You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
When creating a new alert via the API we are allowed to provide IOC's. When setting the IOC description field to NULL I do not get any errors from the API, nor are there web errors when viewing the IOC in the alert. The description is simply empty. However, when merging an alert that has a null description field into a case, I am experiencing a perpetual ellipses on the IOC tab in the case view. The web console produced the following error:
common.js:103 Uncaught TypeError: Cannot read properties of null (reading 'length')
at ellipsis_field_raw (common.js:103:14)
at ret_obj_dt_description (common.js:83:15)
at render (case.ioc.js:399:26)
at datatables.min.js:17:6970
at n.fnGetData (datatables.min.js:17:3728)
at _ (datatables.min.js:17:6174)
at P (datatables.min.js:17:10069)
at D (datatables.min.js:17:5951)
at Vt.<anonymous> (datatables.min.js:17:56611)
at Vt.iterator (datatables.min.js:17:48247)
When viewing the network traffic in the browser, I see ioc_description: null, as opposed to ioc_description: "" on IOCs manually submitted without adding a description.
To Reproduce
Steps to reproduce the behavior:
Submit an alert via the API with an IOC that has ioc_description set to null.
Merge alert into a new or existing Case.
View the IOC tab in the Case.
A perpetual ellipses will be shown. The UI will be broken/off centered. After a few moments "Updates available" will be shown in the top right.
Expected behavior
Null values are handled appropriately at some point by IRIS. Either by rejecting alerts with null values in required fields or translating null values to empty strings.
Desktop (please complete the following information):
OS: Windows 11
Browser Chrome 124.0.6367.119
Version 2.3.7 (Alert submitted via API v2.0.2); 2.4.7 (Alert submission not tested on API v v2.0.4)
Additional context
I am submitting alerts via the API without using the provided python client.
The text was updated successfully, but these errors were encountered:
Describe the bug
When creating a new alert via the API we are allowed to provide IOC's. When setting the IOC description field to NULL I do not get any errors from the API, nor are there web errors when viewing the IOC in the alert. The description is simply empty. However, when merging an alert that has a null description field into a case, I am experiencing a perpetual ellipses on the IOC tab in the case view. The web console produced the following error:
When viewing the network traffic in the browser, I see
ioc_description: null
, as opposed toioc_description: ""
on IOCs manually submitted without adding a description.To Reproduce
Steps to reproduce the behavior:
ioc_description
set tonull
.Expected behavior
Null values are handled appropriately at some point by IRIS. Either by rejecting alerts with null values in required fields or translating null values to empty strings.
Desktop (please complete the following information):
Additional context
I am submitting alerts via the API without using the provided python client.
The text was updated successfully, but these errors were encountered: