豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

[Bug] DAC - Timeline rules that validate fine in Kibana fails validation in DAC #5814

@0xBAADF0OD

Description

@0xBAADF0OD

Describe the Bug

Hi

I have a few timeline rules that are running fine, but when I attempt to export via DAC, they throw errors. It looks like the DAC validation only looks for the default timeline template uuids.

TEST_TIMELINE_RULE - {'rule': [ValidationError({'type': ['Must be equal to threshold.'], 'timeline_id': ['Must be one of: db366523-f1c6-4c1f-8731-6ce5ed9e5717, 91832785-286d-4ebe-b884-1a208d111a70, 76e52245-7519-4251-91ab-262fb1a1728c, 495ad7a7-316e-4544-8a0f-9c098daee76e, 4d4c0b59-ea83-483f-b8c1-8c360ee53c5c, e70679c2-6cde-4510-9764-4823df18f7db, 300afc76-072d-4261-864d-4149714bf3f1, 3e47ef71-ebfc-4520-975c-cb27fc090799, 3e827bab-838a-469f-bd1e-5e19a2bff2fd, 4434b91a-94ca-4a89-83cb-a37cdc0532b7.'], 'timeline_title': ['Must be one of: Generic Endpoint Timeline, Generic Network Timeline, Generic Process Timeline, Generic Threat Match Timeline, Comprehensive File Timeline, Comprehensive Process Timeline, Comprehensive Network Timeline, Comprehensive Registry Timeline, Alerts Involving a Single User Timeline, Alerts Involving a Single Host Timeline.'], 'threshold': ['Missing data for required field.']}),

The docs mention limited API coverage, but is there any way to bypass these validation checks so we can at least export the rules into our repo?

To Reproduce

No response

Expected Behavior

No response

Screenshots

No response

Desktop - OS

None

Desktop - Version

No response

Additional Context

No response

Metadata

Metadata

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions