Repository navigation
[SIEM] fix timeline/kql search disparity - #42843
Conversation
|
Pinging @elastic/siem |
💚 Build Succeeded |
💔 Build Failed |
💚 Build Succeeded |
💚 Build Succeeded |
|
The following documents some of the ad hoc tests I ran against the PR branch in our development environment: All tests were run with an absolute date range: user "bob" as a Filter
Result: user "bob" as KQL (AND mode)
Result: user "bob" as KQL (OR mode)
Result: user "bob" as both a Filter and KQL (AND mode) (should return the same results)
Result: user "bob" as both a Filter and KQL (OR mode) (should return the same results)
Result: user "bob" AND host "jessie" as Filters
Result: user "bob" AND host "jessie" as KQL (AND mode)
Result: user "bob" AND host "jessie" as KQL (OR mode)
Result: user "bob" AND host "jessie" as both a Filter and KQL (AND mode) (should return the same results)
Result: user "bob" AND host "jessie" as both a Filter and KQL (OR mode) (should return the same results)
Result: user "bob" OR host "jessie" as Filters
Result: user "bob" OR host "jessie" as KQL (AND mode)
Result: user "bob" OR host "jessie" as KQL (OR mode)
Result: user "bob" OR host "jessie" as both a Filter and KQL (AND mode) (should return the same results)
Result: user "bob" OR host "jessie" as both a Filter and KQL (OR mode) (should return the same results)
Result: user "bob" OR host "jessie" split between Filter and KQL (OR mode)
Result: user "bob" OR host "jessie" split between Filter and KQL (AND mode)
Result: user "bob" AND host "jessie" or user "bob" split between Filter and KQL (AND mode)
Result: user "bob" AND host "jessie" or user "bob" split between Filter and KQL (OR mode)
Result: user.name exists as a Filter
Result: user.name exists as KQL (AND mode)
Result: user.name exists as KQL (OR mode)
Result: user "bob" AND user.name exists, split between Filter and KQL (AND mode)
Result: user "bob" OR user.name exists, split between Filter and KQL (OR mode)
Result: host "jessie" OR user "bob" AND user.name exists, split between Filter and KQL (AND mode)
Result: host "jessie" OR user "bob" OR user.name exists, split between Filter and KQL (OR mode)
Result: |
andrew-goldstein
left a comment
There was a problem hiding this comment.
🦅 👀 Thanks @stephmilovic for catching this disparity, and for the fix in this PR! In addition to the fix itself, the removal of the extra ( )s in the generated KQL query is icing on the 🍰.
I ran some ad hoc tests against the development environment and added some of the results as a comment to this PR.
LGTM 🙏 🦅
spong
left a comment
There was a problem hiding this comment.
Checked out, tested locally, and also performed a code review. Gave the Query Builder + KQL AND/OR's quite a bit of testing and all event counts + queries looked good! Did come across this separate escaping issue in testing (#42866), but unrelated.
Looooks good to meeeee! Great job with these changes @stephmilovic! 😃🎉
|
@stephmilovic Generally bug fixes should have |
Summary
This PR resolves this issue: #42549
The KQL query was getting appended to the timerange like this
source.ip: 10.142.0.9 OR (dest.ip: 10.142.0.9 AND @timestamp in range)instead of to the timeline portion like this(source.ip: 10.142.0.9 OR dest.ip: 10.142.0.9) AND @timestamp in range. By moving the)in the kuery string to the end of the KQL append, this fixes the issue.Note: no more disparity in the number of events displayed in the lower left corner!


Checklist
Use
strikethroughsto remove checklist items you don't feel are applicable to this PR.This was checked for cross-browser compatibility, including a check against IE11Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n supportDocumentation was added for features that require explanation or tutorialsThis was checked for keyboard-only and screenreader accessibilityFor maintainers
This was checked for breaking API changes and was labeled appropriatelyThis includes a feature addition or change that requires a release note and was labeled appropriately