Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Error is displayed when trying to add exception to an alert triggered by a deleted Rule #81303

Open
MadameSheema opened this issue Oct 21, 2020 · 1 comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Rule Exceptions Security Solution Rule Exceptions feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. needs design Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@MadameSheema
Copy link
Member

Bug originally reported by: @karanbirsingh-qasource

Description
Descriptive Error Message is not displayed while adding Exception of deleted Detection Rules

Environment Detail
7.9.0 BC6

Browser: All

Preconditions

  1. Deploy the ES Cloud Build with 7.9 version selected from General Available versions.

Steps to Reproduce

  1. Navigate to 'Security' panel from the Kibana left navigation bar.
  2. Enable Elastic Endpoint Security pre-built rule.
  3. Trigger mimikatz on windows Endpoint.
  4. Alert show under Alert List on Detection page.
  5. Delete the Elastic Endpoint Security pre-built rule.
  6. Click on 'Add Exception' option from more action overview for alert triggered in step 4
  7. Observed that error "Error fetching exception list" is displayed.

Test data
N/A

Impacted Test case id
N/A

Actual Result
"Error Fetching Exception List" error message is displayed on Adding exception

Expected Result
Descriptive error message should be displayed while adding Exception of deleted Detection Rules

What's working

  • N/A

What's not working

  • N/A

Screenshot

image

Logs
N/A

@MadameSheema MadameSheema added bug Fixes for quality problems that affect the customer experience Team:Detections and Resp Security Detection Response Team labels Oct 21, 2020
@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
@peluja1012 peluja1012 added the impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. label Oct 28, 2020
@peluja1012 peluja1012 added the Feature:Rule Exceptions Security Solution Rule Exceptions feature label Nov 17, 2020
@marrasherrier
Copy link
Contributor

marrasherrier commented Nov 19, 2020

Figma

@dontcallmesherryli dontcallmesherryli added loe:needs-research This issue requires some research before it can be worked on or estimated needs design and removed loe:needs-research This issue requires some research before it can be worked on or estimated labels Apr 14, 2021
@peluja1012 peluja1012 added the Team:Detection Alerts Security Detection Alerts Area Team label Sep 15, 2021
@marshallmain marshallmain added Team:Security Solution Platform Security Solution Platform Team and removed Team:Detection Alerts Security Detection Alerts Area Team labels Apr 14, 2022
@yctercero yctercero added Team:Detection Engine Security Solution Detection Engine Area and removed Team:Security Solution Platform Security Solution Platform Team labels May 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Rule Exceptions Security Solution Rule Exceptions feature impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. needs design Team:Detection Engine Security Solution Detection Engine Area Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

7 participants