-
Notifications
You must be signed in to change notification settings - Fork 8.6k
[Security Solution] Conflict modal is shown under Platinum license / Essentials tier #214302
Copy link
Copy link
Closed
Closed
Copy link
Labels
8.18 candidateFeature:Prebuilt Detection RulesSecurity Solution Prebuilt Detection Rules areaSecurity Solution Prebuilt Detection Rules areaTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection Rule ManagementSecurity Detection Rule Management TeamSecurity Detection Rule Management TeamTeam:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v8.18.0
Metadata
Metadata
Assignees
Labels
8.18 candidateFeature:Prebuilt Detection RulesSecurity Solution Prebuilt Detection Rules areaSecurity Solution Prebuilt Detection Rules areaTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detection Rule ManagementSecurity Detection Rule Management TeamSecurity Detection Rule Management TeamTeam:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v8.18.0
Type
Fields
Give feedbackNo fields configured for Bug.
Description:
When bulk updating rules in the Rule Updates table, if some of the rules have conflicts, the system displays a confirmation message indicating that users can proceed with updating auto-resolved conflict rules or opt to update only conflict-free rules. However, under a Platinum License/Essentials Tier, rule modifications and conflict reviews are not allowed.
The issue is just observed by using "Update All" button while bulk updating N rules don't result in same.
For lower licenses, bulk updates should directly update all rules.
Screenshot:
Active license:
When a mix of unresolved and auto-resolved conflicts is available:
When only unresolved conflicts are available:
When only auto-resoled conflicts are available:
Kibana/Elasticsearch Stack version:
Functional Area (e.g. Endpoint management, timelines, resolver, etc.):
Prebuilt Rules
Pre requisites:
Steps to reproduce:
Current behavior:
Expected behavior: