Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] [BUG] Legacy risk score is not displayed on Entity Analytics Dashboard #206809

Open
machadoum opened this issue Jan 15, 2025 · 11 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience Team:Entity Analytics Security Entity Analytics Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: entity_analytics

Comments

@machadoum
Copy link
Member

machadoum commented Jan 15, 2025

Describe the bug:
Legacy risk score is not displayed on the Entity Analytics Dashboard

Kibana/Elasticsearch Stack version:
8.18.0 (8.x branch)

Steps to reproduce:

  1. Install the legacy risk score (by document generator or using and old kibana version and upgrading)
  2. Open entity analytics dashboard
  3. The Risk score panels should show the legacy risk score values

Current behavior:
It shows empty panels

Expected behavior:
The Risk score panels should show the legacy risk score values

Screenshots (if relevant):

Image

@machadoum machadoum added bug Fixes for quality problems that affect the customer experience Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Entity Analytics Security Entity Analytics Team Theme: entity_analytics triage_needed labels Jan 15, 2025
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-entity-analytics (Team:Entity Analytics)

@machadoum machadoum changed the title [Security Solution] Legacy risk score is not displayed on Entity Analytics Dashboard [Security Solution] [BUG] Legacy risk score is not displayed on Entity Analytics Dashboard Jan 15, 2025
@hop-dev hop-dev self-assigned this Feb 5, 2025
@jaredburgettelastic
Copy link
Contributor

@machadoum can you please test this one now that the fix has been merged

@muskangulati-qasource
Copy link

Hi @machadoum,

We have tested this ticket on the 8.18.0 BC5 build. Please find below the testing details:

Build details:

VERSION: 8.18.0
BUILD: 82557
COMMIT: b1da764d7db918082e4b9b82a8df5007f555e9b0

Observations and screen shots
When entity store is disabled and risk score is enabled:

Image

Image

When entity store is enabled and risk score is disabled:

Image

Image

When both entity store and risk score are disabled:

Image

When both entity store and risk score are enabled:

Image

Please let us know if anything else is required from our end.

Thank you!

@machadoum
Copy link
Member Author

@muskangulati-qasource Have you Installed the legacy risk score for these tests?

@muskangulati-qasource
Copy link

Hi @machadoum,

We have validated this issue on 8.5.3 release build and below are our observations:

Build details:

VERSION: 8.5.3
BUILD: 57217
COMMIT: 93852c98d9e9902fe166302fae10bc8c5f3502fb

8.5.3:

  • User and host risk enabled:

Image

  • User risk enabled, host risk disabled:

Image

  • User risk disabled, host risk enabled:

Image

  • User risk disabled, host risk disabled:

Image

8.18.0:
After upgrade, we see the below UI in every space:

Image

After clicking on 'Manage', the user is navigated to the Entity Risk score tab and is asked to update :

Image

Image

And, we are successfully able to view the risk scores data generated before upgrade:

Image

Everything seems to be working fine on the Entity Analytics dashboard:

Image

Please let us know if anything else is required from our end.

Thank you!

@machadoum
Copy link
Member Author

@muskangulati-qasource It looks like you were able to reproduce the bug here:

Image

@hop-dev will dig into it.

@hop-dev
Copy link
Contributor

hop-dev commented Mar 4, 2025

@muskangulati-qasource am I able to access this test environment to run some searches? Thanks

@muskangulati-qasource
Copy link

Hi @hop-dev,

Please find the credentials here for the environment that is now upgraded to 8.18.0: https://p.elstc.co/paste/tjkckfIw#+7Drx3ENAbtMeYGNQVlcxOypzRVE0PeO77iPLLfgppx

Thanks!

@hop-dev
Copy link
Contributor

hop-dev commented Mar 5, 2025

Thanks @muskangulati-qasource this is a case of a missed backport, I have put the PR in now #213249

@MadameSheema MadameSheema removed the fixed label Mar 5, 2025
@MadameSheema
Copy link
Member

@hop-dev please add the fixed label once the backport PR is merged. I would deeply appreciate if you can add the labels of the versions where the fix is availalble.

Thanks!! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience Team:Entity Analytics Security Entity Analytics Team Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Theme: entity_analytics
Projects
None yet
Development

No branches or pull requests

6 participants