Repository navigation
[SIEM] Removing a Rule's Action breaks Rule execution #64870
Description
Activity
- addedbugFixes for quality problems that affect the customer experienceFixes for quality problems that affect the customer experience
on Apr 30, 2020 Pinging @elastic/siem (Team:SIEM)
- changed the title
[-]Removing a Rule's Action breaks Rule execution[/-][+][SIEM] Removing a Rule's Action breaks Rule execution[/+]on Apr 30, 2020 This is a consequence of #53868, which is currently blocked and under discussion.
Dev update: we have a temporary solution in the following diff:
diff --git a/x-pack/plugins/siem/server/lib/detection_engine/routes/rules/update_rules_route.ts b/x-pack/plugins/siem/server/lib/detection_engine/routes/rules/update_rules_route.ts index f15154a096..29dd52cc57 100644 --- a/x-pack/plugins/siem/server/lib/detection_engine/routes/rules/update_rules_route.ts +++ b/x-pack/plugins/siem/server/lib/detection_engine/routes/rules/update_rules_route.ts @@ -138,6 +138,7 @@ export const updateRulesRoute = (router: IRouter, ml: SetupPlugins['ml']) => { ruleActions, ruleStatuses.saved_objects[0] ); + await alertsClient.updateApiKey({ id: rule.id }); if (errors != null) { return siemResponse.error({ statusCode: 500, body: errors }); } else {
It's not ideal as the call to
updateApiKeyitself logs an error when removing the rule's action, but it does allow the rule to continue executing sans actions. If acceptable we'll have to add a similar fix to all patch/update rule routes that can delete actions.However, we're still digging into the underlying cause here, so we'll be roping in Alerting for some assistance before this ships.
Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate datausually means data has change since it was last encrypted. This can happen when doing a partial update or when the Elasticsearch document merges json on update. You can tell the latter by comparing alert params on update vs what is stored in the document in ES after update.I don't think #53868 will solve the issue because that is to handle invalidating API keys where this issue is trying to decrypt the API key from a saved object.
If it's confirmed that the alert params get merged with old values on update, this file
x-pack/plugins/siem/server/lib/detection_engine/signals/signal_params_schema.tswould need to set defaultnullvalues to all the optional properties.7.7: #67426
Fixed in 7.7.1 :)
- added 6 commits that reference this issue
on Jun 3, 2020 - addedTeam: SecuritySolutionSecurity Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
on Oct 27, 2020 - added a commit that references this issue
on May 6, 2026
[reported originally by @rylnd)
Kibana version: 7.7.0
After an action is removed from a rule, the rule fails to execute. To resolve this, disable and then re-enable the rule.
This is present on master and 7.7.
Steps to Reproduce
on each rule executionperform no actionsLast responsewill remain as it was prior to step 3)NB That querying the corresponding task, we find that it still exists in the "idle" state: