Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] Add #102146 to the 7.13.2 RN as a known issue #764

Closed
nastasha-solomon opened this issue Jun 15, 2021 · 1 comment
Closed

[BUG] Add #102146 to the 7.13.2 RN as a known issue #764

nastasha-solomon opened this issue Jun 15, 2021 · 1 comment
Assignees
Labels

Comments

@nastasha-solomon
Copy link
Contributor

nastasha-solomon commented Jun 15, 2021

Add a new section to the Security RN for 7.13.2 and document elastic/kibana#102146 as a known issue using the following summary and workaround.

Summary: The following ML rules contain incorrectly configured ML job IDs (underscores were used in place of dashes between words) and cannot be successfully activated after they are enabled. Running these rules will cause an error message to display, indicating that an error occurred during the rule's execution. This issue is present in 7.13, 7.13.1, and 7.13.2.

  • high-count-by-destination-country
  • high-count-network-denies
  • high-count-network-events
  • rare-destination-country

Workaround: Duplicate the rule and edit it using these steps:

  1. Go to the Detections page and select Manage detection rules.
  2. Filter the Rules table to only display rules with the ML tag and search for the ML rule you want to duplicate.
  3. Select the rule you want to duplicate and click Bulk actions --> Duplicate selected.
  4. Select the duplicated rule and click Edit rule settings.
  5. From the Definition tab, enter the correct ML Job ID. For example, to fix the incorrectly configured high_count_by_destination_country ML rule job ID, enter high-count-by-destination-country. Click Save changes after you've finished.
  6. Delete the prebuilt ML job.

Above information was grabbed from this Slack convo.

@nastasha-solomon nastasha-solomon self-assigned this Jun 15, 2021
@nastasha-solomon nastasha-solomon changed the title [BUG] Add #102146 to the 7.13 RN as a known issue [BUG] Add #102146 to the 7.13.2 RN as a known issue Jun 15, 2021
@nastasha-solomon
Copy link
Contributor Author

Merged #765.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant