Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution]Rule Action not able to perform after deletion of Rule Action Connector #126756

Closed
karanbirsingh-qasource opened this issue Mar 3, 2022 · 13 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience Feature:Rule Actions Security Solution Rule Actions feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detections and Resp Security Detection Response Team Team:Security Solution Platform Security Solution Platform Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@karanbirsingh-qasource
Copy link

karanbirsingh-qasource commented Mar 3, 2022

Describe the bug
Rule Action not able to perform after deletion of Rule Action item

Build Details

Version:8.1.0 BC5
Commit:23423b0db7d5ffae1d0578e8d9e2c1afab90cdcf
Build:50459

Pre-Condition

  • kibana Version 8.1.0 BC5 should exist
  • Any Connector should be present on the kibana

Steps

  • Login to Kibana
  • Navigate to Alert Page
  • Add any rule action item let say swim lane to the rule as a rule action item
  • Generate some alerts from above rule
  • Now delete the rule action item from stack management in our case it is swim lane
  • Come back to rule details page
  • Perform rule action like Enable,Disable and Duplicate
  • Observed user is not able to perform any of the above mentioned operation of rule after deleting the rule action on it

Screen-Cast

rule-action.mp4
@karanbirsingh-qasource karanbirsingh-qasource added bug Fixes for quality problems that affect the customer experience triage_needed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Mar 3, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@karanbirsingh-qasource karanbirsingh-qasource added the impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. label Mar 3, 2022
@MadameSheema
Copy link
Member

@karanbirsingh-qasource can you please confirm if the action can be done after refreshing the page?

@karanbirsingh-qasource
Copy link
Author

yes @MadameSheema I have tried hard refresh and also opening kibana login in private windows, the error is consistent

image

@karanbirsingh-qasource
Copy link
Author

more to add we have found one related issue in which there have some changes done in rule action item is the user after delete the added connector , if it helps to troubleshoot

#89062

@MadameSheema
Copy link
Member

@karanbirsingh-qasource can you please check if this is happening on 7.17.x and 8.0.x? Thanks :)

@karanbirsingh-qasource
Copy link
Author

sure @MadameSheema

@MadameSheema MadameSheema added the Team:Detections and Resp Security Detection Response Team label Mar 3, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@karanbirsingh-qasource
Copy link
Author

Issue occuring on 7.17.0

7.17.0.mp4

@karanbirsingh-qasource
Copy link
Author

issue occurring on 8.0.0

8.0.0.mp4

@peluja1012
Copy link
Contributor

Hi @karanbirsingh-qasource, I'm a little bit confused a about the steps followed to reproduce this bug. Could you please send us a video that shows you running through these steps?

Login to Kibana
Navigate to Alert Page
Add any rule action item let say swim lane to the rule as a rule action item
Generate some alerts from above rule
Now delete the rule action item from stack management in our case it is swim lane
Come back to rule details page

@peluja1012 peluja1012 added the Team:Security Solution Platform Security Solution Platform Team label Mar 3, 2022
@karanbirsingh-qasource
Copy link
Author

Hi @karanbirsingh-qasource, I'm a little bit confused a about the steps followed to reproduce this bug. Could you please send us a video that shows you running through these steps?

Login to Kibana
Navigate to Alert Page
Add any rule action item let say swim lane to the rule as a rule action item
Generate some alerts from above rule
Now delete the rule action item from stack management in our case it is swim lane
Come back to rule details page

Sure @peluja1012 please find below screen-cast of the above written steps , however just to clear the issue is "User is not able to perform Rule Action Duplicate,Enable,Disable if user delete the added rule action item(Notification component of the rule) in it"

Rule-Actions-Second.mp4

@peluja1012 peluja1012 added Feature:Rule Actions Security Solution Rule Actions feature and removed triage_needed labels Mar 4, 2022
@peluja1012
Copy link
Contributor

@MadameSheema I believe this bug is a duplicate of this bug, which you filed a few months back: #69142. I think impact is correct as there is a workaround for it. The proper treatment is probably to warn users before deleting connectors that there are rules associated with them.

@peluja1012 peluja1012 changed the title [Security Solution]Rule Action not able to perform after deletion of Rule Action item [Security Solution]Rule Action not able to perform after deletion of Rule Action Connector Mar 4, 2022
@MadameSheema
Copy link
Member

Closing as duplicate of #69142

cc @yctercero

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Rule Actions Security Solution Rule Actions feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detections and Resp Security Detection Response Team Team:Security Solution Platform Security Solution Platform Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

5 participants