Fix timeline query for threshold rules (#88217)

This commit is contained in:
Madison Caldwell 2021-01-13 15:29:14 -05:00 committed by GitHub
parent 5ed91585a8
commit 66129efc15
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -272,24 +272,9 @@ export const sendAlertToTimelineAction = async ({
notes: null,
timeline: {
...timelineDefaults,
kqlMode: 'search',
description: `_id: ${ecsData._id}`,
filters: getFiltersFromRule(ecsData.signal?.rule?.filters as string[]),
dataProviders: [
{
and: [],
id: `send-alert-to-timeline-action-default-draggable-event-details-value-formatted-field-value-${TimelineId.active}-alert-id-${ecsData._id}`,
name: ecsData._id,
enabled: true,
excluded: false,
kqlQuery: '',
queryMatch: {
field: '_id',
value: ecsData._id,
operator: ':',
},
},
...getThresholdAggregationDataProvider(ecsData, nonEcsData),
],
dataProviders: [...getThresholdAggregationDataProvider(ecsData, nonEcsData)],
id: TimelineId.active,
indexNames: [],
dateRange: {