Skip to content

[Security Solution] Prebuilt rules marked as customized after applying updates #201631

@xcrzx

Description

@xcrzx

Summary

Non-customized rules are incorrectly marked as customized after applying an update.

Steps to Reproduce

  1. Enable the rule customization feature flag
  2. Install rules from an older package version.
  3. Upgrade the rules package to the latest version.
  4. Find any upgradable rule without conflicts.
  5. Update the rule to the latest version accepting all incoming changes.

Expected Result

The rule is upgraded and remains marked as non-customized.

Actual Result

The rule is upgraded but is incorrectly marked as customized.

Initial analysis shows a difference in the lookback field between the saved updated rule and the target version. The value changes from -60s to 240s.

Image

Metadata

Metadata

Assignees

Labels

8.18 candidateFeature:Prebuilt Detection RulesSecurity Solution Prebuilt Detection Rules areaTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection Rule ManagementSecurity Detection Rule Management TeamTeam:Detections and RespSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.v8.17.1v8.18.0v9.0.0

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions