Skip to content

Commit 017eb90

Browse files
Additional known issue for 8.16.6 RNs (#6728) (#6736)
* Additional known issue for 8.16.6 * Applies feedback * Update docs/release-notes/8.16.asciidoc Co-authored-by: Janeen Mikell Roberts <[email protected]> --------- Co-authored-by: Janeen Mikell Roberts <[email protected]> (cherry picked from commit aecdee4) Co-authored-by: natasha-moore-elastic <[email protected]>
1 parent 6e7a6f8 commit 017eb90

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

docs/release-notes/8.16.asciidoc

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,19 @@ On November 12, 2024, it was discovered that manually running a custom query rul
2929
====
3030
// end::known-issue[]
3131

32+
// tag::known-issue[]
33+
[discrete]
34+
.Installing an {elastic-defend} integration or a new agent policy upgrades installed prebuilt rules, overwriting user-added actions and exceptions
35+
[%collapsible]
36+
====
37+
*Details* +
38+
When you install an {elastic-defend} integration or a new agent policy for this integration, all the installed prebuilt detection rules are upgraded to their latest versions (if any new versions are available). The upgraded rules lose any user-added rule actions and exceptions.
39+
40+
*Workaround* +
41+
To resolve this issue, before you add an {elastic-defend} integration to a policy in {fleet}, apply any pending prebuilt rule updates. This will prevent rule actions and exceptions from being overwritten.
42+
====
43+
// end::known-issue[]
44+
3245
[discrete]
3346
[[bug-fixes-8.16.6]]
3447
==== Bug fixes

0 commit comments

Comments
 (0)