Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution][Detection] Not all Alert components refresh upon change alert status action #108244

Closed
spong opened this issue Aug 11, 2021 · 9 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience Feature:Detection Alerts Security Solution Detection Alerts Feature fixed impact:critical This issue should be addressed immediately due to a critical level of impact on the product. Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: rac label obsolete v7.15.0

Comments

@spong
Copy link
Member

spong commented Aug 11, 2021

When alerts change status (either via the Alerts Table take action menu, Alerts Table row overflow menu, or Alert Details take action menu), not all of the components on the page are refreshed to reflect the change. Upon alert status change the following components should refresh:

  • Last alert component
  • Histogram
  • Count
  • Alerts Table

Should be able to trigger a global page refresh via redux within the status change actions that way all current and future occurrences are covered.

Related: #107249

@spong spong added bug Fixes for quality problems that affect the customer experience Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Feature:Detection Alerts Security Solution Detection Alerts Feature v7.15.0 labels Aug 11, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@MadameSheema
Copy link
Member

As part of this ticket, we need to remember to unskip the following Cypress test: Creates an exception and deletes it in x-pack/plugins/security_solution/cypress/integration/exceptions/from_alert.spec.ts as soon as the issue is fixed.

@MadameSheema
Copy link
Member

@deepikakeshav-qasource can you please validate the fix of this issue in 7.15BC6? Thanks :)

@ghost
Copy link

ghost commented Sep 15, 2021

Hi @MadameSheema,

We have validated this ticket on 7.15.0 BC6 build and We found that we are unable to update the alert status from Timeline. Please find the below observations for more details:

Build Details:

Version:7.15.0 BC6
Commit:ab43f574e8ea01f5093fe92b2f51c4b686eb6e63
Build:44026
  • Refresh the all components when change alert status from take action under alert table 🟢
take.action.mp4
  • Refresh the all components when change alert status from more action under alert table 🟢
more_action.mp4
  • Refresh the all components when change alert status from rule details page. 🟢
rule_details.mp4
  • Refresh the all components when change alert status from view details icon. 🟢
refresh.2.mp4
  • Refresh the all components when change alert status from exception under alerts table. 🟢
external_alerts.mp4
  • Refresh the all components when change alert status from exception under rule details. 🟢

  • Unable to update the alert status from Timeline. 🔴

timeline.mp4

Thanks!!

@MadameSheema
Copy link
Member

Hi @deepikakeshav-qasource can you please close this ticket and open a different one for the Unable to update the alert status from Timeline? We saw also that on the timeline, when you open the alerts details flyout the take action button it is not displayed at the bottom. Can you please open a ticket for that issue as well? If the issue is already reported, please,share the link of the ticket here. Lots of thanks :)

@rylnd
Copy link
Contributor

rylnd commented Sep 15, 2021

Hi @deepikakeshav-qasource can you please close this ticket and open a different one for the Unable to update the alert status from Timeline?

@deepikakeshav-qasource @MadameSheema @peluja1012 FYI @dplumlee plans to address this issue as part of #112169.

@dplumlee
Copy link
Contributor

I opened another ticket a couple days ago tracking this as well #112011

@ghost
Copy link

ghost commented Sep 16, 2021

Hi Team,

Thank you for the update!!

I opened another ticket a couple days ago tracking this as well #112011

Hence, We are closing this ticket.

Thanks!!

@ghost ghost closed this as completed Sep 16, 2021
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Feature:Detection Alerts Security Solution Detection Alerts Feature fixed impact:critical This issue should be addressed immediately due to a critical level of impact on the product. Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: rac label obsolete v7.15.0
Projects
None yet
Development

No branches or pull requests

6 participants