Skip to content

[Security Solution][Exceptions][Bug] - Error when importing rules with exception lists that don't exist in space #75182

@yctercero

Description

@yctercero

Kibana version: 7.9

Describe the bug:
When importing rules that include references to exception lists that are either 1) deleted or 2) do not exist in imported space, user is unable to add or view exceptions of imported rule.

Rule itself imports successfully.

Steps to reproduce:

  1. Export a rule that includes exceptions.
  2. Delete exceptions list (via API) OR import rule into different space
  3. Import rule
  4. Navigate to imported rule's exceptions tab
  5. See that exceptions fail to fetch
  6. Click to add exception
  7. See error message in modal

Expected behavior:
This is a case of both a missing feature and an existing bug. There is not yet a great way to export exception lists (feature), but if user tries to import a rule with reference to an exception list that does not exist (bug), we should alert the user with an error to allow them to rectify.

Screenshots (if relevant):
ezgif com-optimize

Workaround:
Workaround right now is to export rule --> delete the reference to exception list -> import rule --> add back reference via API or manually re-input exceptions.

Metadata

Metadata

Assignees

Labels

Feature:Detection RulesSecurity Solution rules and Detection EngineTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:SIEMbugFixes for quality problems that affect the customer experiencev7.9.1

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions