Skip to content

[Security Solution] [Bug] User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel #272077

@muskangulati-qasource

Description

@muskangulati-qasource

Describe the bug
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel

Kibana/Elasticsearch Stack version

VERSION: 9.5.0
BUILD: 103621
COMMIT: bd1ffae8026f28c0e0ad949a1e17624cbc98780f

Preconditions

  • Kibana 9.5.0 snapshot environment should exist
  • User has access to the Automatic Migration feature

Steps to reproduce

  • Navigate to Get Started → Manage Automatic Migrations
  • Start migration for Microsoft Sentinel for different event kinds:
    - Event kind: Schedule for Microsoft Sentinel
    - Event kind: Fusion for Microsoft Sentinel
    - Event kind: Security for Microsoft Sentinel
    - Event kind: NRT for Microsoft Sentinel
  • Observe that the user is only able to upload a rule for Event kind: Schedule for Microsoft Sentinel migration

Actual Result
User is not able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel

Expected Result
User should be able to upload rules for Fusion, Security, and NRT event types in Microsoft Sentinel

JSON rules used

  • Event kind: NRT for Microsoft Sentinel

sentinal_nrt.json

  • Event kind: Schedule for Microsoft Sentinel

sentinal_scheduled.json

  • Event kind: Fusion for Microsoft Sentinel

sentinal_fusion.json

  • Event kind: Security for Microsoft Sentinel

sentinal_Security.json

Metadata

Metadata

Labels

Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Automatic MigrationsLabel for Security Automatic Migrations project related task and bugsbugFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.triage_neededv9.5.0

Type

No fields configured for Bug.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions