Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Selecting an Alert take you to an Incorrect Process Analysis page and Document Segment ID

Selecting an Alert take you to an Incorrect Process Analysis page and Document Segment ID

Version

Cb Response Pre 5.2

Issue

From the Detect -> Triage Alerts page, then selecting an Alert, the resulting Process Analysis page does not show any events under the "Alliance Feed Hits" view.

Cause

The Detect -> Triage Alerts page does not take the User to the correct Process Document Segment ID.  For example, with long-running Processes that consist of multiple segments, such as the Process Analysis page URL that has a Segment ID of 25:

https://127.0.0.1/#analyze/00000019-0000-0c50-01d0-ef2c21d1a21d/25

However, the offending event and IOC that triggered the Alert may be on a different Process Document Segment, such as Segment ID of 26:

https://127.0.0.1/#analyze/00000019-0000-0c50-01d0-ef2c21d1a21d/26

Solution

Upgrade to 5.2. Manual workaround is to search for the offending event and IOC from a Process Search.

Labels (1)
Article Information
Author:
Creation Date:
‎09-21-2015
Views:
316
Contributors