Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list #198845

Open
Tracked by #179907
pborgonovi opened this issue Nov 4, 2024 · 4 comments
Labels
bug Fixes for quality problems that affect the customer experience Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Feature:Rule Exceptions Security Solution Detection Rule Exceptions area impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.

Comments

@pborgonovi
Copy link
Contributor

pborgonovi commented Nov 4, 2024

Epics: https://github.com/elastic/security-team/issues/1974 (internal), #179907
Related to: #198771, #178221
Location: Rule Management page, Rule Updates table

Summary

Describe the bug:
When the user attempts to upgrade a prebuilt rule which was linked to a shared exception list that has been deleted, a 'Rule failed to update' message is displayed and the rule is not updated. It works properly in the second attempt.
No error is observed in the API calls.

Note: Reproducible on 8.15

Kibana/Elasticsearch Stack version:
8.16

Pre requisites:

  1. Have an older rules packaged installed (e.g. 8.4.2)
  2. Have rules updates available

Steps to reproduce:

  1. In Rules page, navigate to Shared exception lists and create a new shared exception list
  2. From this shared exception list, create a new exception item and link it to prebuilt rule A (update must be available for this rule)
  3. Delete the exception list
  4. Click to update the prebuilt rule A

Current behavior:
'Rule failed to update' message is displayed and rule is not updated.

Expected behavior:
Rule is updated successful

Screenshots

Screen.Recording.2024-11-04.at.11.36.20.AM.mov

Update works fine in 2nd attempt:

Screen.Recording.2024-11-04.at.11.37.37.AM.mov
@pborgonovi pborgonovi added bug Fixes for quality problems that affect the customer experience impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team triage_needed labels Nov 4, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detection-rule-management (Team:Detection Rule Management)

@pborgonovi pborgonovi changed the title [Security Solution] 'Rule failed to update' message is displayed when user attempts to upgrade a rule linked to a deleted shared exception list [Security Solution] 'Rule failed to update' message is displayed and rule is not updated when user attempts to upgrade a rule linked to a deleted shared exception list Nov 4, 2024
@pborgonovi
Copy link
Contributor Author

Issue is reproducible on 8.15:

Screen.Recording.2024-11-04.at.12.02.49.PM.mov

@pborgonovi pborgonovi changed the title [Security Solution] 'Rule failed to update' message is displayed and rule is not updated when user attempts to upgrade a rule linked to a deleted shared exception list [Security Solution]Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list Nov 4, 2024
@banderror banderror changed the title [Security Solution]Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list [Security Solution] Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list Nov 5, 2024
@banderror banderror added Feature:Rule Exceptions Security Solution Detection Rule Exceptions area Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area and removed triage_needed labels Nov 5, 2024
@banderror banderror removed their assignment Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Prebuilt Detection Rules Security Solution Prebuilt Detection Rules area Feature:Rule Exceptions Security Solution Detection Rule Exceptions area impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team:Detection Rule Management Security Detection Rule Management Team Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Projects
None yet
Development

No branches or pull requests

3 participants