wazuh / wazuh-splunk

Wazuh - Splunk App
https://wazuh.com
GNU General Public License v2.0
49 stars 27 forks source link

wazuh 4.2.2 compatibility with splunk 8.2.2 #1116

Closed MauGaP closed 3 years ago

MauGaP commented 3 years ago

In order to verify the quality of the new release we need to execute the following tasks:

frankeros commented 3 years ago

Bug

RC Splunk Severity
1 8.2.2 Stopper

Description

Opening the Quick settings modal does not work.

This happen after include JQuery as param in wz-table-directive.js and wz-table-server-side-directive.js to upgrade JQuery to 3.5.0

image

Note

Removing this param from the such files the modal opens properly, but the jQuery version is downgraded to 2.1.0

image

CPAlejandro commented 3 years ago

Current feedback

I have found this bugs:

Despite the fact of these bugs, I continue doing the testing for Wazuh 4.2.2, Splunk 8.2.2 and Firefex as navegator.

mpRegalado commented 3 years ago

Completed tests on chrome browser

Overview

Overview - Security events

Overview - Integrity monitoring

Overview - Amazon AWS

Managment - Ruleset

Managment - Configuration

On narrow viewports, when the manager name is long and does not contain spaces or -, the lack of line breaks causes it to overflow onto the next element image

Managment - Status

Managment - Logs

Managment - Reporting

Agent section - Integrity Monitoring

When the viewport width is narrow enough, the gear icon overlaps with the columns

image

No results are shown in the dashboard, it needs further investigating to rule out issues with the test environment itself. Only noticed the issue in a Ubuntu agent, while a windows agent seems to show alerts correctly image image

mpRegalado commented 3 years ago

Completed tests on chrome browser

Managment - Cluster

Agents

Agent Details

Agent section - Integrity Monitoring

When the viewport is narrow enough for the buttons in the visualizations to overlap the timestamp, the heights of all visualizations no longer match image

Agent section - Security events

Agent section - Security events

Agent section - Inventory data

Agent section - Configuration

Documentations link in this section lead to documentation of version 2.1 or to 404 errors

  • [x] Generate PDF
  • [x] Configuration / Main configuration sections
  • [x] Configuration / System threats and incident response sections
  • [ ] Refreshing from within a subsection Refreshing the page leads back to the configuration page rather than the subsection
  • [x] Upon entering log collection
  • [x] Upon entering entegrity monitoring

Agent section - Policy monitoring

Agent section - SCA

Agent section - System auditing

Agent section - CIS-CAT

Agent section - Vulnerabilities

Agent section - Virustotal

Agent section - Osquery

Agent section - PCI DSS

Agent section - GDPR

Discover

Error common.js:489 GET http://localhost:8000/en-US/splunkd/__raw/servicesNS/admin/search/data/ui/prefs/search?output_mode=json&_=1631874697680 404 (Not Found) upon entering

  • [x] Switch between Fast/Smart/Verbose Mode
  • [ ] Statics or Visualization -> Pivot There is a blank space between the menu and the content image
mpRegalado commented 3 years ago

I could no longer replicate the issues with Discover on console

MauGaP commented 3 years ago

We finished executing the regression and the issues found have been added to the backlog.