Skip to content

[windows] Add filters to visuals for only AppLocker data to be displayed#8993

Merged
marc-gr merged 7 commits intoelastic:mainfrom
nicpenning:dashboard-filter-fix
Feb 14, 2024
Merged

[windows] Add filters to visuals for only AppLocker data to be displayed#8993
marc-gr merged 7 commits intoelastic:mainfrom
nicpenning:dashboard-filter-fix

Conversation

@nicpenning
Copy link
Copy Markdown
Contributor

  • Bug

This fixes the visuals in the dashboard for AppLocker so only relevant data is displayed. See: #8969

Checklist

@nicpenning nicpenning requested a review from a team as a code owner January 26, 2024 23:03
@nicpenning nicpenning requested review from belimawr and rdner January 26, 2024 23:03
@nicpenning
Copy link
Copy Markdown
Contributor Author

This is ready to test.

@pierrehilbert pierrehilbert added the Team:Elastic-Agent Platform - Ingest - Agent [elastic/elastic-agent] label Jan 27, 2024
@elasticmachine
Copy link
Copy Markdown

Pinging @elastic/elastic-agent (Team:Elastic-Agent)

@nicpenning nicpenning changed the title [windows] Add filters to visuals for only AppLocker data to be displated [windows] Add filters to visuals for only AppLocker data to be displayed Jan 29, 2024
@cmacknz cmacknz requested a review from leehinman January 29, 2024 21:10
@jamiehynds jamiehynds requested a review from a team January 30, 2024 10:05
@jamiehynds jamiehynds added Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform] Integration:windows Windows labels Jan 30, 2024
marc-gr
marc-gr previously approved these changes Jan 30, 2024
@marc-gr marc-gr self-requested a review January 30, 2024 14:01
@marc-gr marc-gr dismissed their stale review January 30, 2024 14:04

waiting for ci

@belimawr
Copy link
Copy Markdown
Contributor

/test

@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Jan 30, 2024

I think elastic-package check is required to run and commit the changes it does.

@nicpenning
Copy link
Copy Markdown
Contributor Author

Okay - So I need to run that command and then push the changes up?

@nicpenning
Copy link
Copy Markdown
Contributor Author

elastic-package check has been applied and committed. Please test again!

@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Jan 31, 2024

/test

@nicpenning
Copy link
Copy Markdown
Contributor Author

I cannot see the build issues now that it's been moved to buildkite. Any chance this can be opened up to community members contributing?

@nicpenning
Copy link
Copy Markdown
Contributor Author

Any updates on why this failed? I am kinda blind over here.

@strawgate
Copy link
Copy Markdown
Contributor

strawgate commented Feb 2, 2024

I see a failure of:

Error: can't install the package: could not zip-install package; API status code = 500; response body = {"statusCode":500,"error":"Internal Server Error","message":"Migration function for version 7.11.0 threw an error"}

I'll see if we can get someone to comment about plans for access.

In the meantime please feel free to ping me with @strawgate and I'll grab the logs

@nicpenning
Copy link
Copy Markdown
Contributor Author

Thank you. Any idea how that issue can be resolved?

@pierrehilbert
Copy link
Copy Markdown
Contributor

/test

@nicpenning
Copy link
Copy Markdown
Contributor Author

Is this issue sourced from using 8.12.0 when I checked the package?

@strawgate - is it still the same error?

@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Feb 5, 2024

Is this issue sourced from using 8.12.0 when I checked the package?

@strawgate - is it still the same error?

Could be, I checked and for 8.12 it passes alright, but CI uses the minimum supported version which is 8.8.0. If you used 8.12 to do the changes that might be the issue. I'd suggest doing them with an 8.8.0 stack (elastic-package stack up -v -d --version=8.8.0)

@nicpenning
Copy link
Copy Markdown
Contributor Author

nicpenning commented Feb 5, 2024

Bummer - Okay, I can do that. Perhaps it is a deeper issue, but it is concerning we must use such an older version of the stack. In an example of a visualization that only exists in the latest, this would likely then be a blocker and not something we can add until the elastic-package tool can keep up? I can reference this issue there if that will help with this side issue. Please let me know!

-Update - Nevermind, I misread your response. This is a CI limitation not an elastic-package one. Disregard! :)

@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Feb 7, 2024

I'll take care of fixing this one since not having access to CI complicates things for @nicpenning . Thanks for the work done @nicpenning will update this PR with the fix. 👍

@nicpenning
Copy link
Copy Markdown
Contributor Author

👋
Any updates here?

@marc-gr
Copy link
Copy Markdown
Contributor

marc-gr commented Feb 13, 2024

/test

@elasticmachine
Copy link
Copy Markdown

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link
Copy Markdown

💚 Build Succeeded

History

@elastic-sonarqube
Copy link
Copy Markdown

Quality Gate passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No Coverage information No data about Coverage
0.0% 0.0% Duplication on New Code

See analysis details on SonarQube

@marc-gr marc-gr requested a review from rdner February 13, 2024 11:09
@marc-gr marc-gr merged commit cf8591f into elastic:main Feb 14, 2024
@nicpenning
Copy link
Copy Markdown
Contributor Author

🎉

@nicpenning nicpenning deleted the dashboard-filter-fix branch February 14, 2024 12:53
@elasticmachine
Copy link
Copy Markdown

Package windows - 1.44.3 containing this change is available at https://epr.elastic.co/search?package=windows

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Integration:windows Windows Team:Elastic-Agent Platform - Ingest - Agent [elastic/elastic-agent] Team:Security-Windows Platform Security Windows Platform team [elastic/sec-windows-platform]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dashboard issues with "[Windows AppLocker] Audited and Blocked Applications" dashboard as provided by "Windows" integration 1.44.1

8 participants