Skip to content

[Security Solution][Rule with Data View] Analyzer preview details not present under Visualization section of Alert Flyout #164829

Closed
@ghost

Description

Describe the bug:
[Rule with Data View] Analyzer preview details not present under Visualization section of Alert Flyout

Kibana/Elasticsearch Stack version
Version: 8.10.0 BC2
Commit: fa3473f
Build: 66107

Browser and Browser OS Version:
Firefox for windows OS
Version: 116.0.3

Elastic Endpoint Version:
v8.10.2

Original install method:
Build summary: https://staging.elastic.co/8.10.0-049269aa/summary-8.10.0.html

Functional Area:
Alert Flyout

Initial Setup:

  • Rule with Data View should be available with generated alert
  • Alert data should have associated analyzer present also

Steps to reproduce

  • Go to Alert generated from rule using data view not index pattern
  • click on view details
  • Expand visualizations section
  • observed no analyzer preview details

Additional Observation

  • Analyzer details are available in expanded alert fly out
  • Analyzer details are available in alert table

Current behavior

  • [Rule with Data View] Analyzer preview details not present under Visualization section of Alert Flyout

Expected behavior:

  • [Rule with Data View] Analyzer preview details should be present under Visualization section of Alert Flyout

Screen-Shot:

Detection.rules.SIEM.-.Kibana.Mozilla.Firefox.2023-08-25.16-06-06.mp4

image

Errors in browser console:

None

Any additional context (logs, chat logs, magical formulas, etc.):

None

Metadata

Labels

QA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Investigations TeambugFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions