elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.71k stars 8.12k forks source link

[Defend Workflows]Newly Added Defend Integration Policy RAV Settings is Disabled Instead of Syncing with Malware Protection Level #191261

Open sukhwindersingh-qasource opened 2 weeks ago

sukhwindersingh-qasource commented 2 weeks ago

Describe the bug:

Build Details:

VERSION: 8.16.0
BUILD: 77679
COMMIT: 6b091fe3b410eaae9d4805c0a3c0ea6168bf66b0

Login Credentials https://p.elstc.co/paste/lDrf5NTS#u-zff3/Cj2T9laJWLsTIOlSzVViJHTB8zIJ8TWKNkV5

Preconditions

Steps to Reproduce

Actual result

Expected Result

Whats working

Additional Information

Screen-cast

https://github.com/user-attachments/assets/c8c9c7f8-ffb0-41f5-aecc-f7e91d175dda

Logs

AC

elasticmachine commented 2 weeks ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 2 weeks ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

sukhwindersingh-qasource commented 2 weeks ago

@muskangulati-qasource Kindly review this

Thanks!

muskangulati-qasource commented 2 weeks ago

Reviewed and assigned to @dasansol92

dasansol92 commented 2 weeks ago

Thanks for sharing this @sukhwindersingh-qasource About the disabled protections by default:

Also we observed that all the toggle are off and recommended settings are only for OS event Collections

is this also happening in older versions of Kibana like 8.14?

Thanks!

sukhwindersingh-qasource commented 2 weeks ago

Hi @dasansol92 ,

We have observed the same behavior is present on the 8.14.0 as well

Screen Cast :

https://github.com/user-attachments/assets/9821a7f8-6ddd-41d0-9f26-4cdab07e4e6b

Please Let us Know if anything else is required from our end.

Thanks!