No description
Find a file
Frank Hassanabad 3e10276b20
[SIEM][Detection Engine] Fixes bug with timeline templates not working
### Summary

Fixes a bug with the timeline templates not working when specifying filters.

* Creates a type safe mechanism for getting StringArrays or regular strings
* AddsType Script function returns to functions in the helpers file
* Adds unit tests for the effected areas of code and corner cases

Before this fix you would get these toaster errors if you tried to use a template name such as `host.name` in the timeline filters:

<img width="677" alt="Screen Shot 2020-03-18 at 12 58 01 AM" src="https://user-images.githubusercontent.com/1151048/76934058-0bd2fc80-68b4-11ea-8dad-7c257bb81a1d.png">

After this fix it will work for you.

Testing:

1) Create a timeline template that has a host.name as both a query and a filter such as this. You can give the value of the host.name any value such as placeholder.

<img width="1125" alt="Screen Shot 2020-03-18 at 12 56 04 AM" src="https://user-images.githubusercontent.com/1151048/76934108-20af9000-68b4-11ea-8a11-4ba9c935506f.png">

2) Create a signal that uses it and produces a lot of signals off of something such as all host names
<img width="1054" alt="Screen Shot 2020-03-18 at 12 50 47 AM" src="https://user-images.githubusercontent.com/1151048/76934198-4f2d6b00-68b4-11ea-8ae3-6de76154cbb7.png">

3) Ensure you select your **Timeline template** you saved by using the drop down
<img width="1071" alt="Screen Shot 2020-03-18 at 12 51 21 AM" src="https://user-images.githubusercontent.com/1151048/76934281-73894780-68b4-11ea-9a2a-a0a9176f28ce.png">

4) Once your signals have run, go to the signals page and send one of the signals for your newly crated rule which has a host name to the timeline from "View in timeline"
<img width="568" alt="Screen Shot 2020-03-18 at 12 52 10 AM" src="https://user-images.githubusercontent.com/1151048/76934365-a4697c80-68b4-11ea-91a5-e0dea7e3e18f.png">

You should notice that your timeline has both the query and the filter set correctly such as this
<img width="1114" alt="Screen Shot 2020-03-18 at 12 56 23 AM" src="https://user-images.githubusercontent.com/1151048/76934432-c105b480-68b4-11ea-9a82-3e8a2da19376.png">


### Other notes

All the different fields you can choose from for templates are:
```
  'host.name',
  'host.hostname',
  'host.domain',
  'host.id',
  'host.ip',
  'client.ip',
  'destination.ip',
  'server.ip',
  'source.ip',
  'network.community_id',
  'user.name',
  'process.name',
```

And it should not work with anything outside of those. You should be able to mix and match them into different filters and queries to have a multiples of them.

### Checklist

- [x] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios
2020-03-18 11:00:44 -06:00
.ci Fix visual baseline job (#59348) 2020-03-05 13:01:42 -07:00
.github Update ingest management team handle (#60457) 2020-03-17 16:15:27 -07:00
bin Update node options Initialization on our scripts (#40302) 2019-08-15 16:09:22 +01:00
common/graphql
config Instrument Kibana with APM RUM agent (#44281) 2019-12-18 12:16:15 +01:00
data
docs [Visualize] Duplicated query filters in es request (#60106) 2020-03-18 18:06:59 +03:00
examples Embeddable API cleanup (#60207) 2020-03-16 15:37:42 -04:00
licenses
packages Upgrade @types/node to match Node.js runtime (#60368) 2020-03-18 14:27:56 +01:00
rfcs [skip-ci] Service Status RFC (#59621) 2020-03-16 09:23:58 -06:00
scripts The scripts/backport.js file isn't an executable (#59800) 2020-03-10 22:06:56 +01:00
src [NP] Cutover ensureDefaultIndexPattern to kibana_utils (#59895) 2020-03-18 18:28:22 +03:00
tasks fix karma debug typo (#60029) 2020-03-12 13:13:58 -05:00
test FTR configurable test users (#52431) 2020-03-17 10:41:23 -07:00
typings Downgrade to query-string v5.1.1 (#59633) 2020-03-13 17:27:09 +03:00
utilities
vars Skip CI based on changes in PR (#59939) 2020-03-12 11:06:53 -04:00
webpackShims build immutable bundles for new platform plugins (#53976) 2020-02-12 19:42:42 -07:00
x-pack [SIEM][Detection Engine] Fixes bug with timeline templates not working 2020-03-18 11:00:44 -06:00
.backportrc.json
.browserslistrc build immutable bundles for new platform plugins (#53976) 2020-02-12 19:42:42 -07:00
.editorconfig
.eslintignore Migrate existing Cypress tests to Cypress + Cucumber (#57299) 2020-02-26 11:00:54 -08:00
.eslintrc.js skips 'config_open.ts' files from linter check (#60248) 2020-03-16 15:13:03 +01:00
.gitattributes
.gitignore Revert "Using re2 for Timelion regular expressions (#55208)" 2020-03-13 09:14:20 -07:00
.i18nrc.json rename dashboard_embeddable_container to dashboard (#59898) 2020-03-13 12:55:21 -04:00
.node-version
.nvmrc
.prettierrc
.sass-lint.yml
.yarnrc
api-documenter.json
CONTRIBUTING.md docs(NA): add node-gyp setup instructions to the contributing guide. (#60116) 2020-03-13 18:29:41 +00:00
FAQ.md
github_checks_reporter.json
Gruntfile.js
Jenkinsfile Skip CI based on changes in PR (#59939) 2020-03-12 11:06:53 -04:00
kibana.d.ts
LICENSE.txt
NOTICE.txt
package.json Upgrade @types/node to match Node.js runtime (#60368) 2020-03-18 14:27:56 +01:00
preinstall_check.js
README.md
renovate.json5 [Ingest] Add Fleet & EPM features (#59376) 2020-03-12 18:52:06 -04:00
STYLEGUIDE.md
tsconfig.browser.json
tsconfig.json
tsconfig.types.json
TYPESCRIPT.md
yarn.lock Upgrade @types/node to match Node.js runtime (#60368) 2020-03-18 14:27:56 +01:00

Kibana

Kibana is your window into the Elastic Stack. Specifically, it's a browser-based analytics and search dashboard for Elasticsearch.

Getting Started

If you just want to try Kibana out, check out the Elastic Stack Getting Started Page to give it a whirl.

If you're interested in diving a bit deeper and getting a taste of Kibana's capabilities, head over to the Kibana Getting Started Page.

Using a Kibana Release

If you want to use a Kibana release in production, give it a test run, or just play around:

Building and Running Kibana, and/or Contributing Code

You might want to build Kibana locally to contribute some code, test out the latest features, or try out an open PR:

Documentation

Visit Elastic.co for the full Kibana documentation.

For information about building the documentation, see the README in elastic/docs.

Version Compatibility with Elasticsearch

Ideally, you should be running Elasticsearch and Kibana with matching version numbers. If your Elasticsearch has an older version number or a newer major number than Kibana, then Kibana will fail to run. If Elasticsearch has a newer minor or patch number than Kibana, then the Kibana Server will log a warning.

Note: The version numbers below are only examples, meant to illustrate the relationships between different types of version numbers.

Situation Example Kibana version Example ES version Outcome
Versions are the same. 5.1.2 5.1.2 💚 OK
ES patch number is newer. 5.1.2 5.1.5 ⚠️ Logged warning
ES minor number is newer. 5.1.2 5.5.0 ⚠️ Logged warning
ES major number is newer. 5.1.2 6.0.0 🚫 Fatal error
ES patch number is older. 5.1.2 5.1.0 ⚠️ Logged warning
ES minor number is older. 5.1.2 5.0.0 🚫 Fatal error
ES major number is older. 5.1.2 4.0.0 🚫 Fatal error

Questions? Problems? Suggestions?

  • If you've found a bug or want to request a feature, please create a GitHub Issue. Please check to make sure someone else hasn't already created an issue for the same topic.
  • Need help using Kibana? Ask away on our Kibana Discuss Forum and a fellow community member or Elastic engineer will be glad to help you out.