elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.65k stars 8.23k forks source link

[Security Solution] Timeline is always empty when adding a value from dashboard #164344

Open MadameSheema opened 1 year ago

MadameSheema commented 1 year ago

Describe the bug:

Kibana/Elasticsearch Stack version:

Initial Status:

Steps to reproduce:

  1. Navigate to dashboards
  2. Open the one that has a table
  3. Add a field to the timeline by hovering and clicking on the timeline icon

Current behavior:

Screenshot 2023-08-21 at 20 26 23 Screenshot 2023-08-21 at 20 29 17 Screenshot 2023-08-21 at 20 29 57

Expected behavior:

elasticmachine commented 1 year ago

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

elasticmachine commented 1 year ago

Pinging @elastic/security-solution (Team: SecuritySolution)

angorayc commented 1 year ago

Hello @MadameSheema , could you please provide the query the table is using and the query the timeline is using when there's no data? I am wondering if it's caused by different date range in the query. Thank you.

MadameSheema commented 1 year ago

@angorayc and I synced over zoom. These are our observations:

@paulewing may you please help us to prioritise this? Thanks! :)