Comments (10)
@tomsonpl ,
Yes, and no.
For endpoint, we do allow isolate
to be create for hosts that are already isolated (similar with release
). For SentinelOne, Patryk implemented code in the Connector that first checks that the host is in the correct state. Not sure why that was done that way - perhaps the S1 system rejects it? 🤷
That being said - this is expected behaviour for HTTP API requests for all agent types - meaning: if there is an error along the way, we don't create the action documents because that could just fill up the index with "junk".
Note, however, that automated response actions behaviour is a bit different because there is no user behind it. For automated response actions, we do create a failed response action in this case.
from kibana.
@muskangulati-qasource Thanks for bringing this up. This is expected as the action request is not created. We show response history for actions that are actually created and that have pending/failed/successful responses.
from kibana.
Pinging @elastic/security-defend-workflows (Team:Defend Workflows)
from kibana.
@ashokaditya could you take a closer look to this one?
from kibana.
Out of curiosity, is this expected only for S1 actions, or also Endpoint's ?
from kibana.
Thanks @paul-tavares :)
from kibana.
@ashokaditya @paul-tavares can we close this as won't do then?
cc: @arvindersingh-qasource
from kibana.
Yes - it should be closed. Its working as intended.
from kibana.
Thank you for the update @dasansol92 and @paul-tavares .
We are closing this issue as it is WORKING AS DESIGNED. We will keep note of the same.
Thank you!
from kibana.
Bug Conversion
No Test case is required since it is expected behavior!
Thanks!
from kibana.
Related Issues (20)
- Refactor CHIPS support once statehood has partitioned cookie option
- Failing test: Chrome UI Functional Tests.test/functional/apps/discover/esql/_esql_view·ts - discover/esql discover esql view ES|QL in Discover should query an index pattern that doesnt translate to a dataview correctly HOT 3
- [OneDiscover][UnifiedDocViewer] Allow filtering by field type HOT 1
- [Security Solution] Detection Engine - Failing EQL test in Serverless MKI HOT 1
- [ML] Data Drift: Baseline and comparison brushes drift on entering/exiting browser's full screen HOT 1
- [ML] Data Frame Analytics: 'Is not included' filter not working as expected HOT 1
- Test issue HOT 1
- [APM] Service inventory page title has [object object] HOT 1
- Watcher execution details fails to load HOT 1
- [Infra][APM] Create a service in `apm_data_access` to provide APM collected host names HOT 1
- [Infra] Consider only docs from system integration in the hosts view HOT 2
- [Infra] Change host count KPI query HOT 1
- [APM] Replace any reference to `identityFields` HOT 3
- [EEM] Undefined `failedTransactionRate` metric from service entity definition
- [EEM] Discrepancy between `throughput` metric from service entity definition and apm-server
- [ES|QL] Add shortcut for toggling 'break on pipes' HOT 3
- [Dashboard] Adding links or maps saved object from Add from library action to dashboard doesn't display addition was successful message HOT 2
- [Alerting] User shouldn't be able to click on untracked for already untracked alerts HOT 1
- [Alerts] User should be able to unmute a muted alert by clicking on the bell HOT 1
- [Security Solution] [Security Assistant] Error toaster on Alerts page after starting a trial license or upgrading to Enterprise until Kibana server is restarted HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from kibana.