-
Notifications
You must be signed in to change notification settings - Fork 8.5k
Open
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Defend Workflows“EDR Workflows” sub-team of Security Solution“EDR Workflows” sub-team of Security SolutionbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencegroomingimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v9.2.0
Description
Describe the bug:
- When user attempts to add an event filter from the Host Page, the option to select the operating system (OS) is not available.
- Additionally, no matter if the user navigates to the Host Details page of a Linux or macOS host and tries to add an event filter from those hosts, the OS is still automatically selected as Windows, which is not the correct behavior.
Login Credentials:
Testing Details:
Build Details:
VERSION: 9.2.0 BC3
BUILD: 91544
COMMIT: 0c40a02e995201d9395473309adda6cd020d56ca
Preconditions:
- Kibana version 9.2.0
- User must have access to add Event Filter.
Steps to Reproduce:
- Login with the user having above privileges.
- Navigate to "Explore Page"
- Click on "Host".
- Navigate to an event where analyzer button is present and then click on three dots of that event.
- Click on "Add Endpoint event filter" button.
Actual Result:
- The option to select the OS filter is missing, and the default OS is set to Windows.
Expected Result:
- An option to select the OS should be present when adding a filter from the Host Page.
Occurring on Old stacks:
- yes it is occurring on the 9.1.1 as well ✔️
Screen Capture:
Endpoints.-.Kibana.Mozilla.Firefox.2025-10-15.09-11-19.mp4
Logs:
N/A
Metadata
Metadata
Assignees
Labels
Team: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Team:Defend Workflows“EDR Workflows” sub-team of Security Solution“EDR Workflows” sub-team of Security SolutionbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experiencegroomingimpact:highAddressing this issue will have a high level of impact on the quality/strength of our product.Addressing this issue will have a high level of impact on the quality/strength of our product.v9.2.0