Close all alerts ...
option is greyed out (this is the bug)process.executable.caseless
field toprocess.executable
then back toprocess.executable.caseless
Close all alerts ...
option is now available and works if clickedCurrent behavior: See above
Expected behavior: The option should work without any user edits
Screenshots (if relevant): I hope my explaination is good enough
Errors in browser console (if relevant): N/A
Provide logs and/or server output (if relevant): N/A
Any additional context (logs, chat logs, magical formulas, etc.): N/A
The text was updated successfully, but these errors were encountered: