opensearch-project / opensearch-project/security-analytics

[BUG] Unable to create a Correlation Rule

Open
#1,799 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug untriaged
Dominant language
Java
Stars
111
Forks
111
Avg merge
1d 17h
Merged PRs (30d)
13

Description

What is the bug?
When creating a correlation rule in the Security Analytics plugin, after correctly filling out all of the fields to create the correlation rule, clicking the button "Create correlation rule" does nothing. I am unable to create a Correlation Rule. It appears that the button on the UI is broken. I am doing this after I have successfully created Detection Rules and Detectors.

How can one reproduce the bug?
Steps to reproduce the behavior:

  1. Go to the Security Analytics plugin and create a Correlation Rule.
  2. Fill out the fields in order to correctly create a Correlation Rule.
  3. Scroll down to the button Create correlation rule and click it.
  4. See error in the Inspect Console.

What is the expected behavior?
A correlation rule is created from the fields I have input in the UI.

What is your host/environment?

  • OS: Linux malcolm 6.12.74+deb13+1-amd64 Debian 6.12.74
  • Version 3.7.0
  • Plugins: Security Analytics Plugin

Do you have any screenshots?
The screenshot provided is the error shown in the Inspect Console after filling out the Create Correlation Rule fields and then clicking the button "Create correlation rule."

Image

Do you have any additional context?
I am currently using the Opensearch Security Analytics plugin through Malcolm v26.07.1 with Opensearch version 3.7.0. I have found that I can successfully create a correlation rule in the Security Analytics plugin with Opensearch version 3.5.0 (Malcolm v26.04.1).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue in the Security Analytics plugin with OpenSearch 3.7.0 by completing the Correlation Rule form and clicking "Create correlation rule." Start with the Inspect Console error shown after the click, then compare the behavior with OpenSearch 3.5.0, where creation succeeds; done means a valid correlation rule is created from the submitted fields.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.