-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution][Event Correlation][Sequence]Investigate in timeline returning no result #120898
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
Reviewed & assigned to @MadameSheema |
@karanbirsingh-qasource can you please let us know which data views were selected in the timeline? Thanks |
@karanbirsingh-qasource can you please take the same screenshot after clicking on Advanced options in order to see the data views? thank you |
Sure @MadameSheema please find below the required screen-cast sequence.mp4 |
@karanbirsingh-qasource can you please validate the fix on the latest 8.0.0? Thanks! |
We have validated this issue on 8.0.0-Branch and found that issue is still occuring 🔴 . Build Details:
Screen-Cast: correlation.mp4thanks !! |
@karanbirsingh-qasource the fix was validated with the snapshot or with the latest 8.0 branch? |
Latest 8.0 branch @MadameSheema |
@karanbirsingh-qasource can you please check if the issue you are facing now could be related to the following one? #122958 Thanks! |
@MadameSheema i have checked this issue and its been present on old builds too as in 7.16.3 so i am not sure this #122958 can be the reason for this issue . However we will be keeping any eye on this issue too. |
@karanbirsingh-qasource can you please check it again on 8.0 and also in main branch? Thanks |
HI @MadameSheema issue is still occuring on 8.0.0-SNAPSHOT and main branch too.
event.mp4
|
The current behavior of the above issue has changed. Now we display an alert but we don't display the sequence as a block since we are not filtering by the expected group id value. This is directly related with #123370 |
@deepikakeshav-qasource @manishgupta-qasource can you please help to coordinate the testing of this on 8.0 latest branch? This is top priority, thanks :) |
We have validated this issue on 8.0.0 branch and observed that issue is still Occurring. Please find below testing details: Build Details:
Screencast: eql_rule.mp4Thanks!! |
@deepikakeshav-qasource if you create a new timeline to clear out any existing results and then open an eql sequence, does the data appear? |
@kqualters-elastic I think it could be related to a different issue we are facing in new environments where the |
Hi @MadameSheema & @kqualters-elastic we have validated this issue on 8.0 Branch as well as 8.0.0-RC2-BC2 and found it fixed 🟢 . please find below details: Build Details:
Branch: Screen-Cast actual-Fixed.mp4Hence we are closing this issue. thanks !! |
Describe the bug
[Event Correlation][Sequence]Investigate in timeline returning no result
Build Details
Steps
sequence [ process where process.name == "cmd.exe" ] [ process where process.name == "notepad.exe" ]
Whats Working
Issue is not occuring for single EQL Query
working.mp4
Screen-cast
timeline.mp4
issue-another.mp4
Extra
JSON for Sequence Alert
The text was updated successfully, but these errors were encountered: