-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Closed
Closed
Copy link
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:CasesSecurity Solution Cases teamSecurity Solution Cases teambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.Addressing this issue will have a medium level of impact on the quality/strength of our product.
Description
Describe the bug:
When attaching multiple events to a new case, enabling 'Auto extract observables' does not add observables properly
Kibana/Elasticsearch Stack version:
9.2
Functional Area (e.g. Endpoint management, timelines, resolver, etc.):
Cases
Steps to reproduce:
- Generate some events
- Go to Explore->Host page, select multiple events and add to a new case
- Populate the form and enable auto extract observables
- Go the the created case, notice the observables were not added
Current behavior:
Observables are not extracted in bulk adding events
Expected behavior:
Observables should be extracted in bulk adding events
Screenshots (if relevant):
event-observable-test.mp4
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:CasesSecurity Solution Cases teamSecurity Solution Cases teambugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.Addressing this issue will have a medium level of impact on the quality/strength of our product.