[Security Solution] Preview Histogram displays duplicate alerts based on stackBy
field
#129664
Labels
8.5 candidate
bug
Fixes for quality problems that affect the customer experience
impact:low
Addressing this issue will have a low level of impact on the quality/strength of our product.
Team:Detection Alerts
Security Detection Alerts Area Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
Overview
There is a bug currently in the rule preview feature with the histogram and alert table having incongruent alert/hit counts. The bug is caused by the
stackBy
field in the histogram (currently set asevent.category
) counting certain alerts multiple times if they have 2 or moreevent.category
fields. Discussion needs to be held as to what the best approach to fixing this within the confines of the8.2
release and perhaps ways we can adjust it going forwardScreenshots
The text was updated successfully, but these errors were encountered: