Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Detections] Add Endpoint Exception modal on Detection Rule page does not allow choosing OS #78604

Closed
marshallmain opened this issue Sep 28, 2020 · 2 comments
Labels
Feature:Detection Rules Security Solution rules and Detection Engine Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM

Comments

@marshallmain
Copy link
Contributor

marshallmain commented Sep 28, 2020

The "Add Endpoint Exception" modal does not mention that the exception will only be sent to endpoints of the same os family (windows, linux, or mac) as the endpoint that an alert came from, nor is there a way to choose the OS when adding an endpoint exception from the Detection Rule page (i.e. without an alert to base the exception on). Instead the OS defaults to Windows and macOS. Endpoint exceptions are OS specific so this should be clear in the UI and selectable if creating an endpoint exception from scratch.

@marshallmain marshallmain added Team:SIEM Feature:Detection Rules Security Solution rules and Detection Engine labels Sep 28, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
@peluja1012
Copy link
Contributor

This is fixed by #103404

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature:Detection Rules Security Solution rules and Detection Engine Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM
Projects
None yet
Development

No branches or pull requests

4 participants