-
Notifications
You must be signed in to change notification settings - Fork 8.6k
[Security Solution] Unable to upgrade rules with missing base version #200904
Copy link
Copy link
Closed
Labels
8.17 candidateFeature:Prebuilt Detection RulesSecurity Solution Prebuilt Detection Rules areaSecurity Solution Prebuilt Detection Rules areaTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection Rule ManagementSecurity Detection Rule Management TeamSecurity Detection Rule Management TeamTeam:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v8.16.2v8.17.0v8.18.0
Metadata
Metadata
Assignees
Labels
8.17 candidateFeature:Prebuilt Detection RulesSecurity Solution Prebuilt Detection Rules areaSecurity Solution Prebuilt Detection Rules areaTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection Rule ManagementSecurity Detection Rule Management TeamSecurity Detection Rule Management TeamTeam:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v8.16.2v8.17.0v8.18.0
Type
Fields
Give feedbackNo fields configured for issues without a type.
Epic: #174168
Related to: #200286
Summary
When a rule has a missing
baseversion, the update to theversionfield is treated as a conflict, which blocks the update flow.Steps to Reproduce
baseversion.Expected Result
Users should be able to resolve conflicts and update the rule successfully.
Actual Result
Rule update is not possible, even after resolving all conflicts, due to an "invisible" conflict in the
versionfield: