Skip to content

[Security Solution]Raw Event default view showing for Show Top under Alert Reason #164801

@ghost

Description

Describe the bug:
Raw Event default view showing for Show Top under Alert Reason

Kibana/Elasticsearch Stack version
Version: 8.10.0 BC2
Commit: fa3473f
Build: 66107

Browser and Browser OS Version:
Firefox for windows OS
Version: 116.0.3(64-bit)

Elastic Endpoint Version:
v8.10.2

Original install method:
Build summary: https://staging.elastic.co/8.10.0-049269aa/summary-8.10.0.html

Functional Area:
New Alert Fly out

Initial Setup:

  • None

Steps to reproduce

  • Navigate to Alert page and click on view details on any one alert
  • under fly out open alert reason
  • Perform top action on any field value
  • Observed that raw event view is selected before 8.10 default view is Detection Alert

Additional Observation

  • In 8.9.1 by default Detection Alert view is shown in show top modal
Alerts.-.Kibana.-.Google.Chrome.2023-08-25.12-11-51.mp4
  • Issue is not occuring on opening show top modal opened from Alert Table

image

Current behavior

  • Raw Event default view showing for Show Top under Alert Reason

Expected behavior:

  • Detection Alert default view showing for Show Top under Alert Reason

Screen-cast:

Alerts.-.Kibana.Mozilla.Firefox.2023-08-25.12-17-53.mp4

image

Errors in browser console:
None

Any additional context (logs, chat logs, magical formulas, etc.):

None

Metadata

Metadata

Labels

QA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Threat HuntingSecurity Solution Threat Hunting TeamTeam:Threat Hunting:InvestigationsSecurity Solution Threat Hunting Investigations TeambugFixes for quality problems that affect the customer experiencefixedimpact:mediumAddressing this issue will have a medium level of impact on the quality/strength of our product.v8.19.0

Type

No type
No fields configured for issues without a type.

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions