-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] Enriched fields are not displayed on the alert timeline view #119633
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
Pinging @elastic/security-detections-response (Team:Detections and Resp) |
the linked PR has been merged. Could you verify that the fix works? Happy to close the issue upon your confirmation. |
Hi @ecezalp!! I checked the issue, is fixed!! I'll add the I have created a PR in order to unskip the Thanks!! :) |
@deepikakeshav-qasource can you please validate this on the latest 8.0.0 snapshot? Thanks! |
Hi @MadameSheema , We have validated this issue on latest 8.0.0 SNAPSHOT. Please find the below observations: Build Details:
Please let us know if anything else is need to be test. else we are good to close this issue. Thanks!! |
thank you @deepikakeshav-qasource! Observed behavior is expected. If an event is enriched in 7.16 it will have threat.indicator fields. if it is enriched in 8.0 it will have threat.enrichments fields. the most important part of this work is that the JavaScript error is no longer present with the CTI row renderer. Are you able to verify that there are no javascript errors when a CTI event is viewed on timeline (with the CTI row renderer?) Once we have confirmation of that we should be good to close. |
@deepikakeshav-qasource can you please verify @ecezalp request on 8.0.0-rc1? Thanks! |
Hi @MadameSheema and @ecezalp We have validated this issue on 8.0.0-rc1 production and observed that no java script error is displayed. Please find the below testing details: Build Details:
Screen record: indicator.mp4Please let us know if we are missing anything Thanks!! |
Describe the bug:
Enriched fields are not displayed on the alert timeline view
Kibana/Elasticsearch Stack version:
main (c6f491c)
Steps to reproduce:
Current behavior:
threat.indicator.matched*
fields are availableExpected behavior:
The text was updated successfully, but these errors were encountered: