You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add a new section to the Security RN for 7.13.2 and document elastic/kibana#102146 as a known issue using the following summary and workaround.
Summary: The following ML rules contain incorrectly configured ML job IDs (underscores were used in place of dashes between words) and cannot be successfully activated after they are enabled. Running these rules will cause an error message to display, indicating that an error occurred during the rule's execution. This issue is present in 7.13, 7.13.1, and 7.13.2.
high-count-by-destination-country
high-count-network-denies
high-count-network-events
rare-destination-country
Workaround: Duplicate the rule and edit it using these steps:
Go to the Detections page and select Manage detection rules.
Filter the Rules table to only display rules with the ML tag and search for the ML rule you want to duplicate.
Select the rule you want to duplicate and click Bulk actions --> Duplicate selected.
Select the duplicated rule and click Edit rule settings.
From the Definition tab, enter the correct ML Job ID. For example, to fix the incorrectly configured high_count_by_destination_country ML rule job ID, enter high-count-by-destination-country. Click Save changes after you've finished.
Add a new section to the Security RN for 7.13.2 and document elastic/kibana#102146 as a known issue using the following summary and workaround.
Summary: The following ML rules contain incorrectly configured ML job IDs (underscores were used in place of dashes between words) and cannot be successfully activated after they are enabled. Running these rules will cause an error message to display, indicating that an error occurred during the rule's execution. This issue is present in 7.13, 7.13.1, and 7.13.2.
Workaround: Duplicate the rule and edit it using these steps:
ML
tag and search for the ML rule you want to duplicate.high_count_by_destination_country
ML rule job ID, enterhigh-count-by-destination-country
. Click Save changes after you've finished.Above information was grabbed from this Slack convo.
The text was updated successfully, but these errors were encountered: