Skip to content

[Security Solution] [Bug] User Risk Score under Risk Scores table does not reset to zero when there are no alerts in lookback time period with Retain previously calculated risk scores disabled. #238431

@arvindersingh-qasource

Description

@arvindersingh-qasource

Describe the bug
User Risk Score under Risk Scores table does not reset to zero when there are no alerts in lookback time period with Retain previously calculated risk scores disabled.

Kibana/Elasticsearch Stack version

VERSION: 9.2.0
BUILD: 91544
COMMIT: 0c40a02e995201d9395473309adda6cd020d56ca

Pre Conditions

  1. Kibana v9.2.0 must be available.
  2. Risk Score and Entity Store must be enabled.
  3. Retain previously calculated risk scores should be disabled
  4. No Alerts should be present in look back time period for Risk Score.

Steps to reproduce

  1. Navigate to Security -> Entity Analytics -> Overview.
  2. Under Entity Analytics Dashboard, Observe that User Risk Score under Risk Scores table does not reset to zero when there are no alerts in lookback time period with Retain previously calculated risk scores disabled.
  3. Click on any Host/User Entity to open Details Flyout.
  4. Observe that Risk Score will be shown as 0 however the same is not shown under User Risk Score column.

Expected Results
User/Host Risk Score under Risk Scores table should be reset to zero when there are no alerts in lookback time period with Retain previously calculated risk scores disabled.

Observation

Screen.Recording.2025-10-10.at.5.45.51.PM.mov

Metadata

Metadata

Assignees

Labels

QA:ValidatedIssue has been validated by QATeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Entity AnalyticsSecurity Entity Analytics TeambugFixes for quality problems that affect the customer experiencefixedimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.triage_neededv9.2.0

Type

No fields configured for Bug.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions