Open sukhwindersingh-qasource opened 1 month ago
Pinging @elastic/security-defend-workflows (Team:Defend Workflows)
Pinging @elastic/security-solution (Team: SecuritySolution)
@muskangulati-qasource Kindly review this
Thanks !!
Reviewed and assigned to @dasansol92
Describe the bug:
agent.id
fieldBuild Details:
VERSION: 9.0.0 PR shared by @tomsonpl BUILD: 79377 COMMIT: 3a77c531cbb558bd84332a9ca161291ecd997efc
Login Credentials
Preconditions
Kibana should be running.
Create a threshold rule with below configuration
Generate the alert from this rule by executing
ls
command on Linux endpointSteps to Reproduce
agent.id
fieldActual result
agent.id
fieldExpected Result
agent.id
fieldScreen-shot
Exported Rule
rules_export.ndjson.zip
Logs
AC