-
Notifications
You must be signed in to change notification settings - Fork 76
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Alerts not working with custom detection rule #1227
Labels
bug
Something isn't working
Comments
duzvik
changed the title
[BUG] In custom detection rule
[BUG] Alerts not working with custom detection rule
Aug 8, 2024
updates cluster + plugin to latest(2.16.0) error message in logs:
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
What is the bug?
Alerts not working with custom detection rule.
How can one reproduce the bug?
A new detection rule(yaml) adde with API call /_plugins/_security_analytics/rules?category=windows
Enable this rule in "Active rules" section
Alerting doesn't work.
If I disable custom rule - everything works fine.
What is the expected behavior?
A clear and concise description of what you expected to happen.
What is your host/environment?
Do you have any additional context?
yaml file:
API request to POST /_plugins/_security_analytics/rules/_search?pre_packaged=false
shows that generated query looks like:
seems
_ws_
is used for space.error log:
The text was updated successfully, but these errors were encountered: