-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
skip query of detections page when we do not have .siem-signals index #74580
Conversation
Pinging @elastic/siem (Team:SIEM) |
f4ce231
to
a925deb
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Checked out and tested locally and sorting is working without a toaster error on both the Detections and Rule Details pages. Also did a little regression testing around the timeline event type selector and all looked good there as well! 👍 Thanks for clearing this one up for our users @XavierM! LGTM! 🌈 🦋
x-pack/plugins/security_solution/public/timelines/containers/helpers.ts
Outdated
Show resolved
Hide resolved
💚 Build SucceededBuild metrics@kbn/optimizer bundle module count
async chunks size
History
To update your PR or re-run it, just comment with: |
…elastic#74580) * skip query of detections page when we do not have .siem-signals index * review I
…elastic#74580) * skip query of detections page when we do not have .siem-signals index * review I
Pinging @elastic/security-solution (Team: SecuritySolution) |
Summary
This PR is to resolve this issue #74180
If you look at the error toaster you will see this:
data:image/s3,"s3://crabby-images/2d05a/2d05a114c75bb31238114e50345ef78946bb07ac" alt="Screen Shot 2020-08-03 at 3 42 30 PM"
The root of the issue looks to be that when timeline mounts its self it is causing initial queries against the
data:image/s3,"s3://crabby-images/e95e6/e95e61d1120b2e5cd65c69b05833f2599aba893d" alt="Screen Shot 2020-08-03 at 3 43 07 PM"
sime:defaultIndex
and does not have the siem signals:Later queries will be the correct ones which will be just the siem-signals index and not include these extra indexes on page load. We really want to eliminate duplicate queries of timeline when it first mounts and want to eliminate it from querying the
data:image/s3,"s3://crabby-images/80ee0/80ee00bcf8b384489f2e33b581724945192e5bfb" alt="Screen Shot 2020-08-03 at 3 54 25 PM"
siem:defaultIndex
on page load. You do run the risk of the second query taking longer than the first and possibly wrong data on your visualization:Checklist