elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.81k stars 8.2k forks source link

[Defend Workflows] An empty value is present in the suggestion list for the process.name field in Event Filters #196824

Open sukhwindersingh-qasource opened 1 day ago

sukhwindersingh-qasource commented 1 day ago

Describe the bug:

Build Details:

VERSION: 8.16.0-snapshot BUILD: 79197 COMMIT: 2601f8aa203cd733a7669a59398a185ed8af12c4

Login Credentials

Preconditions

Steps to Reproduce

Actual result

Expected Result

Screen-cast

https://github.com/user-attachments/assets/30602927-9332-42c2-a582-d3e8febfb28f

Logs

elasticmachine commented 1 day ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 1 day ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

sukhwindersingh-qasource commented 1 day ago

Please review this @muskangulati-qasource Thanks!!

muskangulati-qasource commented 23 hours ago

Reviewed and assigned to @dasansol92

dasansol92 commented 22 hours ago

@sukhwindersingh-qasource Thanks for creating this. If I'm not wrong, this is because there is an endpoint event with an empty process.name value in the system. Is this also happening for other fields? @gergoabraham Could that be related to the recent changes we made in this area?

sukhwindersingh-qasource commented 20 hours ago

Hi @dasansol92,

Yes, the issue is caused by empty fields in the host events related to process.name. We could hide these empty fields from the suggestions, as selecting an empty value doesn’t serve any purpose.

Screen-shot Image

Please let us know if anything else is required from our end,

Thanks!