-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security Solution] Threat Intelligence Overview card not supported on CCS setup #106099
Comments
Pinging @elastic/security-solution (Team: SecuritySolution) |
so it looks like a custom index name is assigned to what would have otherwise been the |
Note: this same issue will also affect the event enrichment query added in #103383, in that it will not support remote clusters. |
@deepikakeshav-qasource can you please validate the fix for this issue on the latest version? (7.15.0) Thanks :) |
Hi @MadameSheema, We have validated this ticket on 7.15.0 Latest build and observed that issue is Still occurring. Threat Intelligence Overview card not supported on CCS setup Build Details:
Screenshot: threat.card.mp4Thanks!! |
@deepikakeshav-qasource can you please retest again adding the CCS index on the |
Thank you for the update!! We have added CCS index in Threat indices placed on the Kibana advanced settings and observed that data is displayed under Threat Intelligence overview card. However, dashboard button is disable. Could you please confirm if it is expected or we are missing something? Screenshots Overview_threat_card.mp4indicator_match.mp4Thanks!! |
@deepikakeshav-qasource did you follow the guide to |
Hi @ecezalp and @MadameSheema , Dashboard button is disable Threat Intelligence overview card for source machine. Please find the below detailed steps:
Note: We did not installed the filebeat on source machine. Could you please confirm if it is expected or we are missing anything? Thanks!! |
@ecezalp any update regarding the above comment? |
To summarize: the bug as currently stated is that dashboard links don't work for remote clusters, despite the remote cluster having the necessary dashboards. Since those dashboards are kibana data (saved objects), and the current kibana instance has no dashboards, this is expected behavior. Kibana cannot read saved objects from a remote cluster, it can only read from data indices. |
Kibana version:
Describe the bug:
No threat intel data available to display
message displayed on overview page on a CCS with threat intel alerts generated by filebeat with the module enabledInitial status:
Steps to reproduce:
Current behaviour:
Expected behavior:
The text was updated successfully, but these errors were encountered: