-
Notifications
You must be signed in to change notification settings - Fork 8.6k
[SIEM][Detection Engine] Closing a signal silently fails with reduced privileges #56991
Copy link
Copy link
Closed
Closed
Copy link
Labels
Feature:Detection AlertsSecurity Solution Detection Alerts FeatureSecurity Solution Detection Alerts FeatureTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeamTeam:SIEMbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.Addressing this issue will have a medium level of impact on the quality/strength of our product.v7.11.0v7.12.0v8.0.0
Metadata
Metadata
Assignees
Labels
Feature:Detection AlertsSecurity Solution Detection Alerts FeatureSecurity Solution Detection Alerts FeatureTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Detections and RespSecurity Detection Response TeamSecurity Detection Response TeamTeam:SIEMbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.Addressing this issue will have a medium level of impact on the quality/strength of our product.v7.11.0v7.12.0v8.0.0
Type
Fields
Give feedbackNo fields configured for issues without a type.
Scenario:
For a user missing the required privileges to update signal documents, the icon is visible and can be clicked. However, closing the signal will silently fail, with an error in the Network tab.
Privileges:
manage_api_keyread,view_index_metadata,create_docon.siem-signals-default*,readandview_index_metadataonpacketbeat-*Allon SIEMWhat did I do? Click close signal icon
Suggestion:
Expose the background error.
Screenshot
