elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.66k stars 8.23k forks source link

[Security Solution] No value is displaying for rule.reference field under alerts details #116260

Open ghost opened 3 years ago

ghost commented 3 years ago

Describe the bug No value is displaying for rule.reference field under alerts details

Build Details: Version:7.16.0 BC1 Build: 45504 COMMIT: 9231d806c9384df4026977ba7435a9302dc2d4ab

Browser Details: N/A

Preconditions

  1. Kibana should be running.
  2. Agent should be installed
  3. Malicious Behavior Alerts should be generated

Steps to Reproduce

  1. Navigate to alerts tab
  2. Click on view details
  3. Search with field "rule.reference" under table tab
  4. Observe that no value is displaying for rule.reference field under alerts details

Actual Result No value is displaying for rule.reference field under alerts details

Expected Result Value should be displayed for rule.reference field under alerts details

What's Working

What's Not Working

Screen-Shot image

elasticmachine commented 3 years ago

Pinging @elastic/security-solution (Team: SecuritySolution)

MadameSheema commented 3 years ago

@deepikakeshav-qasource is the value available in the alerts table and in the json tab? Thanks!

ghost commented 3 years ago

Hi @madamesheema,

Yes, the values are displaying in alert table and json tab.

Screenshots: Json Tab image

Alert Table: image

Please let us know if anything else is required from our end.

Thanks!!

michaelolo24 commented 3 years ago

Thanks for letting us know @deepikakeshav-qasource!

MadameSheema commented 3 years ago

Changing to impact low since there is no data loss

elasticmachine commented 2 years ago

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

PhilippeOberti commented 10 hours ago

The bug is still happening today, as shown on this screenshot of 8.16 version Image