[SIEM] Fixes escape bug for filterQuery #43030
Merged
stephmilovic merged 11 commits intoelastic:masterfrom Sep 6, 2019
Merged
Conversation
Contributor
|
Pinging @elastic/siem |
Contributor
💚 Build Succeeded |
Contributor
💚 Build Succeeded |
FrankHassanabad
approved these changes
Aug 12, 2019
Contributor
FrankHassanabad
left a comment
There was a problem hiding this comment.
Tested it out and played with it and it fixes the issue.
If there are changes required of the downstream libs and a new PR for the downstream lib is created just tack it on optionally I would say.
Contributor
💔 Build Failed |
Contributor
Author
|
update: @XavierM and i need to pair on this further |
Contributor
💔 Build Failed |
Contributor
💚 Build Succeeded |
Contributor
💔 Build Failed |
Contributor
💔 Build Failed |
Contributor
💚 Build Succeeded |
9 tasks
XavierM
approved these changes
Sep 6, 2019
Contributor
XavierM
left a comment
There was a problem hiding this comment.
I tested locally, and I agreed that match_phrase will do the job, no need to be stubburn and use only used match in dsl
Contributor
💚 Build Succeeded |
stephmilovic
added a commit
to stephmilovic/kibana
that referenced
this pull request
Sep 6, 2019
stephmilovic
added a commit
to stephmilovic/kibana
that referenced
this pull request
Sep 6, 2019
This was referenced Sep 6, 2019
jloleysens
added a commit
to jloleysens/kibana
that referenced
this pull request
Sep 6, 2019
…ete-for-distance_feature * 'master' of github.com:elastic/kibana: [SIEM] Fixes escape bug for filterQuery (elastic#43030) Export saved objects based on search criteria (elastic#44723) refactor(webhook-whitelisting): Removed unneeded schema config (elastic#44974) [APM] Make number of x ticks responsive to the plot width (elastic#44870) [ML] Single metric viewer: Fix top nav refresh behaviour. (elastic#44860)
stephmilovic
added a commit
that referenced
this pull request
Sep 6, 2019
stephmilovic
added a commit
that referenced
this pull request
Sep 6, 2019
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@spong noticed a bug where when searching fields with escaped values, nothing would get returned: #42866
After playing with the query, I noticed Elasticsearch does not enjoy getting escaped values on strings.
This does not have matches:
This has matches
I fixed the bug by surrounding all strings in returned in
escapeQueryValuewith". This way we only need to escape"and it eliminates the bugs we were seeing.To test:
Check the following timeline links return results:
Checklist
Use
strikethroughsto remove checklist items you don't feel are applicable to this PR.This was checked for cross-browser compatibility, including a check against IE11Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n supportDocumentation was added for features that require explanation or tutorialsThis was checked for keyboard-only and screenreader accessibilityFor maintainers
This was checked for breaking API changes and was labeled appropriatelyThis includes a feature addition or change that requires a release note and was labeled appropriately