elastic / kibana

Your window into the Elastic Stack
https://www.elastic.co/products/kibana
Other
19.7k stars 8.24k forks source link

[Defend Workflows] SentinelOne response actions failing with error: `Response validation failed (Error: [data.0.rangerVersion]: expected value of type [string] but got [null])` #202398

Open sukhwindersingh-qasource opened 2 days ago

sukhwindersingh-qasource commented 2 days ago

Describe the bug:

Build Details:

VERSION: 8.17.0 BC2
BUILD: 80427
COMMIT: 2421fb67e0069e7e2c3036cb4e9077fceb4a587a

Login Credentials

Preconditions

Steps to Reproduce

Whats not working :

Actual result

Expected Result

Screen-cast

Image

https://github.com/user-attachments/assets/dcf23ea2-5718-4adb-8d5b-50a4ac9da810

Logs

elasticmachine commented 2 days ago

Pinging @elastic/security-solution (Team: SecuritySolution)

elasticmachine commented 2 days ago

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

sukhwindersingh-qasource commented 2 days ago

@muskangulati-qasource Please review this

dasansol92 commented 2 days ago

Hey @sukhwindersingh-qasource , is this working as expected in previous stack versions? Thanks!

sukhwindersingh-qasource commented 1 day ago

Hi @dasansol92,

We tested this on the previous version using the same setup and VM. We observed that it is not working on 8.16.0. However, during the 8.16.0 release process, it was working on the same stack. We're not sure why it is no longer functioning in 8.16.0.

Additionally, there is another related ticket with a somewhat similar issue, although the error message differs. We also validated the fix for this issue on the serverless environment.

Build Details:

VERSION: 8.16.0
BUILD: 79644
COMMIT: a8a07dfc586d78b8f4b7997b00e126363d68c043

Screen cast :

https://github.com/user-attachments/assets/e9a4a32b-fe46-4045-be36-c5b6881a904e

Please let us know if anything else is required from our end.

Thanks!!

muskangulati-qasource commented 1 day ago

Secondary review is Done for this ticket!

paul-tavares commented 1 day ago

PR https://github.com/elastic/kibana/pull/202515

paul-tavares commented 1 day ago

Fix for this has been merged.