Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Fields Displayed in Current Version Despite Being Removed #200285

Open
pborgonovi opened this issue Nov 15, 2024 · 3 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed

Comments

@pborgonovi
Copy link

pborgonovi commented Nov 15, 2024

Describe the bug:

When fields like Tags, Related Integrations, and MITRE ATT&CK are removed in the Customized version of a rule, they still appear in the Current version within the rule updates table.

Kibana/Elasticsearch Stack version:

8.x

Current branch: 8.x  
Latest commit: d0c9a2f1f52 - [8.x] [Stack Monitoring / Logs] Fix Stack Monitoring logs links (#200043) (#200227)  
Remote tracking: origin/8.x  
Status relative to remote: up to date (no pending commits)  

Server OS version:

Browser and Browser OS versions:

Elastic Endpoint version:

Original install method (e.g. download page, yum, from source, etc.):

Functional Area (e.g. Endpoint management, timelines, resolver, etc.):

Steps to reproduce:

  1. Select a prebuilt rule which has an update available and customize it by removing all tags in the Tags, Related Integrations and MITRE ATT&CK fields.
  2. Save the customized rule.
  3. Open the Rule Updates table for the customized rule.
  4. Observe the tags displayed under the Current version.

Current behavior:

Fields that were cleared (e.g., Tags, Related Integrations, MITRE ATT&CK) in the Customized version still appear with their previous values in the Current version within the rule updates table.

Expected behavior:

The Current version should correctly reflect the actual customized state of the rule. For fields like Tags, Related Integrations, or MITRE ATT&CK, if all values are removed during customization, the Current version should display an empty state or indicate that the field is cleared.

Screenshots (if relevant):

Screen.Recording.2024-11-14.at.3.57.45.PM.mov

Errors in browser console (if relevant):

Provide logs and/or server output (if relevant):

Any additional context (logs, chat logs, magical formulas, etc.):

@pborgonovi pborgonovi added bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team triage_needed labels Nov 15, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-rule-management (Team:Detection Rule Management)

@pborgonovi pborgonovi changed the title [Security Solution] Tags Displayed in Current Version Despite Being Removed [Security Solution] Fields Displayed in Current Version Despite Being Removed Nov 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed
Projects
None yet
Development

No branches or pull requests

3 participants