Skip to content

Commit c7febd7

Browse files
[SIEM] Default the Timeline events filter to show All events (#58953)
## [SIEM] Default the Timeline events filter to show All events The Timeline events filter introduced in `7.6` to support the [detection engine](https://www.elastic.co/guide/en/siem/guide/current/detection-engine-overview.html) defaulted to filtering by `Raw events`, and thus required manually selecting `All events` or `Signal events` from the dropdown to view signals. The new default is `All events`, per the screenshots below: ### Before ![event-filter-before](https://user-images.githubusercontent.com/4459398/75593223-ecc61500-5a41-11ea-8d7d-8db5eccb1eb4.png) ### After ![event-filter-after](https://user-images.githubusercontent.com/4459398/75593238-f5b6e680-5a41-11ea-9e12-2fc1232f58d1.png)
1 parent bf89b9d commit c7febd7

4 files changed

Lines changed: 49 additions & 5 deletions

File tree

x-pack/legacy/plugins/siem/public/components/open_timeline/helpers.test.ts

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -236,7 +236,7 @@ describe('helpers', () => {
236236
description: '',
237237
deletedEventIds: [],
238238
eventIdToNoteIds: {},
239-
eventType: 'raw',
239+
eventType: 'all',
240240
filters: [],
241241
highlightedDropAndProviderId: '',
242242
historyIds: [],
@@ -330,7 +330,7 @@ describe('helpers', () => {
330330
description: '',
331331
deletedEventIds: [],
332332
eventIdToNoteIds: {},
333-
eventType: 'raw',
333+
eventType: 'all',
334334
filters: [],
335335
highlightedDropAndProviderId: '',
336336
historyIds: [],
@@ -417,7 +417,7 @@ describe('helpers', () => {
417417
description: '',
418418
deletedEventIds: [],
419419
eventIdToNoteIds: {},
420-
eventType: 'raw',
420+
eventType: 'all',
421421
filters: [],
422422
highlightedDropAndProviderId: '',
423423
historyIds: [],
@@ -539,7 +539,7 @@ describe('helpers', () => {
539539
description: '',
540540
deletedEventIds: [],
541541
eventIdToNoteIds: {},
542-
eventType: 'raw',
542+
eventType: 'all',
543543
filters: [
544544
{
545545
$state: {

x-pack/legacy/plugins/siem/public/components/timeline/search_or_filter/pick_events.tsx

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,6 +77,7 @@ const PickEventTypeComponents: React.FC<PickEventTypeProps> = ({
7777
return (
7878
<PickEventContainer>
7979
<EuiSuperSelect
80+
data-test-subj="pick-event-type"
8081
fullWidth={false}
8182
valueOfSelected={eventType}
8283
onChange={onChangeEventType}

x-pack/legacy/plugins/siem/public/components/timeline/timeline.test.tsx

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,49 @@ describe('Timeline', () => {
208208

209209
expect(wrapper.find('[data-test-subj="table-pagination"]').exists()).toEqual(false);
210210
});
211+
212+
test('it defaults to showing `All events`', () => {
213+
const wrapper = mount(
214+
<TestProviders>
215+
<MockedProvider mocks={mocks}>
216+
<TimelineComponent
217+
browserFields={mockBrowserFields}
218+
columns={defaultHeaders}
219+
id="foo"
220+
dataProviders={mockDataProviders}
221+
end={endDate}
222+
filters={[]}
223+
flyoutHeight={testFlyoutHeight}
224+
flyoutHeaderHeight={flyoutHeaderHeight}
225+
indexPattern={indexPattern}
226+
indexToAdd={[]}
227+
isLive={false}
228+
itemsPerPage={5}
229+
itemsPerPageOptions={[5, 10, 20]}
230+
kqlMode="search"
231+
kqlQueryExpression=""
232+
loadingIndexName={false}
233+
onChangeDataProviderKqlQuery={jest.fn()}
234+
onChangeDroppableAndProvider={jest.fn()}
235+
onChangeItemsPerPage={jest.fn()}
236+
onDataProviderEdited={jest.fn()}
237+
onDataProviderRemoved={jest.fn()}
238+
onToggleDataProviderEnabled={jest.fn()}
239+
onToggleDataProviderExcluded={jest.fn()}
240+
show={true}
241+
showCallOutUnauthorizedMsg={false}
242+
start={startDate}
243+
sort={sort}
244+
toggleColumn={jest.fn()}
245+
/>
246+
</MockedProvider>
247+
</TestProviders>
248+
);
249+
250+
expect(wrapper.find('[data-test-subj="pick-event-type"] button').text()).toEqual(
251+
'All events'
252+
);
253+
});
211254
});
212255

213256
describe('event wire up', () => {

x-pack/legacy/plugins/siem/public/store/timeline/defaults.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ export const timelineDefaults: SubsetTimelineModel & Pick<TimelineModel, 'filter
1414
dataProviders: [],
1515
deletedEventIds: [],
1616
description: '',
17-
eventType: 'raw',
17+
eventType: 'all',
1818
eventIdToNoteIds: {},
1919
highlightedDropAndProviderId: '',
2020
historyIds: [],

0 commit comments

Comments
 (0)