Description
openedon Feb 15, 2024
Description
Using the "Correlation View" in the Knowledge Graphs (I tried Analysis Reports, not sure if this problem is across all data types with these graphs), multiple reports I have that show "Correlated reports" in the Overview no longer render these correlations in the Knowledge->Correlation View visualization. Not sure why, but it appears some data is missing from the data selection. I did find one report that does show a single correlating observable with two reports, but Overview for that one lists multiple correlations. Additionally, when viewing the correlated report shown in that graph, its knowledge->correlation graph is empty.
Environment
- OS (where OpenCTI server runs): Linux w/ Docker
- OpenCTI version: 5.12.31
- OpenCTI client: Frontend
- Other environment details: Docker-compose - https://github.com/ckane/opencti-docker/tree/tf-main
Reproducible Steps
Look at overview in analysis reports, find one with correlated reports, view knowledge->correlation, see no graph linking the correlations
Expected Output
Display of graph linking correlations as shown on Overview page
Actual Output
Nothing, or very sparse information. Inconsistency between reports where one shows a rendered correlation, but visiting its correlating report shows an empty graph.
Verified that the normal "Graph view" does render entities
Screenshots (optional)
Example 1:
One report with two correlations listed:
Looking at its Knowledge->Correlation view - nothing:
Example 2:
Shows 2 correlations, but nothing in the Knowledge->Correlation view:
If I click on the report above from AhnLab, I also see correlations, one of which is the report from the above screenshot:
Looking at the AhnLab report's correlation view, you can see that the CUDESO report (Zip uploaded...) is rendered, but none of the DIGITALSIDE.IT malware report links are rendered in this chart:
So, the behavior appears to be missing data, but also seems to inconsistently be working (because it shows one other correlation from one report, but none when viewing from the same correlated report that is displayed here).