-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] .caseless fields are missing in .siem-signals mapping #110130
Comments
Pinging @elastic/security-detections-response (Team:Detections and Resp) |
Pinging @elastic/security-solution (Team: SecuritySolution) |
Is the Also what about this issue? It looked like the endpoint uses different data driven values vs. using the caseless version from ECS that already exists |
@FrankHassanabad |
@deepikakeshav-qasource please validate the fix of this issue on the current BC. Thanks |
Hi @MadameSheema , We have validated this ticket on 7.15.0 BC6 build and Please find the below observations: Build Details:
Observations:
host.os.name.caseless_close.all.mp4
host.os.name.caseless_close.all_rule_exception.mp4
close_this_alert1.mp4
Please let us know if we are missing anything or anything else is required to be tested. Thanks!! |
As per the comments on #111455 the results are expected. Thanks @deepikakeshav-qasource |
Overview
There are no
.caseless
fields currently present in the.siem-signals
mapping. This has already caused some issues dealing with exceptions but has the potential to cause other broken queries that won't work against the.siem-signals
indexSpecific discovery case
Currently the
host.os.name.caseless
is not mapped within.siem-signals
index. When creating or updating an endpoint exception, if a user checks the bulk close option, the query does not perform as expected. It should filter byhost.os.type
orhost.os.name.caseless
, but some alerts do not contain theos.type
field. If that is the case, the query and expected output will silently fail as no alerts will be found because the query is sent to the.siem-signals
index which doesn't contain thecaseless
field mapping.In order to reproduce:
os.type
field (pre 7.15 endpoint version).siem-signals
The text was updated successfully, but these errors were encountered: