Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Copies over settings from timeline template #190511

Merged
merged 4 commits into from
Aug 14, 2024

Conversation

logeekal
Copy link
Contributor

@logeekal logeekal commented Aug 14, 2024

Summary

Handles : #189992

When user had created a timeline template and attached it to the rule, the columns were not being copied over from template to the timeline created from the alert generated by same rule.

This PR fixes that as shown in demo below :

timeline_columns_copy_fix.mp4

Caution

This PR checks below objects that are needed to be copied over from template

  • columns
  • data providers

If we think, more things should be copied over, please comment below.

Test Results

grafik

Checklist

Delete any items that are not applicable to this PR.

@logeekal logeekal added release_note:fix Team:Threat Hunting:Investigations Security Solution Investigations Team backport:prev-minor Backport to (9.0) the previous minor version (i.e. one version back from main) v8.15.1 labels Aug 14, 2024
@logeekal logeekal requested a review from a team as a code owner August 14, 2024 13:04
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations)

@@ -160,7 +170,7 @@ export const useInvestigateInTimeline = ({
notes: [],
timeline: {
...timeline,
columns: !unifiedComponentsInTimelineDisabled ? defaultUdtHeaders : defaultHeaders,
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

so this was only broken by introduction of this feature flag?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No it was broken in 8.14 as well and becuase of that this feature flag replaced that broken code and produced same output.

Copy link
Contributor Author

@logeekal logeekal Aug 14, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually, I retract my statement. Yes unified components changes broke it but initial feature flag was introduced in 8.14 and that is why it was broken in 8.14 also.

@logeekal logeekal enabled auto-merge (squash) August 14, 2024 14:57
@kibana-ci
Copy link
Collaborator

💛 Build succeeded, but was flaky

Failed CI Steps

Metrics [docs]

Async chunks

Total size of all lazy-loaded chunks that will be downloaded as the user navigates the app

id before after diff
securitySolution 20.7MB 20.7MB +380.0B
Unknown metric groups

ESLint disabled line counts

id before after diff
securitySolution 536 537 +1

Total ESLint disabled count

id before after diff
securitySolution 621 622 +1

History

To update your PR or re-run it, just comment with:
@elasticmachine merge upstream

@logeekal logeekal merged commit a13f8d9 into elastic:main Aug 14, 2024
40 checks passed
kibanamachine pushed a commit to kibanamachine/kibana that referenced this pull request Aug 14, 2024
…tic#190511)

## Summary

Handles : elastic#189992

When user had created a timeline template and attached it to the rule,
the columns were not being copied over from template to the timeline
created from the alert generated by same rule.

This PR fixes that as shown in demo below :

https://github.com/user-attachments/assets/4237672e-943a-43f9-b160-5449399a5fd8

> [!Caution]
> This PR checks below objects that are needed to be copied over from
template
> - columns
> - data providers
>
> If we think, more things should be copied over, please comment below.

## Test Results

![grafik](https://github.com/user-attachments/assets/ad527eda-a1c2-49f0-bcfe-0ea449c29b34)

### Checklist

Delete any items that are not applicable to this PR.

- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios

(cherry picked from commit a13f8d9)
@kibanamachine
Copy link
Contributor

💚 All backports created successfully

Status Branch Result
8.15

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Aug 14, 2024
#190511) (#190530)

# Backport

This will backport the following commits from `main` to `8.15`:
- [[Security Solution] Copies over settings from timeline template
(#190511)](#190511)

<!--- Backport version: 9.4.3 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sqren/backport)

