Skip to content

Advanced Policy UI in Endpoint Security should delete empty entries in Package Policy #84127

@kevinlog

Description

@kevinlog

Kibana version:
7.11, 8.0

Elasticsearch version:
7.11, 8.0

Describe the bug:
The Advanced Policy UI leaves behind empty fields in the Package Policy which can pollute the Policy that is sent to the Endpoint. It should delete empty fields in the Advanced section of the Endpoint Package Policy.

Steps to reproduce:

  1. Create Endpoint Policy
  2. Navigate to the Endpoint Policy and add a value to an Advanced field in the UI and save. See that the value is reflected in the Package Policy in Fleet
  3. Return to the Endpoint Policy and remove the field previously added. Save. See that the value is still present in the Policy in Fleet, but it's empty.

Expected behavior:
If the value is empty, it should be completely removed from the Policy sent to the Endpoint.

Screenshots (if relevant):

Here is the Policy with an advanced field added:
image

After removing the value via the UI, the field is still present, but empty. It should be removed entirely.
image

Advanced policy fields are added here:
image

Metadata

Metadata

Assignees

Labels

Feature:PolicySecurity Solution Policy featureQA:ValidatedIssue has been validated by QATeam:Defend Workflows“EDR Workflows” sub-team of Security SolutionbugFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.v7.11.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions