elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.68k stars 8.23k forks source link

[Security Solution] Update and recreate data view does not work in the first iteration for an imported timeline #201765

Open MadameSheema opened 2 hours ago

MadameSheema commented 2 hours ago

Describe the bug:

Kibana/Elasticsearch Stack version:

Steps to reproduce:

  1. Navigate to timelines
  2. Click Import button
  3. Import the following timelines

    Timelines to import {"savedObjectId":"fe763e70-4ba2-11ec-8573-d909b3bd6040","version":"WzY3MzYsMl0=","columns":[{"columnHeaderType":"not-filtered","id":"@timestamp","type":"number"},{"columnHeaderType":"not-filtered","id":"message"},{"columnHeaderType":"not-filtered","id":"event.category"},{"columnHeaderType":"not-filtered","id":"event.action"},{"columnHeaderType":"not-filtered","id":"host.name"},{"columnHeaderType":"not-filtered","id":"source.ip"},{"columnHeaderType":"not-filtered","id":"destination.ip"},{"columnHeaderType":"not-filtered","id":"user.name"}],"dataProviders":[],"description":"","eqlOptions":{"tiebreakerField":"","size":100,"query":"","eventCategoryField":"event.category","timestampField":"@timestamp"},"eventType":"custom","filters":[],"kqlMode":"filter","kqlQuery":{"filterQuery":{"kuery":{"kind":"kuery","expression":"host.name:*"},"serializedQuery":"{\"bool\":{\"should\":[{\"exists\":{\"field\":\"host.name\"}}],\"minimum_should_match\":1}}"}},"indexNames":["auditbeat-*,packetbeat-*"],"title":"cool timeline","timelineType":"default","templateTimelineVersion":null,"templateTimelineId":null,"dateRange":{"start":"2021-11-17T07:00:00.000Z","end":"2021-11-18T06:59:59.999Z"},"sort":[{"columnType":"date","sortDirection":"desc","columnId":"@timestamp"}],"created":1637592396759,"createdBy":"smilovic","updated":1637592459151,"updatedBy":"smilovic","savedQueryId":null,"dataViewId":null,"eventNotes":[],"globalNotes":[],"pinnedEventIds":[]} {"savedObjectId":"fe7776f0-4ba2-11ec-8573-d909b3bd6040","version":"WzY3MTUsMl0=","columns":[{"columnHeaderType":"not-filtered","id":"@timestamp","type":"number"},{"columnHeaderType":"not-filtered","id":"message"},{"columnHeaderType":"not-filtered","id":"event.category"},{"columnHeaderType":"not-filtered","id":"event.action"},{"columnHeaderType":"not-filtered","id":"host.name"},{"columnHeaderType":"not-filtered","id":"source.ip"},{"columnHeaderType":"not-filtered","id":"destination.ip"},{"columnHeaderType":"not-filtered","id":"user.name"}],"dataProviders":[],"description":"","eventType":"custom","filters":[],"kqlMode":"filter","timelineType":"default","kqlQuery":{"filterQuery":{"serializedQuery":"{\"bool\":{\"should\":[{\"exists\":{\"field\":\"host.name\"}}],\"minimum_should_match\":1}}","kuery":{"expression":"host.name:*","kind":"kuery"}}},"title":"wonderful timeline","sort":[{"columnType":"date","sortDirection":"desc","columnId":"@timestamp"}],"templateTimelineId":null,"templateTimelineVersion":null,"dateRange":{"start":"2021-11-17T07:00:00.000Z","end":"2021-11-18T06:59:59.999Z"},"indexNames":[".siem-signals-default","auditbeat-*","auditbeat-*,packetbeat-*","apm-*,auditbeat-*,endgame-*,filebeat-*,logs-*","auditbeat-*,packetbeat-*,journalbeat-*","auditbeat-*,endgame-*,filebeat-*,logs-*"],"eqlOptions":{"tiebreakerField":"","size":100,"query":"","eventCategoryField":"event.category","timestampField":"@timestamp"},"created":1637592396767,"createdBy":"smilovic","updated":1637592396767,"updatedBy":"smilovic","savedQueryId":null,"dataViewId":null,"eventNotes":[],"globalNotes":[],"pinnedEventIds