You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When exporting an alert into a case, the tags included within the observables are not imported into the case. For example, an alert could be generated with the observable 8[.]8[.]8[.]8 and tag 'IP'. When the alert is imported into a Hive case, the tags from the observables are removed. See images below.
Steps to Reproduce
Create an alert with an alert artifact that uses tags
View the alert and import into a Hive case
Complementary information
Screenshot one shows the artifacts with tags inside of an alert:
Screenshot two shows that once imported, the artifact tags are removed:
The text was updated successfully, but these errors were encountered:
Request Type
Bug
Work Environment
Problem Description
When exporting an alert into a case, the tags included within the observables are not imported into the case. For example, an alert could be generated with the observable 8[.]8[.]8[.]8 and tag 'IP'. When the alert is imported into a Hive case, the tags from the observables are removed. See images below.
Steps to Reproduce
Complementary information
Screenshot one shows the artifacts with tags inside of an alert:
Screenshot two shows that once imported, the artifact tags are removed:
The text was updated successfully, but these errors were encountered: