elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.71k stars 8.12k forks source link

[Security Solution] Threat Intel card on overview page shows persistent caution message #126092

Closed MikePaquette closed 2 years ago

MikePaquette commented 2 years ago

Kibana version: 8.1.0 BC1

Elasticsearch version: 8.1.0 BC1

Server OS version: Elastic Cloud ESS default

Browser version: Google Chrome Version 98.0.4758.102 (Official Build) (x86_64)

Browser OS version: macOS Monterey Version 12.2.1 (21D62)

Original install method (e.g. download page, yum, from source, etc.): Elastic Cloud ESS GCP Europe-West-1

Describe the bug:

Overview page threatintel message persists even though I am cool with the feeds I've enabled.

Steps to reproduce:

  1. Install the Filebeat Threatintel module on an external system
  2. Configure it to pull you desired threat intelligence feeds
  3. Setup and Run the filebeat module
  4. Notice that you are successfully receiving your threat intelligence
  5. Notice the caution message on your overview page - raising your awareness that not all feeds are configured.
  6. This message persists forever.

Expected behavior: I should be able to dismiss this message, so that analysts and soc managers are not worried that there may be a problem.

Screenshots (if relevant):

image

Errors in browser console (if relevant): None

Provide logs and/or server output (if relevant): N/A

Any additional context:. None

elasticmachine commented 2 years ago

Pinging @elastic/security-detections-response (Team:Detections and Resp)

ecezalp commented 2 years ago

closing as duplicate of https://github.com/elastic/security-team/issues/3115