[SECURITY SOLUTIONS] Bugs overview page + investigate eql in timeline#81550
Merged
XavierM merged 10 commits intoelastic:masterfrom Oct 27, 2020
Merged
[SECURITY SOLUTIONS] Bugs overview page + investigate eql in timeline#81550XavierM merged 10 commits intoelastic:masterfrom
XavierM merged 10 commits intoelastic:masterfrom
Conversation
Contributor
Author
|
@elasticmachine merge upstream |
patrykkopycinski
approved these changes
Oct 26, 2020
spong
reviewed
Oct 26, 2020
Comment on lines
+154
to
+155
| ecsData.signal?.rule?.type?.length && | ||
| ecsData.signal?.rule?.type[0] === 'eql' && |
Member
There was a problem hiding this comment.
nit: Could consolidate to the following using array item access with optional chaining if you'd like:
Suggested change
| ecsData.signal?.rule?.type?.length && | |
| ecsData.signal?.rule?.type[0] === 'eql' && | |
| ecsData.signal?.rule?.type?.[0] === 'eql' && |
spong
reviewed
Oct 26, 2020
| ]); | ||
| const resultingTimeline: TimelineResult = getOr({}, 'data.getOneTimeline', responseTimeline); | ||
| const eventData: TimelineEventsDetailsItem[] = getOr([], 'data', eventDataResp); | ||
| const eventData: TimelineEventsDetailsItem[] = eventDataResp.data ?? []; |
Member
There was a problem hiding this comment.
Thank you for cleaning up more getOr's! 🙇♂️
rylnd
approved these changes
Oct 26, 2020
Contributor
rylnd
left a comment
There was a problem hiding this comment.
Tested "investigate in timeline" with both sequence alerts and non-sequence alerts. LGTM!
| ecsData.signal?.rule?.type?.length && ecsData.signal?.rule?.type[0] === 'eql'; | ||
| export const isEqlRuleWithGroupId = (ecsData: Ecs) => | ||
| ecsData.signal?.rule?.type?.length && | ||
| ecsData.signal?.rule?.type[0] === 'eql' && |
Contributor
There was a problem hiding this comment.
We've also got those rule type helpers that could be leveraged here!
andrew-goldstein
approved these changes
Oct 26, 2020
Contributor
💚 Build SucceededMetrics [docs]async chunks size
page load bundle size
History
To update your PR or re-run it, just comment with: |
XavierM
added a commit
to XavierM/kibana
that referenced
this pull request
Oct 27, 2020
…elastic#81550) * fix overview query to be connected to sourcerer * investigate eql in timeline * keep timeline indices * trusting what is coming from timeline saved object for index pattern at initialization * fix type + initialize old timeline to sourcerer Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
XavierM
added a commit
to XavierM/kibana
that referenced
this pull request
Oct 27, 2020
…elastic#81550) * fix overview query to be connected to sourcerer * investigate eql in timeline * keep timeline indices * trusting what is coming from timeline saved object for index pattern at initialization * fix type + initialize old timeline to sourcerer Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
gmmorris
added a commit
to gmmorris/kibana
that referenced
this pull request
Oct 27, 2020
* master: (37 commits) [ILM] Migrate Warm phase to Form Lib (elastic#81323) [Security Solutions][Detection Engine] Fixes critical bug with error reporting that was doing a throw (elastic#81549) [Detection Rules] Add 7.10 rules (elastic#81676) [kbn/optimizer] ignore missing metrics when updating limits with --focus (elastic#81696) [SECURITY SOLUTIONS] Bugs overview page + investigate eql in timeline (elastic#81550) [Maps] fix unable to edit cluster vector styles styled by count when switching to super fine grid resolution (elastic#81525) Fixed migration issue for case specific actions, by extending email action migrator checks (elastic#81673) [CI] Preparation for APM tracking on CI (elastic#80399) [Home] Fixes Kibana app description order on home page and updates Canvas copy (elastic#80057) Make sure `to` is 'now' and not the same as `from` (elastic#81524) Nitpicking the 8.0 Breaking Change issue template (elastic#81678) [SECURITY_SOLUTION] Fix text on onboarding screen (elastic#81672) [data.search] Skip async search tests in build candidates and production builds (elastic#81547) Fix previousStartedAt by not changing when execution fails (elastic#81388) [Monitoring] Fix a couple of issues with the cpu usage alert (elastic#80737) Telemetry collection xpack to ts project references (elastic#81269) Elasticsearch: don't use url authentication for new client (elastic#81564) [App Search] Credentials: implement working flyout form (elastic#81541) Properly encode links to edit user page (elastic#81562) [Alerting UI] Don't wait for health check before showing Create Alert flyout (elastic#80996) ...
XavierM
added a commit
that referenced
this pull request
Oct 27, 2020
…#81550) (#81708) * fix overview query to be connected to sourcerer * investigate eql in timeline * keep timeline indices * trusting what is coming from timeline saved object for index pattern at initialization * fix type + initialize old timeline to sourcerer Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com> Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
XavierM
added a commit
that referenced
this pull request
Oct 27, 2020
…#81550) (#81712) * fix overview query to be connected to sourcerer * investigate eql in timeline * keep timeline indices * trusting what is coming from timeline saved object for index pattern at initialization * fix type + initialize old timeline to sourcerer Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com> Co-authored-by: Kibana Machine <42973632+kibanamachine@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Host/Network events query on Overview page were not taking into consideration of the sourcerer (meaning the change of indices)

Signals from the correlation rules (EQL) does not have all the time a
signal.group.idwhen there is no sequences so we need a way to fallback of the basic query of the_id: ididididididididTimeline custom indexes change depending on the page the timeline is opened [Security Solution] Timeline custom indexes change depending on the page the timeline is opened #81640
Checklist