Go to file
Frank Hassanabad e5944a3646
[Security Solutions][Detection Engine] Fixes timestamp bugs within source indexes when the formats are not ISO8601 format (#101349)
## Summary

We have a few bugs where when the source index for detections is not `"strict_date_optional_time"` it is possible that we will misinterpret the format to be epoch milliseconds when it could be epoch seconds or another ambiguous format or blow up when trying to write out the signals index. This fixes it to where we query for the source index format as an ISO8601 and when we copy the date time format we copy it back out as ISO8601 and insert it into the signal index as ISO8601.

See this [gist](https://gist.github.com/FrankHassanabad/f614ec9762d59cd1129b3269f5bae41c) for more details of how this was accidentally introduced when we added support for runtime fields and the general idea of the fix.

* Removes `docvalue_field` and we now only use `fields` in detection engine search requests
* Splits out the timestamp e2e tests into their own file for `timestamps` file
* Adds more tests to ensure we copy what we expect and we are converting to ISO8601 in the signals
* Removes `ts-expect-error` in a lot of areas including tests and then I fix the types and issues once it is removed. 

### Checklist

- [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios
2021-06-04 16:19:59 -06:00
.buildkite [CI] Buildkite support with Baseline pipeline (#100492) 2021-06-01 13:11:07 -04:00
.ci [CI] For PRs, build TS refs before public api docs check (#100791) 2021-06-01 21:27:42 -04:00
.github Update CODEOWNERS to ping Stack Management team. (#101350) 2021-06-04 09:22:40 -07:00
api_docs Ensure comments on parameters in arrow functions are captured in the docs and ci metrics. (#100823) 2021-05-28 11:56:31 -04:00
config
dev_docs [dev-docs] Fix expression string syntax (#101419) 2021-06-04 15:02:33 -05:00
docs [DOCS] Updates video in Intor & Maps take 2 (#101330) 2021-06-03 13:36:45 -07:00
examples [Screenshot mode] Create plugin to provide "screenshot mode" awareness (#99627) 2021-05-19 16:03:27 +02:00
licenses
packages Improve Task Manager instrumentation (#99160) 2021-06-04 16:30:11 -04:00
plugins
rfcs [RFC][Maps] Adding a timeslider to Maps (#98355) 2021-05-13 10:39:37 -04:00
scripts
src Saved object export: apply export hooks to referenced / nested objects (#100769) 2021-06-04 14:46:05 +02:00
tasks/config
test [ts] migrate root test dir to project refs (#99148) 2021-06-04 13:17:00 -04:00
typings [RAC] Decouple registry from alerts-as-data client (#98935) 2021-05-13 17:12:47 +02:00
utilities
vars [CI] For PRs, build TS refs before public api docs check (#100791) 2021-06-01 21:27:42 -04:00
x-pack [Security Solutions][Detection Engine] Fixes timestamp bugs within source indexes when the formats are not ISO8601 format (#101349) 2021-06-04 16:19:59 -06:00
.backportrc.json
.bazelignore
.bazeliskversion
.bazelrc
.bazelrc.common
.bazelversion
.browserslistrc
.editorconfig
.eslintignore
.eslintrc.js Ban use of lodash.template (#100277) 2021-05-19 10:06:52 -04:00
.fossa.yml
.gitattributes
.gitignore Automated package testing (#88900) 2021-05-27 13:37:43 -05:00
.i18nrc.json [Pie] New implementation of the vislib pie chart with es-charts (#83929) 2021-06-03 18:17:14 +03:00
.node-version Bump Node.js from version 14.16.1 to 14.17.0 (#100314) 2021-05-19 07:36:43 -07:00
.npmrc
.nvmrc Bump Node.js from version 14.16.1 to 14.17.0 (#100314) 2021-05-19 07:36:43 -07:00
.prettierignore
.prettierrc
.stylelintignore
.stylelintrc
.telemetryrc.json
.yarnrc
api-documenter.json
BUILD.bazel
CODE_OF_CONDUCT.md
CONTRIBUTING.md
FAQ.md
github_checks_reporter.json
Gruntfile.js
Jenkinsfile
jest.config.integration.js
jest.config.js
kibana.d.ts
LICENSE.txt
NOTICE.txt
package.json chore(NA): upgrade bazel rules nodejs to v3.5.1 (#101412) 2021-06-04 19:56:52 +01:00
preinstall_check.js
README.md
renovate.json5 include 7.13 as a possible base branch of renovate prs 2021-05-26 11:25:25 -07:00
RISK_MATRIX.mdx Add "Risk Matrix" section to the PR template (#100649) 2021-06-02 14:43:47 +02:00
SECURITY.md
STYLEGUIDE.mdx Syntax in styleguide.mdx is breaking docs build (#99840) 2021-05-11 18:06:42 -04:00
tsconfig.base.json fix(NA): windows ts_project outside sandbox compilation (#100947) 2021-06-03 17:53:39 +01:00
tsconfig.browser.json
tsconfig.json [Pie] New implementation of the vislib pie chart with es-charts (#83929) 2021-06-03 18:17:14 +03:00
tsconfig.refs.json [ts] migrate root test dir to project refs (#99148) 2021-06-04 13:17:00 -04:00
tsconfig.types.json
TYPESCRIPT.md
WORKSPACE.bazel chore(NA): upgrade bazel rules nodejs to v3.5.1 (#101412) 2021-06-04 19:56:52 +01:00
yarn.lock chore(NA): upgrade bazel rules nodejs to v3.5.1 (#101412) 2021-06-04 19:56:52 +01:00

Kibana

Kibana is your window into the Elastic Stack. Specifically, it's a browser-based analytics and search dashboard for Elasticsearch.

Getting Started

If you just want to try Kibana out, check out the Elastic Stack Getting Started Page to give it a whirl.

If you're interested in diving a bit deeper and getting a taste of Kibana's capabilities, head over to the Kibana Getting Started Page.

Using a Kibana Release

If you want to use a Kibana release in production, give it a test run, or just play around:

Building and Running Kibana, and/or Contributing Code

You might want to build Kibana locally to contribute some code, test out the latest features, or try out an open PR:

Documentation

Visit Elastic.co for the full Kibana documentation.

For information about building the documentation, see the README in elastic/docs.

Version Compatibility with Elasticsearch

Ideally, you should be running Elasticsearch and Kibana with matching version numbers. If your Elasticsearch has an older version number or a newer major number than Kibana, then Kibana will fail to run. If Elasticsearch has a newer minor or patch number than Kibana, then the Kibana Server will log a warning.

Note: The version numbers below are only examples, meant to illustrate the relationships between different types of version numbers.

Situation Example Kibana version Example ES version Outcome
Versions are the same. 5.1.2 5.1.2 💚 OK
ES patch number is newer. 5.1.2 5.1.5 ⚠️ Logged warning
ES minor number is newer. 5.1.2 5.5.0 ⚠️ Logged warning
ES major number is newer. 5.1.2 6.0.0 🚫 Fatal error
ES patch number is older. 5.1.2 5.1.0 ⚠️ Logged warning
ES minor number is older. 5.1.2 5.0.0 🚫 Fatal error
ES major number is older. 5.1.2 4.0.0 🚫 Fatal error

Questions? Problems? Suggestions?

  • If you've found a bug or want to request a feature, please create a GitHub Issue. Please check to make sure someone else hasn't already created an issue for the same topic.
  • Need help using Kibana? Ask away on our Kibana Discuss Forum and a fellow community member or Elastic engineer will be glad to help you out.