Open arvindersingh-qasource opened 3 months ago
Pinging @elastic/security-solution (Team: SecuritySolution)
@karanbirsingh-qasource Please review this ticket.
Thanks.
@arvindersingh-qasource is this happening just for imported rules? You exported the rule after the upgrade was done, correct? Can you please also provide the output of one of the exported rules? Thanks! :)
Pinging @elastic/security-detections-response (Team:Detections and Resp)
Pinging @elastic/security-detection-engine (Team:Detection Engine)
Hi @MadameSheema
is this happening just for imported rules?
Yes Glo for the imported ones ( using the export file from 8.15 only )
Observation for Existing Rule ( ones which are created on 8.12)
Observation for new rule created after upgrade ( ones which are created on BC6)
You exported the rule after the upgrade was done, correct?
Yes after the build got upgrade from 8.12 , we exported all the rule on 8.15 then deleted those same rule and imported them back
Can you please also provide the output of one of the exported rules?
yes here is the exported copy of rule which consist of 3 rules
Please let us know if anything else is required from our end.
Thanks.
Describe the bug Getting
[request params]: Invalid value "undefined" supplied to "id" (400)
for adding rule exception to Alert after importing rule.Build Details
Browser Details This issue is occurring on all browsers.
Preconditions
Steps to Reproduce
Security
->Rules
->Detection Rule (SIEM)
Security
->Alerts
....
option for the Alert respective to the pre requisite Alert.Add rule exception
option.Add rule exception
.[request params]: Invalid value "undefined" supplied to "id" (400)
.Actual Result Getting
[request params]: Invalid value "undefined" supplied to "id" (400)
for adding rule exception to Alert after importing rule.Expected Result There should be no error while adding Rule Exception.
What's Working
What's Not Working
Event Correlation
,Custom Query
,Threshold
AlertsScreenshot