Skip to content

[DOCS][Exceptions] - Unsupported detection engine operator discovered in past releases #2199

@yctercero

Description

@yctercero

Description

A bug was discovered that surfaces the "matches" operator in the exception item builder, however, this operator is not supported by the detection engine, only by OLM team (artifacts, event filters, etc). This was found to be present in 8.2 and 8.3.

The following doc updates will be needed:

  • 8.2 add known issue. Users who add an exception item that uses "matches" will result in a rule run error (see bug issue for error)
  • 8.3/8.3.1/8.3.2 - add known issue. Users who add an exception item that uses "matches" will result in a rule run error (see bug issue for error)
  • 8.3.3 - bug fix will be backported to 8.3 so just a release note should suffice (?)

Issue - elastic/kibana#136224
PR - elastic/kibana#136340

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions