Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Expiration date on exceptions are not duplicated when duplicating a rule #151100

Closed
MadameSheema opened this issue Feb 14, 2023 · 3 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience fixed Team:Detection Alerts Security Detection Alerts Area Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v8.7.0

Comments

@MadameSheema
Copy link
Member

MadameSheema commented Feb 14, 2023

Describe the bug:

  • Expiration date on exceptions are not duplicated when duplicating a rule.

Kibana/Elasticsearch Stack version:

  • 8.7.0 - BC1

Preconditions:

  • To have a rule with at least one exception with an expiration date

Steps to reproduce:

  1. Duplicate the rule
  2. Make sure the Duplicate rule and their exceptions option is selected

Current behavior:

  • The rule is duplicated
  • The exception of the duplicated rule does not have expiration date

Expected behavior:

  • The rule should be duplicated
  • The exception of the duplicated rule should have the same expiration date as the original one.
@MadameSheema MadameSheema added bug Fixes for quality problems that affect the customer experience triage_needed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team Team:Detection Alerts Security Detection Alerts Area Team labels Feb 14, 2023
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@MadameSheema MadameSheema added Team:Detections and Resp Security Detection Response Team and removed Team:Detection Rule Management Security Detection Rule Management Team labels Feb 14, 2023
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@marshallmain
Copy link
Contributor

@MadameSheema Can you confirm if this bug is fixed on the latest BC?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience fixed Team:Detection Alerts Security Detection Alerts Area Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v8.7.0
Projects
None yet
Development

No branches or pull requests

4 participants