[Security Solution] Rule is not updated and is followed by 'Rule failed to update' message when user attempts to upgrade a rule linked to a deleted shared exception list #198845
Labels
bug
Fixes for quality problems that affect the customer experience
Feature:Prebuilt Detection Rules
Security Solution Prebuilt Detection Rules area
Feature:Rule Exceptions
Security Solution Detection Rule Exceptions area
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
Team:Detection Rule Management
Security Detection Rule Management Team
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Epics: https://github.com/elastic/security-team/issues/1974 (internal), #179907
Related to: #198771, #178221
Location: Rule Management page, Rule Updates table
Summary
Describe the bug:
When the user attempts to upgrade a prebuilt rule which was linked to a shared exception list that has been deleted, a 'Rule failed to update' message is displayed and the rule is not updated. It works properly in the second attempt.
No error is observed in the API calls.
Note: Reproducible on 8.15
Kibana/Elasticsearch Stack version:
8.16
Pre requisites:
Steps to reproduce:
Current behavior:
'Rule failed to update' message is displayed and rule is not updated.
Expected behavior:
Rule is updated successful
Screenshots
Screen.Recording.2024-11-04.at.11.36.20.AM.mov
Update works fine in 2nd attempt:
Screen.Recording.2024-11-04.at.11.37.37.AM.mov
The text was updated successfully, but these errors were encountered: