-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution]Cases information not available under preview result alert flyout #129288
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
Reviewed & assigned to @MadameSheema |
Pinging @elastic/security-threat-hunting (Team:Threat Hunting) |
After syncing with @MadameSheema we found out that this is a genuine issue. Luckily it is not an issue with the data model but rather a UX issue. The alert is not attached to a case because it's not an alert that comes from the same index as the previously attached alert. The alert from the table comes from the preview index and therefore has a different ID. So on paper the issue appears to be expected behaviour. However, I think this is a genuine issue because it is a confusing UX to display the case count when opening the flyout from the preview table. IMO, not displaying the case count would be the better UX. Wdyt @michaelolo24 ? |
I agree that it is a genuine issue, but not sure what the potential fix is here. If the alert in the preview index has a different id, then it won't appear in the flyout no matter what we do unless there's a way to do a look up in the back end from the preview table and return the id of the matching alert from the alerts index. Alternative is to not show the cases section from the flyout, but we should talk to @paulewing and @monina-n about that |
Also @marshallmain wanted to link this issue with: #129286 as a general question of How should the preview table behave relative to the full fledged alert table? |
Pinging @elastic/security-detections-response (Team:Detections and Resp) |
@michaelolo24 Generally the preview table should behave as a "read only" version of the full alerts table. The table supports paging, sorting, choosing columns, and viewing alert details, but does not support any stateful actions on alerts. Users can't add exceptions, add preview alerts to cases, or open/close preview alerts. |
I think we should remove the cases info from the preview flyout. cc @dplumlee |
@dplumlee I assigned you here because I think you're working on this already as part of the other preview fixes? Lmk if I assumed incorrectly! |
@deepikakeshav-qasource @karanbirsingh-qasource can you please help to coordinate the test of this? Thanks! |
Hi @MadameSheema, We have validated this issue on 8.3.0 BC2 and observed that issue is now Still Occurring. 🔴 Please find below the testing details:
Build Details:
Screencast cases.mp4Thanks!! |
Thanks @deepikakeshav-qasource!! Looks like it is missing the backport to 8.3 branch. Please make sure it is properly retested on next BC!! |
We have validated this issue on 8.3.0 BC3 and observed that issue is Fixed. 🟢 Please find below the testing details: Build Details:
Screencast Preview.Results.mp4Hence, We are closing this issue and marking as QA Validated!! cc: @MadameSheema Thanks!! |
Describe the bug
Cases information not available under preview result alert flyout
Build Details
Steps
Expected Result
As per our observation the expected result should be either of the following
Screen-Cast
Rules.-.Kibana.Mozilla.Firefox.2022-04-04.13-12-50.mp4
The text was updated successfully, but these errors were encountered: