Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution]Endpoint security not getting install until we add os query integrations #141036

Closed
ghost opened this issue Sep 20, 2022 · 5 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team:Defend Workflows “EDR Workflows” sub-team of Security Solution Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed

Comments

@ghost
Copy link

ghost commented Sep 20, 2022

Describe the bug
Endpoint security not getting install until we add os query integrations

Build Details:

VERSION: 8.5.0-SNAPSHOT
commit:189196181c975b620ab18ea9d7662aa38d0e9294
build:56410

Steps

  • Login to kibana deployment
  • Create new policy , add endpoint security integration
  • install the agent
  • Agent start showing on build with healthy status however no endpoint show on the build

image

  • now add os query integrations and observed that now endpoint start showing on the endpoint page

Note: On checking here there we have seen in above steps if you add the os query 2 integration after then after some time endpoint start reflect but after we face another issue after updating anything in policy it does not get saved

image

image

Screen-Shoot:

image

@ghost ghost added bug Fixes for quality problems that affect the customer experience triage_needed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Sep 20, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@ghost ghost added impact:critical This issue should be addressed immediately due to a critical level of impact on the product. Team:Defend Workflows “EDR Workflows” sub-team of Security Solution labels Sep 20, 2022
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-onboarding-and-lifecycle-mgt (Team:Onboarding and Lifecycle Mgt)

@muskangulati-qasource muskangulati-qasource added impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. and removed impact:critical This issue should be addressed immediately due to a critical level of impact on the product. labels Sep 20, 2022
@ghost ghost assigned kevinlog Sep 20, 2022
@kevinlog
Copy link
Contributor

@karanbirsingh-qasource I think this may be related to this open issue: elastic/fleet-server#1877

There is a known bug with the Agent installing Endpoint correctly. We will keep this open until we can verify that Endpoint is installed correctly

@AndersonQ
Copy link
Member

It might be indeed caused by the same thing as elastic/fleet-server#1877. Do you have the fleet-server logs as well a diagnostics from the broken agent?

@ghost
Copy link
Author

ghost commented Sep 21, 2022

Hi @kevinlog and @AndersonQ thanks for looking into the issue.

we have check the endpoint installation on fresh build and observed that endpoint got successfully installed, changes in policy got successfully applied and alerts are also getting generated. so closing this issue .

image

image

image

image

image

@ghost ghost closed this as completed Sep 21, 2022
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience impact:high Addressing this issue will have a high level of impact on the quality/strength of our product. Team:Defend Workflows “EDR Workflows” sub-team of Security Solution Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed
Projects
None yet
Development

No branches or pull requests

4 participants