[Security Solution] Detection rules with actions cannot be created #155146
Labels
bug
Fixes for quality problems that affect the customer experience
impact:critical
This issue should be addressed immediately due to a critical level of impact on the product.
Team:Detection Alerts
Security Detection Alerts Area Team
Team:Detections and Resp
Security Detection Response Team
Team:ResponseOps
Label for the ResponseOps team (formerly the Cases and Alerting teams)
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Describe the bug:
Kibana/Elasticsearch Stack version:
Initial Setup:
Steps to reproduce:
Rules page
Create new rule
Define rule
stepAbout rule
stepContinue
button of theSchedule rule
stepPerform no actions
Send alert notification with the selected time frame only
Send alert notification with the selected time frame only
Create & enable rule
Current behavior:
Expected behavior:
Additional information:
Send alert notification with the selected time frame only
the rule is created properlyFailed to validate actions due to the following error: Action's alertsFilter must have either "query" or "timeframe" : 60d62e68-7f0d-4953-abbe-c3f561cb0e3a (400)
The text was updated successfully, but these errors were encountered: