-
Notifications
You must be signed in to change notification settings - Fork 8.2k
Issues: elastic/kibana
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
[Security Solution] Required fields are getting erased on rule PATCH
8.17 candidate
bug
Fixes for quality problems that affect the customer experience
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
triage_needed
#199665
opened Nov 11, 2024 by
xcrzx
[Security Solution] Rules mistakenly marked as customized
8.17 candidate
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
impact:high
Addressing this issue will have a high level of impact on the quality/strength of our product.
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.16.1
v8.17.0
v9.0.0
#199629
opened Nov 11, 2024 by
xcrzx
[Security Solution] Add support for editing prebuilt rules to the Rule Editing page
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.17.0
v9.0.0
[Security Solution] Fixes multi-line diff algorithm performance in the Backport to applied version labels
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.16.1
v8.17.0
v9.0.0
upgrade/_review
endpoint
backport:version
#199388
opened Nov 7, 2024 by
dplumlee
Loading…
1 of 4 tasks
[Security Solution] Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
impact:critical
This issue should be addressed immediately due to a critical level of impact on the product.
performance
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.16.1
v8.17.0
v9.0.0
upgrade/_review
blocks main thread
8.17 candidate
bug
#199290
opened Nov 7, 2024 by
xcrzx
[Security Solution] Add EQL query editable component with EQL options fields
backport:version
Backport to applied version labels
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.17.0
v9.0.0
#199115
opened Nov 6, 2024 by
maximpn
Loading…
[Security Solution] Security Solution Prebuilt Detection Rules
performance
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
/upgrade/_perform
performance improvements
Feature:Prebuilt Detection Rules
#199101
opened Nov 6, 2024 by
xcrzx
[Security Solution] Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Feature:Rule Exceptions
Security Solution Rule Exceptions feature
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#198845
opened Nov 4, 2024 by
pborgonovi
[Security Solution] Error when upgrading a rule that has an action referencing a deleted connector
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Feature:Rule Actions
Security Solution Rule Actions feature
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
needs product
sdh-linked
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#198771
opened Nov 4, 2024 by
banderror
[Security Solution] Add Alert Suppression editable component
backport:prev-minor
Backport to (8.x) the previous minor version (i.e. one version back from main)
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.17.0
v9.0.0
#198673
opened Nov 1, 2024 by
maximpn
Loading…
Authorized route migration for routes owned by security-detection-rule-management
Authz: API migration
backport:prev-minor
Backport to (8.x) the previous minor version (i.e. one version back from main)
enhancement
New value added to drive a business result
Feature:Security/Authorization
Platform Security - Authorization
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
#198383
opened Oct 30, 2024 by
kibanamachine
Loading…
[Security Solution] Allows editing and exporting prebuilt rules from the Rule Management and Rule Details pages
backport:version
Backport to applied version labels
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
release_note:skip
Skip the PR/issue when compiling release notes
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.17.0
v9.0.0
#198202
opened Oct 29, 2024 by
dplumlee
Loading…
13 tasks done
[Security Solution] [Detection Engine] Rule skipped due to use of data view message is displayed when an existing index pattern is selected to be added with Bulk Actions
bug
Fixes for quality problems that affect the customer experience
impact:low
Addressing this issue will have a low level of impact on the quality/strength of our product.
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
triage_needed
#197739
opened Oct 24, 2024 by
pborgonovi
[Security Solution] Detection Rules fail to install/update with basic license
bug
Fixes for quality problems that affect the customer experience
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
triage_needed
#197246
opened Oct 22, 2024 by
syk-99
[Security Solution] Rule Management tests shouldn't access system indices directly
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
test
#197110
opened Oct 21, 2024 by
banderror
Failing test: Rules Management - Prebuilt Rules Management Integration Tests - ESS Env - Trial License.x-pack/test/security_solution_api_integration/test_suites/detections_response/rules_management/prebuilt_rules/management/trial_license_complete_tier/bootstrap_prebuilt_rules·ts - Rules Management - Prebuilt Rules - Prebuilt Rules Management @ess @serverless @skipInServerlessMKI Bootstrap Prebuilt Rules should skip installing fleet packages if they are already installed
8.17 candidate
failed-test
A test failure on a tracked branch, potentially flaky-test
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#197108
opened Oct 21, 2024 by
kibanamachine
[Security Solution] Remove the banner promoting a blog post about the new and existing detection capabilities
8.17 candidate
Feature:Rule Management
Security Solution Detection Rule Management
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
v8.17.0
#197024
opened Oct 21, 2024 by
banderror
Failing test: Rules Management - Rule Bulk Actions Integration Tests - ESS Env - Trial License.x-pack/test/security_solution_api_integration/test_suites/detections_response/rules_management/rule_bulk_actions/trial_license_complete_tier/perform_bulk_action_ess·ts - Rules Management - Rule Bulk Action API @ess perform_bulk_action - ESS specific logic should disable rules and migrate actions
8.16 candidate
failed-test
A test failure on a tracked branch, potentially flaky-test
Feature:Rule Management
Security Solution Detection Rule Management
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#196462
opened Oct 16, 2024 by
kibanamachine
[Security Solution] Unskip tests for preventing non-customizable fields from updating for Prebuilt rule types
8.17 candidate
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
skipped-test
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#195921
opened Oct 11, 2024 by
banderror
[Security Solution] Cannot enable more than 1000 detection rules at once
bug
Fixes for quality problems that affect the customer experience
Feature:Rule Management
Security Solution Detection Rule Management
impact:low
Addressing this issue will have a low level of impact on the quality/strength of our product.
needs design
needs product
sdh-linked
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#195805
opened Oct 10, 2024 by
banderror
[Security Solution] Create asynchronous rules import API
8.17 candidate
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Feature:Rule Import/Export
Security Solution Rule Import & Export
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#195633
opened Oct 9, 2024 by
banderror
[Security Solution] Benchmark performance of importing a large number of prebuilt rules
8.17 candidate
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Feature:Rule Import/Export
Security Solution Rule Import & Export
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#195632
opened Oct 9, 2024 by
banderror
[Security Solution] Duplicating OOTB Prebuilt Security Rules for ES|QL Require Query Metadata
bug
Fixes for quality problems that affect the customer experience
Feature:Rule Management
Security Solution Detection Rule Management
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
triage_needed
#194724
opened Oct 2, 2024 by
terrancedejesus
[Security Solution] Create types or tests to link Rule Schema and Diffable Rule schema
8.18 candidate
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
#194484
opened Sep 30, 2024 by
jpdjere
[Security Solution] Replace Security Solution Detection Rule Details
Feature:Rule Monitoring
Security Solution Detection Rule Monitoring
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
technical debt
Improvement of the software architecture and operational architecture
MultiselectFilter
in Rule Monitoring with a component from common directory
Feature:Rule Details
#194301
opened Sep 27, 2024 by
nikitaindik
Previous Next
ProTip!
Find all open issues with in progress development work with linked:pr.