elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.65k stars 8.23k forks source link

[Defend Workflows] Endpoints count Mismatch Due to Filter Applied by the Policies Tab for Endpoints. #197581

Closed sukhwindersingh-qasource closed 3 weeks ago

sukhwindersingh-qasource commented 3 weeks ago

Describe the bug:

Build Details:

VERSION: 8.16.0 BC1 BUILD: 79314 COMMIT: 5575428dd3aef69366cddb4ccf07a2a26d30ce48

Login Credentials

Preconditions

Steps to Reproduce

Actual result

Expected Result

Screen-cast

https://github.com/user-attachments/assets/2d87139f-7248-4fb2-b68c-f2c933cd7b66

Logs

elasticmachine commented 3 weeks ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 3 weeks ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

muskangulati-qasource commented 3 weeks ago

Reviewed and assigned to @dasansol92

dasansol92 commented 3 weeks ago

@sukhwindersingh-qasource thanks for raising this. As I can see, we are filtering by policy id in the endpoints list. Did you wait enough time for the transforms to update that list? Were the initial 4 enrolled agents still enrolled and online at the time you clicked on the number of hosts (5) at policy list page?

@pzl @joeypoon any other thoughts why that search is not returning the total list of enrolled endpoints (5)?

Thanks!

sukhwindersingh-qasource commented 3 weeks ago

Hi @dasansol92,

Thanks for the updates.

We tested on a single VM by installing/uninstalling agents to check the agent count. However, the transforms were not updated for the old entries since it was the same host. We tried it with multiple live hosts, waited for the transform updates, and observed that everything worked fine once the transforms were updated.

Screen Cast:

https://github.com/user-attachments/assets/d6192af6-6d46-431d-9565-1ecfd2b93c95

Hence, we are closing this ticket as it is now working fine.

Thanks!