Describe the bug
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
Kibana/Elasticsearch Stack version
VERSION: 9.5.0
BUILD: 103621
COMMIT: bd1ffae8026f28c0e0ad949a1e17624cbc98780f
Preconditions
- Kibana 9.5.0 snapshot environment should exist
- User has access to the Automatic Migration feature
Steps to reproduce
- Navigate to Get Started → Manage Automatic Migrations
- Start migration for Microsoft Sentinel for different event kinds:
- Event kind: Schedule for Microsoft Sentinel
- Event kind: Fusion for Microsoft Sentinel
- Event kind: Security for Microsoft Sentinel
- Event kind: NRT for Microsoft Sentinel
- Observe that the user is only able to upload a rule for Event kind: Schedule for Microsoft Sentinel migration
Actual Result
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
Expected Result
User should be able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
JSON rules used
- Event kind: NRT for Microsoft Sentinel
sentinal_nrt.json
- Event kind: Schedule for Microsoft Sentinel
sentinal_scheduled.json
- Event kind: Fusion for Microsoft Sentinel
sentinal_fusion.json
- Event kind: Security for Microsoft Sentinel
sentinal_Security.json
Describe the bug
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
Kibana/Elasticsearch Stack version
Preconditions
Steps to reproduce
- Event kind: Schedule for Microsoft Sentinel
- Event kind: Fusion for Microsoft Sentinel
- Event kind: Security for Microsoft Sentinel
- Event kind: NRT for Microsoft Sentinel
Actual Result
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
Expected Result
User should be able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel
JSON rules used
sentinal_nrt.json
sentinal_scheduled.json
sentinal_fusion.json
sentinal_Security.json