[AI4DSOC] Remove Assistant icon from row action in alert summary table#219141
Merged
PhilippeOberti merged 2 commits intoelastic:mainfrom Apr 24, 2025
Merged
Conversation
e4bd55b to
19289a5
Compare
Contributor
|
Pinging @elastic/security-threat-hunting-investigations (Team:Threat Hunting:Investigations) |
19289a5 to
bd53804
Compare
stephmilovic
approved these changes
Apr 24, 2025
Contributor
stephmilovic
left a comment
There was a problem hiding this comment.
Long term fix filed as issue here: #219142
christineweng
approved these changes
Apr 24, 2025
0b382f7 to
b34a563
Compare
Contributor
💛 Build succeeded, but was flaky
Failed CI Steps
Metrics [docs]Module Count
Async chunks
Page load bundle
History
|
akowalska622
pushed a commit
to akowalska622/kibana
that referenced
this pull request
May 29, 2025
elastic#219141) ## Summary During testing we discovered an issue related to the Assistant icon displayed in the AI4DSOC alert summary page table. The issue is related to the fact that the alert registers its context with the assistant. When the assistant flyout is opened from the `Ask AI assistant` button in the alert flyout, we have one flyout which means one alert in the assistant. But with the Assistant icon shown on each row of the table, we need to register context for each alert. That means that x alert buttons equals to x alerts in the assistant. This is how it translates in the UI:  Redesigning how the assistant context works is very involved and too risky to do at such a late time. This PR removes the Assistant button from the row actions, which solves the issue: https://github.com/user-attachments/assets/0fd94cc1-4fbd-4e70-9790-22e4913477ff Also, @stephmilovic noticed that when the assistant is opened from a different launch point than the suggested prompt, and the suggested prompt is still in the DOM, its prompt context shows up empty: <img width="600" alt="Screenshot 2025-04-24 at 11 41 23 AM" src="https://github.com/user-attachments/assets/0ceb3ffc-72e5-425c-b550-9b8d5896f359" /> She resolved this by adding a check in the ContextPills component for `description.length > 0`. This would be resolved by the on click issue, so might be worth coming back to. This change is visible in the second commit and stolen from [this PR](elastic#219144). ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios relates to elastic/security-team#11973
PhilippeOberti
added a commit
to PhilippeOberti/kibana
that referenced
this pull request
May 30, 2025
elastic#219141) ## Summary During testing we discovered an issue related to the Assistant icon displayed in the AI4DSOC alert summary page table. The issue is related to the fact that the alert registers its context with the assistant. When the assistant flyout is opened from the `Ask AI assistant` button in the alert flyout, we have one flyout which means one alert in the assistant. But with the Assistant icon shown on each row of the table, we need to register context for each alert. That means that x alert buttons equals to x alerts in the assistant. This is how it translates in the UI:  Redesigning how the assistant context works is very involved and too risky to do at such a late time. This PR removes the Assistant button from the row actions, which solves the issue: https://github.com/user-attachments/assets/0fd94cc1-4fbd-4e70-9790-22e4913477ff Also, @stephmilovic noticed that when the assistant is opened from a different launch point than the suggested prompt, and the suggested prompt is still in the DOM, its prompt context shows up empty: <img width="600" alt="Screenshot 2025-04-24 at 11 41 23 AM" src="https://github.com/user-attachments/assets/0ceb3ffc-72e5-425c-b550-9b8d5896f359" /> She resolved this by adding a check in the ContextPills component for `description.length > 0`. This would be resolved by the on click issue, so might be worth coming back to. This change is visible in the second commit and stolen from [this PR](elastic#219144). ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios relates to elastic/security-team#11973 (cherry picked from commit cc98975)
PhilippeOberti
added a commit
to PhilippeOberti/kibana
that referenced
this pull request
May 30, 2025
elastic#219141) ## Summary During testing we discovered an issue related to the Assistant icon displayed in the AI4DSOC alert summary page table. The issue is related to the fact that the alert registers its context with the assistant. When the assistant flyout is opened from the `Ask AI assistant` button in the alert flyout, we have one flyout which means one alert in the assistant. But with the Assistant icon shown on each row of the table, we need to register context for each alert. That means that x alert buttons equals to x alerts in the assistant. This is how it translates in the UI:  Redesigning how the assistant context works is very involved and too risky to do at such a late time. This PR removes the Assistant button from the row actions, which solves the issue: https://github.com/user-attachments/assets/0fd94cc1-4fbd-4e70-9790-22e4913477ff Also, @stephmilovic noticed that when the assistant is opened from a different launch point than the suggested prompt, and the suggested prompt is still in the DOM, its prompt context shows up empty: <img width="600" alt="Screenshot 2025-04-24 at 11 41 23 AM" src="https://github.com/user-attachments/assets/0ceb3ffc-72e5-425c-b550-9b8d5896f359" /> She resolved this by adding a check in the ContextPills component for `description.length > 0`. This would be resolved by the on click issue, so might be worth coming back to. This change is visible in the second commit and stolen from [this PR](elastic#219144). ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios relates to elastic/security-team#11973 (cherry picked from commit cc98975)
PhilippeOberti
added a commit
to PhilippeOberti/kibana
that referenced
this pull request
Jun 4, 2025
elastic#219141) ## Summary During testing we discovered an issue related to the Assistant icon displayed in the AI4DSOC alert summary page table. The issue is related to the fact that the alert registers its context with the assistant. When the assistant flyout is opened from the `Ask AI assistant` button in the alert flyout, we have one flyout which means one alert in the assistant. But with the Assistant icon shown on each row of the table, we need to register context for each alert. That means that x alert buttons equals to x alerts in the assistant. This is how it translates in the UI:  Redesigning how the assistant context works is very involved and too risky to do at such a late time. This PR removes the Assistant button from the row actions, which solves the issue: https://github.com/user-attachments/assets/0fd94cc1-4fbd-4e70-9790-22e4913477ff Also, @stephmilovic noticed that when the assistant is opened from a different launch point than the suggested prompt, and the suggested prompt is still in the DOM, its prompt context shows up empty: <img width="600" alt="Screenshot 2025-04-24 at 11 41 23 AM" src="https://github.com/user-attachments/assets/0ceb3ffc-72e5-425c-b550-9b8d5896f359" /> She resolved this by adding a check in the ContextPills component for `description.length > 0`. This would be resolved by the on click issue, so might be worth coming back to. This change is visible in the second commit and stolen from [this PR](elastic#219144). ### Checklist - [x] [Unit or functional tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html) were updated or added to match the most common scenarios relates to elastic/security-team#11973 (cherry picked from commit cc98975)
PhilippeOberti
added a commit
that referenced
this pull request
Jun 4, 2025
…) (#222074) # Backport This will backport the following commits from `main` to `8.19`: - [[AI4DSOC] Alert summary page routing and initialization (#214889)](#214889) - [[AI4DSOC] Alert summary landing page (#215246)](#215246) - [[AI4DSOC] Alert summary dataview (#215265)](#215265) - [[AI4DSOC] Alert summary KQL bar [#215586]](#215586) - [[AI4DSOC] Alert summary KPI charts [#215585]](#215585) - [[AI4DSOR] Alert summary integrations section [#215266]](#215266) - [[AI4DSOC] Fix issue with filtering by integrations [#216574]](#216574) - [[AI4DSOC] Alert summary table setup [#216744]](#216744) - [Alerty summary table flyout setup [#217421]](#217421) - [[AI4DSOC] Alert summary alert actions in table and flyout [#217696]](#217696) - [[AI4DSOC] Alert summary table custom cell renderers [#217124]](#217124) - [[AI4DSOC] Alert summary table and flyout ai assistant [#217744]](#217744) - [[AI4DSOC] Alert summary page performance improvements [#218632]](#218632) - [[AI4DSOC] Change the Attack Discovery page to use the AI for SOC alerts table [#218736]](#218736) - [[AI4DSOC] Change the Cases page to use the AI for SOC alerts table [#218742]](#218742) - [[AI4DSOC] Fix spacing issue on alert summary landing page integration card [#218868]](#218868) - [[AI4DSOC][ResponseOps] Fix alerts table not handling undefined maintenanceWindow capability [#218999]](#218999) - [[AI4DSOC] Fix link to the new integrations page [#219030]](#219030) - [[AI4DSOC] Disable CellActions and PreviewLinks on the Attack discovery page [#219033]](#219033) - [[AI4DSOC] Add cell renderer for datetime fields to the alert summary table [#219126]](#219126) - [[AI4DSOC] Remove Assistant icon from row action in alert summary table [#219141]](#219141) - [[AI4DSOC] Add checkboxes to the alert summary table [#219169]](#219169) - [[Security Solution][AI4DSOC] Fix table not applying alert tags for Attack discovery and Cases pages in AI4DSOC [#219410]](#219410) - [[AI4DSOC] Fix logic that renders the group title when grouping by integrations [#219430]](#219430) - [[AI4DSOC] Alert summary table truncates long values and display the field/value pair in tooltip [#219438]](#219438) - [[Security Solution] Fix alerts table potentially not applying alert assignees [#219460]](#219460) --------- Co-authored-by: kibanamachine <42973632+kibanamachine@users.noreply.github.com> Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
During testing we discovered an issue related to the Assistant icon displayed in the AI4DSOC alert summary page table.
The issue is related to the fact that the alert registers its context with the assistant. When the assistant flyout is opened from the
Ask AI assistantbutton in the alert flyout, we have one flyout which means one alert in the assistant. But with the Assistant icon shown on each row of the table, we need to register context for each alert. That means that x alert buttons equals to x alerts in the assistant.This is how it translates in the UI:
Redesigning how the assistant context works is very involved and too risky to do at such a late time.
This PR removes the Assistant button from the row actions, which solves the issue:
Screen.Recording.2025-04-24.at.12.49.17.PM.mov
Also, @stephmilovic noticed that when the assistant is opened from a different launch point than the suggested prompt, and the suggested prompt is still in the DOM, its prompt context shows up empty:

She resolved this by adding a check in the ContextPills component for
description.length > 0. This would be resolved by the on click issue, so might be worth coming back to.This change is visible in the second commit and stolen from this PR.
Checklist
relates to https://github.com/elastic/security-team/issues/11973