-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Open
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Defend Workflows“EDR Workflows” sub-team of Security Solution“EDR Workflows” sub-team of Security SolutionbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v9.2.0
Description
Describe the bug:
- When the policy applied to a Windows endpoint fails due to a global artifact download issue, the Policy Failure Insights feature incorrectly reports that the “Elastic Defiant configuration appears to be missing endpoint event data.” This message is misleading because the real cause of the failure is the artifact download problem, not missing endpoint data.
Login Credentials:
Testing Details:
Build Details:
VERSION: 9.2.0 BC3
BUILD: 91544
COMMIT: 0c40a02e995201d9395473309adda6cd020d56ca
Preconditions:
- Kibana version 9.2.0
- Endpoint has an assigned policy.
Steps to Reproduce:
- Navigate to the endpoints tab
- Open the policy applied to that Windows endpoint.
- Click on Policy details.
- Disable “Enable automatic updates.”
- Set the policy version to one year back date.
- Save the policy.
- Wait for 2–3 minutes until a warning appears in the policy status.
- Click on the endpoint name.
- Click Scan to run the policy scan and observe the failure reason.
Actual Result:
- Policy Failure Insights displays incorrect failure reason for policy failure due to global artifact download issue
Expected Result:
- Policy Failure Insights should correctly identify and display the actual reason:
- “It is due to global artifact download issue.”
Screen Capture:
Endpoints.-.Kibana.Mozilla.Firefox.2025-10-15.08-58-19.mp4
Logs:
N/A
Metadata
Metadata
Assignees
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Defend Workflows“EDR Workflows” sub-team of Security Solution“EDR Workflows” sub-team of Security SolutionbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experienceimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v9.2.0