Open sukhwindersingh-qasource opened 2 months ago
Pinging @elastic/security-defend-workflows (Team:Defend Workflows)
Pinging @elastic/security-solution (Team: SecuritySolution)
@muskangulati-qasource , Kindly review this Thanks!!
Reviewed and assigned to @dasansol92
Pinging @elastic/security-detection-engine (Team:Detection Engine)
Describe the bug:
Build Details:
Login Credentials
Preconditions
logs-sentinel_one.alert*
observer.serial_number:*
Steps to Reproduce
The "event.category" field can not be used for filtering.
although Event.category field is present in the Alerts DataActual result
Expected Result
Whats working
Screen-cast
https://github.com/user-attachments/assets/8849512c-3ec3-4fe2-be5a-ceb2190b9dec
Logs