":[]} {"savedObjectId":"fe774fe0-4ba2-11ec-8573-d909b3bd6040","version":"WzY3MTQsMl0=","columns":[{"columnHeaderType":"not-filtered","id":"@timestamp","type":"number"},{"columnHeaderType":"not-filtered","id":"message"},{"columnHeaderType":"not-filtered","id":"event.category"},{"columnHeaderType":"not-filtered","id":"event.action"},{"columnHeaderType":"not-filtered","id":"host.name"},{"columnHeaderType":"not-filtered","id":"source.ip"},{"columnHeaderType":"not-filtered","id":"destination.ip"},{"columnHeaderType":"not-filtered","id":"user.name"}],"dataProviders":[],"description":"","eqlOptions":{"tiebreakerField":"","size":100,"query":"","eventCategoryField":"event.category","timestampField":"@timestamp"},"eventType":"custom","filters":[],"kqlMode":"filter","kqlQuery":{"filterQuery":{"kuery":{"kind":"kuery","expression":"host.name:*"},"serializedQuery":"{\"bool\":{\"should\":[{\"exists\":{\"field\":\"host.name\"}}],\"minimum_should_match\":1}}"}},"indexNames":["auditbeat-*,packetbeat-*,journalbeat-*"],"title":"neato timeline","timelineType":"default","templateTimelineVersion":null,"templateTimelineId":null,"dateRange":{"start":"2021-11-17T07:00:00.000Z","end":"2021-11-18T06:59:59.999Z"},"sort":[{"columnType":"date","sortDirection":"desc","columnId":"@timestamp"}],"created":1637592396766,"createdBy":"smilovic","updated":1637592396766,"updatedBy":"smilovic","savedQueryId":null,"dataViewId":null,"eventNotes":[],"globalNotes":[],"pinnedEventIds":[]} {"savedObjectId":"94555c10-4ba2-11ec-8573-d909b3bd6040","version":"WzY2MzMsMl0=","columns":[{"columnHeaderType":"not-filtered","id":"@timestamp","type":"number"},{"columnHeaderType":"not-filtered","id":"message"},{"columnHeaderType":"not-filtered","id":"event.category"},{"columnHeaderType":"not-filtered","id":"event.action"},{"columnHeaderType":"not-filtered","id":"host.name"},{"columnHeaderType":"not-filtered","id":"source.ip"},{"columnHeaderType":"not-filtered","id":"destination.ip"},{"columnHeaderType":"not-filtered","id":"user.name"}],"dataProviders":[],"description":"","eventType":"custom","filters":[],"kqlMode":"filter","timelineType":"default","kqlQuery":{"filterQuery":{"serializedQuery":"{\"bool\":{\"should\":[{\"exists\":{\"field\":\"_id\"}}],\"minimum_should_match\":1}}","kuery":{"expression":"_id:*","kind":"kuery"}}},"title":"stephbeat","sort":[{"columnType":"number","sortDirection":"desc","columnId":"@timestamp"}],"templateTimelineId":null,"templateTimelineVersion":null,"dateRange":{"start":"2021-11-18T07:00:00.000Z","end":"2021-11-20T06:59:59.999Z"},"indexNames":["stephbeat-*"],"eqlOptions":{"tiebreakerField":"","size":100,"query":"","eventCategoryField":"event.category","timestampField":"@timestamp"},"created":1637592218704,"createdBy":"smilovic","updated":1637592218704,"updatedBy":"smilovic","savedQueryId":null,"dataViewId":null,"eventNotes":[],"globalNotes":[],"pinnedEventIds":[]}

  1. Click timeline with title wonderful timeline
  2. Click Update available in the Data view dropdown
  3. Click Update and recreate data view
  4. Click Add index pattern
  5. A toast with the following message will appear One or more settings require you to reload the page to take effect
  6. Click Reload page in the toast message

Current behavior:

Expected behavior:

Additional information:

elasticmachine commented 2 hours ago

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

elasticmachine commented 2 hours ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 2 hours ago

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)