[Security Solution] Fields with more than one value may display different Alert prevalence
counts in the alert flyout vs a timeline
#131967
Labels
bug
Fixes for quality problems that affect the customer experience
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Team:Threat Hunting:Investigations
Security Solution Investigations Team
Team:Threat Hunting
Security Solution Threat Hunting Team
Summary
Fields with more than one value may display different
Alert prevalence
counts in the alert flyout vs a timelineBackground
#131255 adds the
Investigate in timeline
action to theAlert prevalence
column of theHighlighted fields
table in the alert flyout, as shown in the screenshot below:Fields that typically have just one value, like
process.name
, consistently display the same alert counts in both theAlert prevalence
column in the flyout, and in a timeline when theInvestigate in timeline
action is performed by clicking the hover action next to the count.Fields that have more than one value sometimes display different counts between the flyout and Timeline.
Example: The
process.args
in the sample JSON below contains two values:In the video below:
process.args
field displays570
in theAlert prevalence
column in the flyout285
alerts when theInvestigate in timeline
action is invokedprocess_args.mov
Kibana/Elasticsearch Stack version:
8.3.0
Steps to reproduce:
Navigate to the
Alerts
page in the Security SolutionAdd the following query to the search bar to filter for
process
events whereprocess.args
exists:Keep clicking the
View details
action on alerts in the table until an alert that has multiple values for theprocess.args
field is displayed in the alerts flyoutFor a field with a single value, like
process.name
, click theInvestigate in timeline
action next to the count in theAlert prevalence
columnExpected result
Alert prevalence
count displayed in the flyout exactly matches the count displayed in Timeline'sQuery
tabClose timeline
In the alerts flyout, click the click the
Investigate in timeline
action next to theprocess.args
column, which contains multiple valuesExpected result
Alert prevalence
count displayed in the flyout exactly matches the count displayed in Timeline'sQuery
tabActual result
process_args.mov
The text was updated successfully, but these errors were encountered: