-
Notifications
You must be signed in to change notification settings - Fork 69
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Security Analytics do not throw an error when incompatible detectorType is mentioned with detector rules #518
Labels
bug
Something isn't working
Comments
5 tasks
riysaxen-amzn
pushed a commit
to riysaxen-amzn/security-analytics
that referenced
this issue
Feb 20, 2024
* [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#491 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Provide empty states for Findings and Alerts page opensearch-project#471 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor and move field mapping to first the page of create detector feature opensearch-project#495 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#493 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#493 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor alert triggers per mocks opensearch-project#498 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#493 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create global state object for async requests opensearch-project#493 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor alert triggers per mocks opensearch-project#498 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Create detector \ Refactor alert triggers per mocks opensearch-project#498 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Update detector details component opensearch-project#502 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Update detector details component opensearch-project#502 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Update detector details component opensearch-project#502 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [FEATURE] Update detector details component opensearch-project#502 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * Feature] update detector details component opensearch-project#504 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * Feature] update detector details component opensearch-project#504 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * Update detector details component opensearch-project#504 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [BUG] No space between the detector details and the rule panel opensearch-project#522 [BUG] A rule flyout without references have an empty link opensearch-project#521 [FEATURE] Update header size to use euiTitle--small opensearch-project#520 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * [BUG] No space between the detector details and the rule panel opensearch-project#522 [BUG] A rule flyout without references have an empty link opensearch-project#521 [FEATURE] Update header size to use euiTitle--small opensearch-project#520 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * updated create detectors cypress specs Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * refactored util methods into cypress commands Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * refactored util methods into cypress commands Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> * cypress tests wait interval updated to 400 Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> --------- Signed-off-by: Jovan Cvetkovic <jovanca.cvetkovic@gmail.com> Signed-off-by: Amardeepsingh Siglani <amardeep7194@gmail.com> Co-authored-by: Amardeepsingh Siglani <amardeep7194@gmail.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
What is the bug?
We do not throw an error when incompatible
detectorType
is mentioned withdetector rules
.e.g.
How can one reproduce the bug?
Steps to reproduce the behavior:
detector_type
iswindows
while the rules are forad_ldap
category(security-analytics/src/main/resources/rules/ad_ldap/win_ldap_recon.yml
Line 2 in 6d49245
What is the expected behavior?
A clear and concise description of what you expected to happen.
What is your host/environment?
Do you have any screenshots?
If applicable, add screenshots to help explain your problem.
Do you have any additional context?
Add any other context about the problem.
The text was updated successfully, but these errors were encountered: