Skip to content

[BUG]: "Indexes" field in "Create threat detector" flow gives a wrong impression that user can use frontend index patterns as a source for threat detection. #995

Open
@xeniatup

Description

What is the bug?
The "Indexes" field in "Create threat detector" flow gives a wrong impression that user can use frontend index patterns as a source for threat detection.
https://playground.opensearch.org/app/opensearch_security_analytics_dashboards#/create-detector

Screenshot 2024-04-25 at 3 02 30 PM

What is the expected behavior?
To clarify the meaning of the field, the field label should be Select or input source indexes or aliases, and the helper text underneath the input should clarify that user can enter * as a wildcard pattern to match multiple indexes as Use * as a wildcard pattern to match multiple sources.

Screenshot 2024-04-25 at 3 04 08 PM

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions