Go to file
Frank Hassanabad c643148f36
[SIEM][Detection Engine] Fix rule notification critical bugs
## Summary

Fixes critical bugs found during testing of the rule notification.

* Fixes a bug where when you turn on rules quickly such as ML rules you would see these message below. This message can also be seen when you first create a rule with an action notification. This is a race condition with how we update rules multiple times when we really should only update it once and do it before enabling a rule

```
server    log   [12:18:35.986] [error][alerting][alerting][plugins][plugins] Executing Alert "63b828b5-24b9-4d55-83ee-8a8201fe2d76" has resulted in Error: [security_exception] missing authentication credentials for REST request [/_security/user/_has_privileges], with { header={ WWW-Authenticate={ 0="Bearer realm=\"security\"" & 1="ApiKey" & 2="Basic realm=\"security\" charset=\"UTF-8\"" } } 
``` 

* Fixes a bug where we were using `ruleParams.interval` when we should have been using `ruleAlertSavedObject.attributes.schedule.interval`. When changing rule notifications to run daily, weekly, etc.. you would see this exception being thrown:

```
server    log   [21:23:08.028] [error][alerting][alerting][plugins][plugins] Executing Alert "fedcccc0-7c69-4e2f-83f8-d8ee88ab5484" has resulted in Error: "from" or "to" was not provided to signals count query
```

* Fixes misc typing issues found
* Fixes it to where we no longer make multiple DB calls but rather pass down objects we already have.
* Changes the work flow to where we only update, create, or patch the alerting object once which fixes the race condition and improves the backend performance.
* Removes left over unused code
* Applied https://en.wikipedia.org/wiki/Single-entry_single-exit to functions where it made sense and easier to read.


### Checklist

- [x] [Unit or functional tests](https://github.com/elastic/kibana/blob/master/CONTRIBUTING.md#cross-browser-compatibility) were updated or added to match the most common scenarios
2020-04-08 17:36:20 -06:00
.ci [jenkins] refer to sizes in most pipeline code (#62082) 2020-04-04 07:11:31 -07:00
.github Remove ES-UI as code owner of Transform app. (#62556) 2020-04-06 09:49:23 -07:00
bin
common/graphql
config Instrument Kibana with APM RUM agent (#44281) 2019-12-18 12:16:15 +01:00
data
docs Add basic StatusService (#60335) 2020-04-08 13:16:32 -06:00
examples Prep for embed saved object refactor + helper (#62486) 2020-04-06 13:45:46 -04:00
licenses
packages FTR: add chromium-based Edge browser support (#61684) 2020-04-09 00:08:21 +03:00
rfcs [skip-ci] Service Status RFC (#59621) 2020-03-16 09:23:58 -06:00
scripts The scripts/backport.js file isn't an executable (#59800) 2020-03-10 22:06:56 +01:00
src Index pattern management plugin - src/legacy/core_plugins/management => new platform plugin (#62594) 2020-04-08 15:10:44 -05:00
tasks Update cache-control header (#62014) 2020-04-06 10:19:42 -04:00
test FTR: add chromium-based Edge browser support (#61684) 2020-04-09 00:08:21 +03:00
typings [Telemetry] update crypto packages (#62469) 2020-04-07 00:36:15 +03:00
utilities remove use of experimental fs.promises api (#53346) 2019-12-25 06:27:21 -07:00
vars [jenkins] refer to sizes in most pipeline code (#62082) 2020-04-04 07:11:31 -07:00
webpackShims [kbn/ui-shared-deps] expand and split (#62364) 2020-04-03 14:11:36 -07:00
x-pack [SIEM][Detection Engine] Fix rule notification critical bugs 2020-04-08 17:36:20 -06:00
.backportrc.json chore(na): add 7.7 branch to the list of branches to backport (#61240) 2020-03-25 07:21:27 -07:00
.browserslistrc build immutable bundles for new platform plugins (#53976) 2020-02-12 19:42:42 -07:00
.editorconfig
.eslintignore Migrate existing Cypress tests to Cypress + Cucumber (#57299) 2020-02-26 11:00:54 -08:00
.eslintrc.js [NP] Vis Default Editor plugin (#62475) 2020-04-08 12:00:13 +03:00
.gitattributes
.gitignore [APM] E2E: Zero config for running e2e locally (#59152) 2020-03-24 20:28:11 +01:00
.i18nrc.json Index pattern management plugin - src/legacy/core_plugins/management => new platform plugin (#62594) 2020-04-08 15:10:44 -05:00
.node-version Update Node.js to version 10.19.0 (#56940) 2020-02-05 21:57:43 -08:00
.nvmrc Update Node.js to version 10.19.0 (#56940) 2020-02-05 21:57:43 -08:00
.prettierrc
.sass-lint.yml License checks for actions plugin (#59070) 2020-03-20 10:49:37 -04:00
.yarnrc
api-documenter.json Normalize EOL symbol in platform docs (#56021) 2020-01-27 18:42:45 +01:00
CONTRIBUTING.md docs(NA): add node-gyp setup instructions to the contributing guide. (#60116) 2020-03-13 18:29:41 +00:00
FAQ.md
github_checks_reporter.json
Gruntfile.js autofix all violations 2019-12-13 23:17:13 -07:00
Jenkinsfile Only run xpack siem cypress in PRs when there are siem changes (#60661) 2020-03-23 10:30:14 -04:00
kibana.d.ts Move src/legacy/server/index_patterns to data plugin (server) (Remove step) (#61618) 2020-04-02 12:53:14 +03:00
LICENSE.txt
NOTICE.txt [ui/utils/query_string]: Remove unused methods & migrate apps to querystring lib (#56957) 2020-02-12 19:51:03 +03:00
package.json FTR: add chromium-based Edge browser support (#61684) 2020-04-09 00:08:21 +03:00
preinstall_check.js
README.md
renovate.json5 [optimizer] validate the syntax of bundled node_modules (#59972) 2020-03-30 15:59:43 -07:00
STYLEGUIDE.md Remove Kibana a11y guide in favor of EUI (#57021) 2020-02-07 10:55:29 -05:00
tsconfig.browser.json
tsconfig.json [Metric] convert mocha tests to jest (#54054) 2020-01-17 12:00:35 -06:00
tsconfig.types.json
TYPESCRIPT.md Update deprecated React.SFC and React.StatelessComponent types (#50852) 2019-11-21 20:53:54 +01:00
yarn.lock FTR: add chromium-based Edge browser support (#61684) 2020-04-09 00:08:21 +03:00

Kibana

Kibana is your window into the Elastic Stack. Specifically, it's a browser-based analytics and search dashboard for Elasticsearch.

Getting Started

If you just want to try Kibana out, check out the Elastic Stack Getting Started Page to give it a whirl.

If you're interested in diving a bit deeper and getting a taste of Kibana's capabilities, head over to the Kibana Getting Started Page.

Using a Kibana Release

If you want to use a Kibana release in production, give it a test run, or just play around:

Building and Running Kibana, and/or Contributing Code

You might want to build Kibana locally to contribute some code, test out the latest features, or try out an open PR:

Documentation

Visit Elastic.co for the full Kibana documentation.

For information about building the documentation, see the README in elastic/docs.

Version Compatibility with Elasticsearch

Ideally, you should be running Elasticsearch and Kibana with matching version numbers. If your Elasticsearch has an older version number or a newer major number than Kibana, then Kibana will fail to run. If Elasticsearch has a newer minor or patch number than Kibana, then the Kibana Server will log a warning.

Note: The version numbers below are only examples, meant to illustrate the relationships between different types of version numbers.

Situation Example Kibana version Example ES version Outcome
Versions are the same. 5.1.2 5.1.2 💚 OK
ES patch number is newer. 5.1.2 5.1.5 ⚠️ Logged warning
ES minor number is newer. 5.1.2 5.5.0 ⚠️ Logged warning
ES major number is newer. 5.1.2 6.0.0 🚫 Fatal error
ES patch number is older. 5.1.2 5.1.0 ⚠️ Logged warning
ES minor number is older. 5.1.2 5.0.0 🚫 Fatal error
ES major number is older. 5.1.2 4.0.0 🚫 Fatal error

Questions? Problems? Suggestions?

  • If you've found a bug or want to request a feature, please create a GitHub Issue. Please check to make sure someone else hasn't already created an issue for the same topic.
  • Need help using Kibana? Ask away on our Kibana Discuss Forum and a fellow community member or Elastic engineer will be glad to help you out.