Closed gurevichdmitry closed 1 year ago
@orestisfl, It appears that this bug is still present in the latest Kibana version, 8.8.0-BC3.
@gurevichdmitry it fails because
"EventSelectors": null,
"MetricTopicBinding": {
"<unauthorized_api_calls_metric>": []
},
Describe the bug Rule 4.1: Ensure a log metric filter and alarm exist for unauthorized API calls. Correctly defined metric and filter for unauthorized API calls is evaluated as failure.
After investigation with @olegsu it was found that csp policy uses incorrect filter evaluation pattern.
Preconditions ELK Stack 8.8 is deployed
To Reproduce Steps to reproduce the behavior:
Expected behavior Cloudbeat evaluates rule 4.1 as passed.
Environment