Skip to content

[Security Solution] [Detection Engine] System Action is duplicated when using bulk actions to add rule actions #191512

Open

Description

Describe the bug:
System Action is duplicated when using bulk actions to add rule actions

Kibana/Elasticsearch Stack version:
8.16 SNAPSHOT

Server OS version:

Browser and Browser OS versions:

Elastic Endpoint version:

Original install method (e.g. download page, yum, from source, etc.):

Functional Area (e.g. Endpoint management, timelines, resolver, etc.):

** Pre conditions:**

  1. Have more than 1 rule
  2. Have at least 1 rule configured with System Action

Steps to reproduce:

  1. Bulk actions to add rule actions
  2. Select Case option
  3. Add the system action
  4. Validate the rules actions

Current behavior:
System Action is duplicated when using bulk actions to add rule actions. When trying to edit the rule and save it, there's an error saying no duplicated system actions are allowed. No duplicate cases are created though

Expected behavior:
System Action should not be duplicated

Screenshots (if relevant):

System.Actions_Duplicated.bulk.actions.mov

Errors in browser console (if relevant):

Provide logs and/or server output (if relevant):

Any additional context (logs, chat logs, magical formulas, etc.):

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Assignees

Labels

8.16 candidateFeature:Rule ActionsSecurity Solution Rule Actions featureTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection EngineSecurity Solution Detection Engine AreaTeam:Detections and RespSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions