Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solutions][Timeline] Extra fields values showing up in timeline details view #91426

Closed
FrankHassanabad opened this issue Feb 15, 2021 · 5 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience Feature:Timeline Security Solution Timeline feature fixed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.11.2 v7.12.0

Comments

@FrankHassanabad
Copy link
Contributor

FrankHassanabad commented Feb 15, 2021

Kibana version:
7.11.BC1

Describe the bug:
When you select one of the events you see extra values showing up in the details view and in the table view which are marked as "fields" but I think this is part of the query results and not the actual contents of the data and should be filtered out.

Expected behavior:
There shouldn't be any fields values.

fields_bug_1

Original install method (e.g. download page, yum, from source, etc.):
cloud

Steps to reproduce:

  1. Provision 7.11.BC1
  2. Add auditbeat data
  3. Select any events and notice the fields extra's
@FrankHassanabad FrankHassanabad added bug Fixes for quality problems that affect the customer experience triage_needed Team:Threat Hunting Security Solution Threat Hunting Team Feature:Timeline Security Solution Timeline feature labels Feb 15, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@FrankHassanabad FrankHassanabad changed the title [Security Solutions][Timeline] Extra fields values showing up in details view [Security Solutions][Timeline] Extra fields values showing up in timeline details view Feb 15, 2021
@MadameSheema
Copy link
Member

@karanbirsingh-qasource can you please validate the fix of this issue on 7.11.2BC2 and 7.12BC3? Thanks :)

@MadameSheema MadameSheema added fixed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Mar 9, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@ghost
Copy link

ghost commented Mar 10, 2021

Hi @MadameSheema

We have validated this issue on 712.0 B3 Cloud and 7.11.2 BC2 Cloud and found it Fixed . Now on the right detail flyout table and json view no extra "fields" [ for eg. fields.timestamp , fields.agent.id ..) are present .

Build Details:

Version: 7.12.0 BC3
Commit: 08417cbd6c15e4c866651a7dcdfeded58845206d
Build:39134

Version: 7.11.2 BC2
Commit:bdba929767160a3272f5144acd9270d7bdaaea7c
Build:38015

Snapshot:

  • 7.12.0
    image

  • 7.11.2
    image

Please let us known if something more to be checked for this issue . Else we are good to add "QA Validated" to it.

thanks !!

@ghost
Copy link

ghost commented Mar 26, 2021

Bug conversion:

Created 01 new Test-Case for this Ticket under Bug Conversion task:
https://elastic.testrail.io/index.php?/cases/view/76925

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Timeline Security Solution Timeline feature fixed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Threat Hunting Security Solution Threat Hunting Team v7.11.2 v7.12.0
Projects
None yet
Development

No branches or pull requests

4 participants