Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Platform] - Remove exceptions duplicates on rule export #116329

Closed
Tracked by #116336
yctercero opened this issue Oct 26, 2021 · 3 comments
Closed
Tracked by #116336
Assignees
Labels
bug Fixes for quality problems that affect the customer experience fixed Team:Security Solution Platform Security Solution Platform Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.16.0

Comments

@yctercero
Copy link
Contributor

Describe the bug:
If two rules refer to the same exception list, said exception list will be exported twice.

Kibana version:
7.16 (BC1/2)\

Expected behavior:
Exception lists which numerous rules point to should only be exported once.

@yctercero yctercero added bug Fixes for quality problems that affect the customer experience triage_needed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.16.0 Team:Security Solution Platform Security Solution Platform Team labels Oct 26, 2021
@yctercero yctercero self-assigned this Oct 26, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

yctercero added a commit that referenced this issue Nov 2, 2021
## Summary

Addresses #116329

Removes duplicate exception lists on rule export when multiple rules reference the same list.
kibanamachine pushed a commit to kibanamachine/kibana that referenced this issue Nov 2, 2021
## Summary

Addresses elastic#116329

Removes duplicate exception lists on rule export when multiple rules reference the same list.
kibanamachine pushed a commit to kibanamachine/kibana that referenced this issue Nov 2, 2021
## Summary

Addresses elastic#116329

Removes duplicate exception lists on rule export when multiple rules reference the same list.
kibanamachine added a commit that referenced this issue Nov 2, 2021
## Summary

Addresses #116329

Removes duplicate exception lists on rule export when multiple rules reference the same list.

Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com>
kibanamachine added a commit that referenced this issue Nov 2, 2021
## Summary

Addresses #116329

Removes duplicate exception lists on rule export when multiple rules reference the same list.

Co-authored-by: Yara Tercero <yctercero@users.noreply.github.com>
@yctercero yctercero added the fixed label Nov 5, 2021
@ghost
Copy link

ghost commented Nov 15, 2021

Hi @yctercero ,

We have validated this ticket on 7.16.0 BC4 On-Prem and found that issue is fixed. please find the below observations:

Build Details:

Version:7.16.0 BC4 ON-Prem
Build: 45952
COMMIT: e50bc2eded568ff3ceaebdbe616f84b3987be975

Observations:

  • Exception list count displayed once if rules contains same exception.
    image

  • Exception list count if rules contains different exception.
    image

  • Exception list count if two rules contains same exception and another rule contains different exception.
    image

We will verified this issue again, once the 7.16.0 BC4 is available on cloud.

Thanks!!

cc: @MadameSheema

@MadameSheema
Copy link
Member

Thanks @deepikakeshav-qasource! the platform does not affect on this behaviour, so we can close the ticket :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience fixed Team:Security Solution Platform Security Solution Platform Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.16.0
Projects
None yet
Development

No branches or pull requests

3 participants