<!--BACKPORT [{"author":{"name":"Jatin
Kathuria","email":"jatin.kathuria@elastic.co"},"sourceCommit":{"committedDate":"2024-08-14T16:27:14Z","message":"[Security
Solution] Copies over settings from timeline template (#190511)\n\n##
Summary\r\n\r\nHandles :
https://github.com/elastic/kibana/issues/189992\r\n\r\nWhen user had
created a timeline template and attached it to the rule,\r\nthe columns
were not being copied over from template to the timeline\r\ncreated from
the alert generated by same rule.\r\n\r\nThis PR fixes that as shown in
demo below :
\r\n\r\n\r\nhttps://github.com/user-attachments/assets/4237672e-943a-43f9-b160-5449399a5fd8\r\n\r\n>
[!Caution]\r\n> This PR checks below objects that are needed to be
copied over from\r\ntemplate\r\n> - columns\r\n> - data
providers\r\n>\r\n> If we think, more things should be copied over,
please comment below.\r\n\r\n## Test
Results\r\n\r\n\r\n![grafik](https://github.com/user-attachments/assets/ad527eda-a1c2-49f0-bcfe-0ea449c29b34)\r\n\r\n\r\n\r\n###
Checklist\r\n\r\nDelete any items that are not applicable to this
PR.\r\n\r\n- [x] [Unit or
functional\r\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\r\nwere
updated or added to match the most common
scenarios","sha":"a13f8d983c38736478f2430efa090fedb1c50784","branchLabelMapping":{"^v8.16.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Threat
Hunting:Investigations","backport:prev-minor","v8.16.0","v8.15.1"],"title":"[Security
Solution] Copies over settings from timeline
template","number":190511,"url":"https://github.com/elastic/kibana/pull/190511","mergeCommit":{"message":"[Security
Solution] Copies over settings from timeline template (#190511)\n\n##
Summary\r\n\r\nHandles :
https://github.com/elastic/kibana/issues/189992\r\n\r\nWhen user had
created a timeline template and attached it to the rule,\r\nthe columns
were not being copied over from template to the timeline\r\ncreated from
the alert generated by same rule.\r\n\r\nThis PR fixes that as shown in
demo below :
\r\n\r\n\r\nhttps://github.com/user-attachments/assets/4237672e-943a-43f9-b160-5449399a5fd8\r\n\r\n>
[!Caution]\r\n> This PR checks below objects that are needed to be
copied over from\r\ntemplate\r\n> - columns\r\n> - data
providers\r\n>\r\n> If we think, more things should be copied over,
please comment below.\r\n\r\n## Test
Results\r\n\r\n\r\n![grafik](https://github.com/user-attachments/assets/ad527eda-a1c2-49f0-bcfe-0ea449c29b34)\r\n\r\n\r\n\r\n###
Checklist\r\n\r\nDelete any items that are not applicable to this
PR.\r\n\r\n- [x] [Unit or
functional\r\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\r\nwere
updated or added to match the most common
scenarios","sha":"a13f8d983c38736478f2430efa090fedb1c50784"}},"sourceBranch":"main","suggestedTargetBranches":["8.15"],"targetPullRequestStates":[{"branch":"main","label":"v8.16.0","branchLabelMappingKey":"^v8.16.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/190511","number":190511,"mergeCommit":{"message":"[Security
Solution] Copies over settings from timeline template (#190511)\n\n##
Summary\r\n\r\nHandles :
https://github.com/elastic/kibana/issues/189992\r\n\r\nWhen user had
created a timeline template and attached it to the rule,\r\nthe columns
were not being copied over from template to the timeline\r\ncreated from
the alert generated by same rule.\r\n\r\nThis PR fixes that as shown in
demo below :
\r\n\r\n\r\nhttps://github.com/user-attachments/assets/4237672e-943a-43f9-b160-5449399a5fd8\r\n\r\n>
[!Caution]\r\n> This PR checks below objects that are needed to be
copied over from\r\ntemplate\r\n> - columns\r\n> - data
providers\r\n>\r\n> If we think, more things should be copied over,
please comment below.\r\n\r\n## Test
Results\r\n\r\n\r\n![grafik](https://github.com/user-attachments/assets/ad527eda-a1c2-49f0-bcfe-0ea449c29b34)\r\n\r\n\r\n\r\n###
Checklist\r\n\r\nDelete any items that are not applicable to this
PR.\r\n\r\n- [x] [Unit or
functional\r\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\r\nwere
updated or added to match the most common
scenarios","sha":"a13f8d983c38736478f2430efa090fedb1c50784"}},{"branch":"8.15","label":"v8.15.1","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Jatin Kathuria <jatin.kathuria@elastic.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport:prev-minor Backport to (9.0) the previous minor version (i.e. one version back from main) release_note:fix Team:Threat Hunting:Investigations Security Solution Investigations Team v8.15.1 v8.16.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants