Skip to content

Fix threat intel edit filters#179607

Merged
lgestc merged 10 commits intoelastic:mainfrom
lgestc:fix_threat_intel_edit_filters
Apr 2, 2024
Merged

Fix threat intel edit filters#179607
lgestc merged 10 commits intoelastic:mainfrom
lgestc:fix_threat_intel_edit_filters

Conversation

@lgestc
Copy link
Copy Markdown
Contributor

@lgestc lgestc commented Mar 28, 2024

Summary

The following PR needs to be merged first: #178701

This fixes #174764 (comment) and #179030

To reproduce:

Add whatever filter in the Threat Intelligence (via table filter in), then click it (in the top bar) - filter edit popover is not filled in with data.

On Alerts page though, it is filled in correctly - and it should look like that on TI:

image

@lgestc lgestc requested review from a team as code owners March 28, 2024 10:47
@elasticmachine
Copy link
Copy Markdown
Contributor

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)

@PhilippeOberti
Copy link
Copy Markdown
Contributor

@lgestc could you add the step to reproduce the issue? I'm looking at the comment but I'm not clear on what I need to test and how

@lgestc
Copy link
Copy Markdown
Contributor Author

lgestc commented Mar 28, 2024

@lgestc could you add the step to reproduce the issue? I'm looking at the comment but I'm not clear on what I need to test and how

upated the desc:)

@PhilippeOberti
Copy link
Copy Markdown
Contributor

PhilippeOberti commented Mar 28, 2024

@lgestc thanks for adding the description. I was originally confused because things were working normally for me until I realized I had to add a filter from the table row actions...

I now tested it and the bug is fixed! I'm ready to approve, but I'm wondering why not doing a PR just for this fix. I don't think you need the first 8 commits and unless I missed something, there aren't any files modified in the last commit that would conflict with the first 8...
Would you be ok making a PR just for this fix? Then I can approve it and we can merge immediately?

@lgestc lgestc force-pushed the fix_threat_intel_edit_filters branch from 770e638 to 292b560 Compare April 2, 2024 09:05
@Dosant Dosant removed the request for review from a team April 2, 2024 09:13
Copy link
Copy Markdown
Contributor

@PhilippeOberti PhilippeOberti left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

code LGTM and desk tested, thanks for fixing this!!

@kibana-ci
Copy link
Copy Markdown

💚 Build Succeeded

Metrics [docs]

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
threatIntelligence 56.9KB 57.1KB +148.0B

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@lgestc lgestc merged commit da69703 into elastic:main Apr 2, 2024
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Apr 2, 2024
## Summary

The following PR needs to be merged first:
elastic#178701

This fixes
elastic#174764 (comment)
and elastic#179030

**To reproduce:**

Add whatever filter in the Threat Intelligence (via table filter in),
then click it (in the top bar) - filter edit popover is not filled in
with data.

On Alerts page though, it is filled in correctly - and it should look
like that on TI:

![image](https://github.com/elastic/kibana/assets/11671118/0de5f076-83dd-48f3-810b-75d1572536e3)

(cherry picked from commit da69703)
@kibanamachine
Copy link
Copy Markdown
Contributor

💚 All backports created successfully

Status Branch Result
8.13

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

@kibanamachine kibanamachine added the backport missing Added to PRs automatically when the are determined to be missing a backport. label Apr 6, 2024
@kibanamachine
Copy link
Copy Markdown
Contributor

Looks like this PR has a backport PR but it still hasn't been merged. Please merge it ASAP to keep the branches relatively in sync.

lgestc added a commit to lgestc/kibana that referenced this pull request Apr 9, 2024
## Summary

The following PR needs to be merged first:
elastic#178701

This fixes
elastic#174764 (comment)
and elastic#179030

**To reproduce:**

Add whatever filter in the Threat Intelligence (via table filter in),
then click it (in the top bar) - filter edit popover is not filled in
with data.

On Alerts page though, it is filled in correctly - and it should look
like that on TI:

![image](https://github.com/elastic/kibana/assets/11671118/0de5f076-83dd-48f3-810b-75d1572536e3)

(cherry picked from commit da69703)
@lgestc
Copy link
Copy Markdown
Contributor Author

lgestc commented Apr 9, 2024

💚 All backports created successfully

Status Branch Result
8.13

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

lgestc added a commit that referenced this pull request Apr 9, 2024
# Backport

This will backport the following commits from `main` to `8.13`:
- [Fix threat intel edit filters
(#179607)](#179607)

<!--- Backport version: 8.9.8 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Luke
G","email":"11671118+lgestc@users.noreply.github.com"},"sourceCommit":{"committedDate":"2024-04-02T11:46:07Z","message":"Fix
threat intel edit filters (#179607)\n\n## Summary\r\n\r\nThe following
PR needs to be merged
first:\r\nhttps://github.com//pull/178701\r\n\r\nThis
fixes\r\nhttps://github.com//issues/174764#issuecomment-1992363217\r\nand
https://github.com/elastic/kibana/issues/179030\r\n\r\n**To
reproduce:**\r\n\r\nAdd whatever filter in the Threat Intelligence (via
table filter in),\r\nthen click it (in the top bar) - filter edit
popover is not filled in\r\nwith data.\r\n\r\nOn Alerts page though, it
is filled in correctly - and it should look\r\nlike that on
TI:\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/11671118/0de5f076-83dd-48f3-810b-75d1572536e3)","sha":"da697032c7ba74a2bba8338f64354cb6b0393ea5","branchLabelMapping":{"^v8.14.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","backport
missing","Team:Threat
Hunting:Investigations","backport:prev-minor","8.14
candidate","v8.14.0"],"number":179607,"url":"https://github.com/elastic/kibana/pull/179607","mergeCommit":{"message":"Fix
threat intel edit filters (#179607)\n\n## Summary\r\n\r\nThe following
PR needs to be merged
first:\r\nhttps://github.com//pull/178701\r\n\r\nThis
fixes\r\nhttps://github.com//issues/174764#issuecomment-1992363217\r\nand
https://github.com/elastic/kibana/issues/179030\r\n\r\n**To
reproduce:**\r\n\r\nAdd whatever filter in the Threat Intelligence (via
table filter in),\r\nthen click it (in the top bar) - filter edit
popover is not filled in\r\nwith data.\r\n\r\nOn Alerts page though, it
is filled in correctly - and it should look\r\nlike that on
TI:\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/11671118/0de5f076-83dd-48f3-810b-75d1572536e3)","sha":"da697032c7ba74a2bba8338f64354cb6b0393ea5"}},"sourceBranch":"main","suggestedTargetBranches":[],"targetPullRequestStates":[{"branch":"main","label":"v8.14.0","labelRegex":"^v8.14.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/179607","number":179607,"mergeCommit":{"message":"Fix
threat intel edit filters (#179607)\n\n## Summary\r\n\r\nThe following
PR needs to be merged
first:\r\nhttps://github.com//pull/178701\r\n\r\nThis
fixes\r\nhttps://github.com//issues/174764#issuecomment-1992363217\r\nand
https://github.com/elastic/kibana/issues/179030\r\n\r\n**To
reproduce:**\r\n\r\nAdd whatever filter in the Threat Intelligence (via
table filter in),\r\nthen click it (in the top bar) - filter edit
popover is not filled in\r\nwith data.\r\n\r\nOn Alerts page though, it
is filled in correctly - and it should look\r\nlike that on
TI:\r\n\r\n\r\n![image](https://github.com/elastic/kibana/assets/11671118/0de5f076-83dd-48f3-810b-75d1572536e3)","sha":"da697032c7ba74a2bba8338f64354cb6b0393ea5"}}]}]
BACKPORT-->
@kibanamachine kibanamachine added v8.13.3 and removed backport missing Added to PRs automatically when the are determined to be missing a backport. labels Apr 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security Solution][Threat Intelligence] - filter in/out not showing value in KQL bar

5 participants