Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution]Keyword 'Deleted Rule' is not getting displayed if 'Rule Name' contains more than 55 words. #103051

Closed
ghost opened this issue Jun 23, 2021 · 7 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience fixed impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.14.0

Comments

@ghost
Copy link

ghost commented Jun 23, 2021

Description:
Keyword 'Deleted Rule' is not getting displayed if 'Rule Name' contains more than 55 words.

Build Details:
Version: 7.14.0 snapshot
Build: 41498
Commit: e265826
Artifact link: https://artifacts-api.elastic.co/v1/search/7.14.0-SNAPSHOT

Browser Details:
All

Preconditions:

  • Kibana Environment should exist.
  • Endpoint security and Elastic Agent should be installed
  • Detection alerts should be generated
  • 'Rule Name' should contain more than 55 words

Steps to Reproduce:

  1. Navigate to 'Detections' tab under Security App.
  2. Click on 'Manage Detection Rules' button.
  3. Click on 'Create New Rule' button
  4. Fill-out all the mandatory fields in all the sections and In 'About' section set the Rule Name say 'Testing keyword 'Deleted Rule' is getting display with 'Rule name'.
  5. Click on 'Create and Activate Rule' and wait till the alerts get generated for the rule.
  6. Now, Delete this Rule and navigate to 'Alert Table' present in Detections tab.
  7. Click on the recently deleted 'Rule Name' from Alert table. Notice that user will be navigated to 'Rule Detail' page
  8. Observe that Keyword 'Deleted Rule' is not getting displayed if 'Rule Name' contains more than 55 words.

Impacted Test case:
N/A

Actual Result:
Keyword 'Deleted Rule' is not getting displayed if 'Rule Name' contains more than 55 words.
Screen-Cast:
rule

Expected Result:
Keyword 'Deleted Rule' should be displayed along with the Rule Name on deleting any rule.

What's not working:

  • This issue is not occurring if word count is less than 55
  • However, keyword 'Deleted Rule' is getting displayed on the hover text displayed on 'Rule detail' page.

What's working:

  • NA
@ghost ghost added bug Fixes for quality problems that affect the customer experience impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. labels Jun 23, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@ghost
Copy link
Author

ghost commented Jun 23, 2021

@manishgupta-qasource Please Review!

Thanks!!

@manishgupta-qasource
Copy link

Reviewed & Assigned to @MadameSheema

@MadameSheema MadameSheema added the Team:Detections and Resp Security Detection Response Team label Jun 23, 2021
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-detections-response (Team:Detections and Resp)

@spong
Copy link
Member

spong commented Jun 23, 2021

To clarify the fix here, the Deleted label should still be present even if the title is truncated.

Label shown with short title

Label not shown with truncated title (but shown in tooltip)

@MadameSheema
Copy link
Member

@mandeepkaur-qasource can you please validate the fix of this issue on the first BC? Thanks :)

@ghost ghost added the QA:Validated Issue has been validated by QA label Jul 7, 2021
@ghost
Copy link
Author

ghost commented Jul 7, 2021

Hi @MadameSheema

We have validated this defect on latest 7.14. 0 BC1 build and found the issue has been Fixed as 'Deleted Rule' badge is now getting displayed if the rule name is long and is getting truncated.

Build Details:
Version: 7.14.0 BC1
Commit:071a74e02f82b79a4a10026b5c9e02d593112fd4
Build:42292
Artifact Page : https://staging.elastic.co/7.14.0-8eba2f5f/summary-7.14.0.html

Please find our observations below:
Screen-Cast:
delete

Hence, we are closing this defect.

Thanks!!

@ghost ghost closed this as completed Jul 7, 2021
This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience fixed impact:medium Addressing this issue will have a medium level of impact on the quality/strength of our product. QA:Validated Issue has been validated by QA Team:Detections and Resp Security Detection Response Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v7.14.0
Projects
None yet
Development

No branches or pull requests

6 participants