Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Anomaly found in Network Session Traffic Analytics Rule Generating Blank Incidents #9983

Closed
NickNicolaou2129 opened this issue Feb 19, 2024 · 16 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@NickNicolaou2129
Copy link

Describe the bug
A clear and concise description of what the bug is.

To Reproduce
When running the "Anomaly found in Network Session Traffic" it does not load any query results, this is because we have so much data coming in that it cannot read it all back. Even if I set the lookback to 1 second, it still does not load any data:
image

This results in incidents being created that are empty because the query cannot load the data:
image

Expected behavior
We expect to see the incident information appear when it is generated.

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Feb 20, 2024
@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 26-02-2024. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, Could you please run below shared query once and check for the result - query.txt
If query not showing any result, then please check the data availability into the table - NetworkCustomAnalytics_protocol_CL

Thanks!

@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, We are waiting for your response from on above comment. Thanks!

@NickNicolaou2129
Copy link
Author

Hi @v-sudkharat NetworkCustomAnalytics_protocol_CL does not refer to a know table:
image

@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, Could you please check the Rule is compliant with required given data sources -
image
image

Thanks!

@NickNicolaou2129
Copy link
Author

NickNicolaou2129 commented Mar 1, 2024 via email

@v-sudkharat
Copy link
Contributor

@NickNicolaou2129, will check on it and if required will schedule a call for it. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, Can we have a call? We need few more details about the incident. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @NickNicolaou2129, Hope you're doing good. As you have raised the support case for this same issue, our team is working on your ticket. So could you please let us know can we close this issue from GitHub? as other team is checking on this. Thanks!

@NickNicolaou2129
Copy link
Author

Hi, I would like to keep this GitHub ticket. I have just sent you the documents you requested from me in yesterdays call. Let me know if you have any further news, thanks!

@v-sudkharat
Copy link
Contributor

@NickNicolaou2129, Sure. we will check it from our end and update you. And please let us know if you get update on this from our support team. Thanks!

@v-sudkharat
Copy link
Contributor

Hey @NickNicolaou2129, Our support team still working on this issue and will communicate with you for required details. Thanks!

@v-muuppugund
Copy link
Contributor

Hi @NickNicolaou2129 ,As the ICM is raised for this issue and so this is duplicate issue and Please let me any work needs to be done will reopen it and closing as per process and will discuss in detail in tomorrow call

@ikkarakashev
Copy link

Hello, I'm facing the same issue for table NetworkCustomAnalytics_protocol_CL which is not present in the LA. Were you able to fix it ?

@NickNicolaou2129
Copy link
Author

NickNicolaou2129 commented Aug 6, 2024 via email

@fkh090
Copy link

fkh090 commented Sep 27, 2024

The Same Problem here. Did anyone find the Solution?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

5 participants