elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.72k stars 8.13k forks source link

[Security Solution][Upgrade Issue]An error is preventing this alert from being analyzed in alert Fly-out #169373

Closed ghost closed 5 months ago

ghost commented 11 months ago

Describe the bug: An error is preventing this alert from being analyzed in alert Fly-out

Kibana/Elasticsearch Stack version Version: 8.11.0 BC3 Commit: 714189fa2b0f0a4d9f3865a8fce08261211570c8 Build: 67923

Browser and Browser OS Version: Firefox for windows OS Version: 118.0.1

Elastic Endpoint Version: 8.11

Original install method: None

Functional Area: Alert Fly Out

Initial Setup:

Steps to reproduce

Additional Result

Current Result

Expected behavior:

Screen-Cast:

Before Upgrade:

https://github.com/elastic/kibana/assets/59917825/1bc385cd-932c-4176-90b1-12839b8bac1b

After Upgrade:

https://github.com/elastic/kibana/assets/59917825/46b0eb56-a9c3-4253-ab93-cd3b2014020a

image

elasticmachine commented 11 months ago

Pinging @elastic/security-solution (Team: SecuritySolution)

christineweng commented 11 months ago

@karanbirsingh-qasource do you have an instance where the error happens?

Does it only happens to alerts that were generated before the upgrade. If you generate some new alerts, does the analyzer preview show error?

ghost commented 11 months ago

Hi @christineweng

we have shared the Instance credentials with you over g mail and yes for newly generated the analyzer details are showing correctly and issue is for old generated alerts.

https://github.com/elastic/kibana/assets/59917825/984bdb60-9b93-4867-9983-94d45901d0c6

ghost commented 9 months ago

Issue is also fixed on 8.11.2 ✔️ .

Build Details:

Version: 8.11.2
Commit: 92746356b61c3e3ac62b6d7045727f8d737fa4b5
Build: 68299

Screen-Cast

https://github.com/elastic/kibana/assets/59917825/43bb3b6b-92ce-441d-a15d-27a7d6fc7058

christineweng commented 8 months ago

Hi @karanbirsingh-qasource is this considered fixed and can we close the issue?

ghost commented 8 months ago

hi @christineweng

we have validated this issue on 8.12 BC4 and on that issue is still occuring ❌

Upgrade Path: 7.17.16 to 8.12.0 BC4

"An error is preventing this alert from being analyzed." is showing up in the alert fly-out visualization section.

image

https://github.com/elastic/kibana/assets/59917825/d3b68375-8541-4f29-8c8a-021e3491819a

c.c @MadameSheema

elasticmachine commented 8 months ago

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

christineweng commented 7 months ago

@karanbirsingh-qasource this is fixed and should be available in 8.12.1

ghost commented 7 months ago

thanks @christineweng for the update we will going to regress this once 8.12.1 will be available.

ghost commented 7 months ago

Hi @christineweng

we have validated this issue on 8.12.1 after upgrading from 7.17.17 and found the issue to be still occuring. ❌

Upgrade Path: 7.17.17 to 8.12.1

Build Details:

Version: 8.12.1
Commit: 3066656a1646ab79fcec004f20d91c80478a0e52
Build: 70233

Screen-Cast:

https://github.com/elastic/kibana/assets/59917825/12c5248e-751e-4d3d-9671-fc76b23183e3

@MadameSheema

christineweng commented 7 months ago

@karanbirsingh-qasource thanks for checking! could you share this instance with me?

MadameSheema commented 7 months ago

@christineweng what is the current status of this fix?

christineweng commented 7 months ago

@MadameSheema I have a fix but want to test it on a 7.x and go through the upgrade path to confirm. Will ping you on test data. Updated impact to medium, because user can use analyzer directly as workaround

christineweng commented 6 months ago

@karanbirsingh-qasource this is fixed in https://github.com/elastic/kibana/pull/178389, should be reflected in 8.13 BC5

ghost commented 5 months ago

Hi @MadameSheema

we have validated this issue on 8.13.1 and found the issue to be fixed ✔️ .

Build Details:

Version: 8.13.1
Commit: 091f486ab05863258cf2f3fa18ea0c59097dee80
Build: 72107

Screen-Cast:

https://github.com/elastic/kibana/assets/59917825/d95e9478-9878-41d2-9cb5-972482a65ad0

Hence we are closing this issue and adding "QA:Validated" tag to it.

thanks !!