Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Defend Workflows[Bug] Unable to download files retrieved via the "Get-File" response action from the SentinelOne response console. #203730

Closed
sukhwindersingh-qasource opened this issue Dec 11, 2024 · 9 comments
Assignees
Labels
bug Fixes for quality problems that affect the customer experience impact:critical This issue should be addressed immediately due to a critical level of impact on the product. OLM Sprint QA:Validated Issue has been validated by QA Team:Defend Workflows “EDR Workflows” sub-team of Security Solution Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v8.17.0

Comments

@sukhwindersingh-qasource
Copy link

sukhwindersingh-qasource commented Dec 11, 2024

Describe the bug:

  • Unable to download files retrieved via the "Get-File" response action from the SentinelOne response console.

Build Details:

VERSION: 8.17.0 BC6
BUILD: 80521
COMMIT: e8a820624a03a412433584d3e3df951838e4c63c

Login Credentials

Preconditions

  • Kibana should be running.
  • Sentinel Alerts should be present

Steps to Reproduce

  • Navigate to the response console through the sentinel alerts flyout
  • Now run the get-file response action on the SentinelOne response console
  • Wait for the results to show up
  • Now Click on the Click here to download link
  • Observe that user is Unable to download files retrieved via the "Get-File" response action from the SentinelOne response console.

Whats working :

  • It is Working fine for the Defend get-file download option ✔
  • File download is also working for the processes response action of the SentinelOne ✔

Image

Actual result

  • Unable to download files retrieved via the "Get-File" response action from the SentinelOne response console.

Expected Result

  • User should be able to download files retrieved via the "Get-File" response action from the SentinelOne response console.

Occurring on the Old stack 8.16.0

Screen-cast

Alerts.-.Kibana.Mozilla.Firefox.2024-12-11.14-43-33.mp4

Error

{"statusCode":500,"error":"Internal Server Error","message":"Attempt to send [downloadAgentFile] to SentinelOne failed: Response validation failed (Error: expected a plain object value, but found [Object] instead.)"}

@sukhwindersingh-qasource sukhwindersingh-qasource added bug Fixes for quality problems that affect the customer experience impact:critical This issue should be addressed immediately due to a critical level of impact on the product. Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:Defend Workflows “EDR Workflows” sub-team of Security Solution v8.17.0 labels Dec 11, 2024
@elasticmachine
Copy link
Contributor

Pinging @elastic/security-defend-workflows (Team:Defend Workflows)

@elasticmachine
Copy link
Contributor

Pinging @elastic/security-solution (Team: SecuritySolution)

@sukhwindersingh-qasource
Copy link
Author

Please review this @amolnater-qasource

@amolnater-qasource
Copy link

Reviewed & assigned to @dasansol92

@paul-tavares
Copy link
Contributor

PR with fix is up: #203820

target is main and 8.17.1

@paul-tavares
Copy link
Contributor

Fix is merged

@paul-tavares paul-tavares added the QA:Ready for Testing Code is merged and ready for QA to validate label Dec 11, 2024
@sukhwindersingh-qasource
Copy link
Author

Hi @paul-tavares ,

We have validated this ticket on the latest 8.16.2 BC1 build and found the issue is NOT FIXED. ❌

Please find below the testing details

Build Details:
VERSION: 8.16.2 BC1
BUILD: 79858
COMMIT: c5bc2be

Screen Recording :

Alerts.-.Kibana.Mozilla.Firefox.2024-12-17.12-06-25.mp4

Please Let us know if anything else is required from our end.

Thanks!!

@sukhwindersingh-qasource
Copy link
Author

Hi @paul-tavares ,

We have validated this ticket on the latest 8.16.3 BC1 build and found the issue is FIXED. ✔

Please find below the testing details

Build Details:

VERSION: 8.16.3 BC1
BUILD: 79924
COMMIT: 2e63133

Screen Recording :

Image

Alerts.-.Kibana.Mozilla.Firefox.2025-01-10.12-09-51.mp4

We will be validating this on 8.17.1, after which the ticket will be closed and marked as QA Validated.

Thanks!!

@sukhwindersingh-qasource
Copy link
Author

Hi @paul-tavares ,

We have validated this ticket on the latest 8.17.1 BC3 build and found the issue is FIXED. ✔

Please find below the testing details

Build Details:

VERSION: 8.17.1 BC3
BUILD: 80642
COMMIT: 9b07116

Screen Recording :

Image

Alerts.-.Kibana.Mozilla.Firefox.2025-01-13.12-42-20.mp4

Hence we are closing this ticket and marking it as QA Validated.

Thanks!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Fixes for quality problems that affect the customer experience impact:critical This issue should be addressed immediately due to a critical level of impact on the product. OLM Sprint QA:Validated Issue has been validated by QA Team:Defend Workflows “EDR Workflows” sub-team of Security Solution Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. v8.17.0
Projects
None yet
Development

No branches or pull requests

5 participants