Skip to content

[Security Solution] Event count is not preserved if sorting is done on empty columns under the timeline #87088

@muskangulati-qasource

Description

@muskangulati-qasource

Describe the bug
Event count is not preserved if sorting is done on empty columns under the timeline

Build Details:

Platform: Staging
Version: 7.10.2-SNAPSHOT
Commit: 733d0aa29750868a043ec307f27a0506d9a3ed62
Build number: 36123
Artifact: https://artifacts-api.elastic.co/v1/search/7.10.2-SNAPSHOT

Browser Details
All

Preconditions

  1. Cloud environment on staging should exist.
  2. Endpoint should be deployed and events should be generated.

Steps to Reproduce

  1. Navigate to Kibana URL on Browser.
  2. Click on the "Timeline" tab under Security from the left navigation bar.
  3. Create a new timeline and observe the count of events.
  4. Observe that if sorting is done for any empty column, the count of events is decreased and not preserved.

Test data
N/A

Impacted Test case(s)
N/A

Actual Result
Event count is not preserved if sorting is done on empty columns under the timeline

Expected Result
Event count should be preserved if sorting is done on any column under the timeline

What's Working
N/A

What's not Working
N/A

Screenshots

  • Timeline data for default sorting:
    TimelineDataBeforeSorting

-Timeline data after sorting with empty fields.
TimelineDataAfterSorting

Logs
N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    Feature:TimelineSecurity Solution Timeline featureTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeambugFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.v7.10.2v7.11.0

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions