Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution]Additional Filter not working under Top risk score contributors Alert Table #168917

Open
ghost opened this issue Oct 16, 2023 · 7 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Entity Analytics Security Entity Analytics Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed v8.11.0

Comments

@ghost
Copy link

ghost commented Oct 16, 2023

Describe the bug:
Additional Filter not working under Top risk score contributors Alert Table

Kibana/Elasticsearch Stack version
Version: 8.11.0 BC2
Commit: 636a833
Build: 67841

Browser and Browser OS Version:
Firefox for windows OS
Version: 118.0.1

Elastic Endpoint Version:
8.11

Original install method:
None

Functional Area:
Host/User Risk Score

Initial Setup:

  • Host and User Risk Score need to be enabled

Steps to reproduce

  • Go to Host details page then host risk tab
  • Under Top risk score contributors Alert Table enable show only threat indicator alert
  • Validate that additional filter was not working

Additional Observation

  • None

Current behavior

  • Additional Filter not working under Top risk score contributors Alert Table
    • Non threat indicator alert was also showing after the additional filter

Expected behavior:

  • Additional Filter should working under Top Risk Score Contributors Alert Table

Screen-Shot:

image

Hosts.-.Kibana.Mozilla.Firefox.2023-10-16.12-47-30.mp4
additional.filter.mp4
@ghost ghost added bug Fixes for quality problems that affect the customer experience triage_needed Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Oct 16, 2023
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@ghost ghost assigned MadameSheema Oct 16, 2023
@MadameSheema MadameSheema added Team:Threat Hunting Security Solution Threat Hunting Team Team:Threat Hunting:Investigations Security Solution Investigations Team and removed Team:Threat Hunting:Explore labels Oct 16, 2023
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting (Team:Threat Hunting)

@MadameSheema MadameSheema removed their assignment Oct 16, 2023
@ghost ghost added the impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. label Oct 16, 2023
@nkhristinin
Copy link
Contributor

Checked that also, yes it looks like a bug. Good thing that top filters work, but definitely those additional filters for Threat Indicator don't work

Screen.Recording.2023-10-18.at.15.39.52.mov

@hop-dev hop-dev self-assigned this Feb 19, 2024
@hop-dev
Copy link
Contributor

hop-dev commented Feb 20, 2024

These filters are working now so I think they may have been fixed. By design they do not get added to the global query bar, they are more akin to the status, servertiy, user, host filters at the top of the visualisations. One thing is that there is no indicator that a filter has been applied, I will put up a PR to make that UX a little better.

In the video below, rule test2 is a building block rule and rule test3 is a threat indicator:

Screen.Recording.2024-02-20.at.11.49.23.mov

@hop-dev hop-dev closed this as completed Feb 20, 2024
hop-dev added a commit that referenced this issue Feb 21, 2024
…table (#177275)

## Summary

While investigating #168917 I
noticed that there is no way to tell if an additional filter has been
applied on the alerts table which can be a bit confusing because it
filters the whole page.

I have added a notification badge to show the number of filters applied,
matching the style of the other badges on the table.

<img width="1446" alt="Screenshot 2024-02-20 at 12 31 02"
src="https://github.com/elastic/kibana/assets/3315046/00f18859-f532-4025-a506-5bdf782d9fe3">


**Video Demo:** 


https://github.com/elastic/kibana/assets/3315046/628f1165-bfe3-4b20-b60f-07fc6bceebe9

---------

Co-authored-by: Kibana Machine <[email protected]>
@ghost ghost reopened this Feb 29, 2024
@ghost
Copy link
Author

ghost commented Feb 29, 2024

Hi @MadameSheema

we have observed this issue to be re-occurring on 8.13 BC2. so we have opened this issue.

Kibana/Elasticsearch Stack version

Version: 8.13.0 BC2
Commit: c2fc8da128504d437897970d142efd4d06970c0b
Build: 71815

Screen-Cast:

show_only_threat_indicator.mov

Please let me know if any more information need from our end.

thanks !!

fkanout pushed a commit to fkanout/kibana that referenced this issue Mar 4, 2024
…table (elastic#177275)

## Summary

While investigating elastic#168917 I
noticed that there is no way to tell if an additional filter has been
applied on the alerts table which can be a bit confusing because it
filters the whole page.

I have added a notification badge to show the number of filters applied,
matching the style of the other badges on the table.

<img width="1446" alt="Screenshot 2024-02-20 at 12 31 02"
src="https://github.com/elastic/kibana/assets/3315046/00f18859-f532-4025-a506-5bdf782d9fe3">


**Video Demo:** 


https://github.com/elastic/kibana/assets/3315046/628f1165-bfe3-4b20-b60f-07fc6bceebe9

---------

Co-authored-by: Kibana Machine <[email protected]>
@hop-dev hop-dev removed their assignment Mar 13, 2024
@hop-dev hop-dev removed the Team:Entity Analytics Security Entity Analytics Team label Mar 27, 2024
@MadameSheema MadameSheema added the Team:Threat Hunting:Investigations Security Solution Investigations Team label Apr 1, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)

@MadameSheema MadameSheema added Team:Entity Analytics Security Entity Analytics Team and removed Team:Threat Hunting Security Solution Threat Hunting Team Team:Threat Hunting:Investigations Security Solution Investigations Team labels Apr 1, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-entity-analytics (Team:Entity Analytics)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Entity Analytics Security Entity Analytics Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. triage_needed v8.11.0
Projects
Status: To do
Development

No branches or pull requests

7 participants