# Double whitespace in Exception's field's value

**URL:** <https://discuss.elastic.co/t/double-whitespace-in-exceptions-fields-value/277909>\
**Category:** Elastic Security\
**Created:** [July 6, 2021, 6:25am UTC](https://discuss.elastic.co/t/double-whitespace-in-exceptions-fields-value/277909 "2021-07-06T06:25:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![inf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/inf/32/85793_2.png) [@inf](https://discuss.elastic.co/u/inf)\
**Post date:** [July 6, 2021, 6:25am UTC](https://discuss.elastic.co/t/double-whitespace-in-exceptions-fields-value/277909/1 "2021-07-06T06:25:33Z")

</div>

Hi there,

I am trying to add an exception to a rule where these are the details given:

- Field: `winlog.event_data.ParentCommandLine`
- Operator: `is`
- Value: `C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -NoProfile ...` (truncated)

It is not obvious just by looking at the `Value`'s content, but there are 2 whitespaces in between `powershell.exe` and `-NoProfile`.

After copying-and-pasting it into the box that requires it (i.e. it is added as a "custom option"), I saved it. Copying-and-pasting the content in `Value` that was now reflected back to me showed that there was only 1 whitespace.

There appears to be no other way for me at the moment to use another field or piece of content for this exception, and thus I would have to look at resolving this error/bug(?)

Thank you so much for reading!

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [July 16, 2021, 5:39pm UTC](https://discuss.elastic.co/t/double-whitespace-in-exceptions-fields-value/277909/2 "2021-07-16T17:39:40Z")

</div>

I think the problem we have is that by default HTML/DOM displays multiple spaces as a single space and that we are doing it as well. We really shouldn't allow the HTML/DOM to change your value when displaying it back to you. We will want to fix the display issue.

Ref: [formatting - Why does HTML require that multiple spaces show up as a single space in the browser? - Stack Overflow](https://stackoverflow.com/questions/433493/why-does-html-require-that-multiple-spaces-show-up-as-a-single-space-in-the-brow)

The good news is that you should still be able to use exceptions even though you have multiple spaces in the value box. That part works.

I just tested it by adding data like this in dev tools:

Create a small mapping

```json
DELETE delme-frank-1
PUT delme-frank-1
{
  "mappings": {
    "dynamic": "strict",
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "winlog": {
        "properties": {
          "event_data": {
            "properties": {
              "ParentCommandLine": {
                "type": "keyword"
              }
            }
          }
        }
      }
    }
  }
}

```

Add two documents. One of which has multiple spaces in the value section

```json
PUT delme-frank-1/_doc/1
{
  "@timestamp": "2021-07-16T17:10:28.902Z",
  "winlog": {
    "event_data": {
      "ParentCommandLine": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -NoProfile"
    }
  }
}

```

```auto
PUT delme-frank-1/_doc/2
{
  "@timestamp": "2021-07-16T17:10:29.902Z",
  "winlog": {
    "event_data": {
      "ParentCommandLine": "something else"
    }
  }
}

```

Make sure we see it

```json
GET delme-frank-1/_search

```

Create a rule without activating that has long look back time to get our timestamp but _dont_ activate until we add an exception.

 ![Screen Shot 2021-07-16 at 11.36.19 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/7/4798ba39bfa3f938b16654654ba9a9fab7a5bddf.png)

Add the exception:

 ![Screen Shot 2021-07-16 at 11.36.29 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a7c85f549826fe6741762d09f98fa513076f9d9.png)

I then checked to ensure it was there with two spaces in the network panel:

 ![Screen Shot 2021-07-16 at 11.26.40 AM](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c19f530d1329f4d3a3340549159c5d61fcbadc8.png)

Checked to see that indeed HTML is hiding double spaces:

 ![Screen Shot 2021-07-16 at 11.29.02 AM](https://us1.discourse-cdn.com/elastic/original/3X/5/7/571572fcecc622975bb0013dfece73b66d0c3ac6.png)

Turned on the rule and saw that it is working and only signaling once:

 ![Screen Shot 2021-07-16 at 11.39.19 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/b/db594d45461a0b08bab5ea1dd3fca9000ae4f485.png)

I did write up a Kibana issue for the HTML display problem but again you should be ok using it, just don't copy and paste from the HTML/DOM as is, since it's truncating the spacing:

> <https://github.com/elastic/kibana/issues/106003>
>
> \*\*Describe the bug:\*\*
> When users create an exception in the exception list, it …is very common for them to use two spaces within their input. However, when we display the exception value, it only shows one space since the HTML/DOM collapses it as one space. This can be avoided with a styled \`\<pre\>\` or other HTML element which preserves the additional spaces.
> 
> This can be a problem because if users copy and paste the value from the HTML DOM \_back into\_ the value box or another area of our application they lose the additional spaces.
> 
> \*\*Steps to reproduce:\*\*
> 
> Go to dev tools and make this index and two pieces of data:
> 
> \`\`\`json
> DELETE delme-frank-1
> PUT delme-frank-1
> {
> "mappings": {
> "dynamic": "strict",
> "properties": {
> "@timestamp": {
> "type": "date"
> },
> "winlog": {
> "properties": {
> "event\_data": {
> "properties": {
> "ParentCommandLine": {
> "type": "keyword"
> }
> }
> }
> }
> }
> }
> }
> }
> \`\`\`
> 
> Add two documents. One of which has multiple spaces in the value section:
> 
> \`\`\`json
> PUT delme-frank-1/\_doc/1
> {
> "@timestamp": "2021-07-16T17:10:28.902Z",
> "winlog": {
> "event\_data": {
> "ParentCommandLine": "C:\\\\Windows\\\\System32\\\\WindowsPowerShell\\\\v1.0\\\\powershell.exe -NoProfile"
> }
> }
> }
> \`\`\`
> 
> \`\`\`json
> PUT delme-frank-1/\_doc/2
> {
> "@timestamp": "2021-07-16T17:10:29.902Z",
> "winlog": {
> "event\_data": {
> "ParentCommandLine": "something else"
> }
> }
> }
> \`\`\`
> 
> Go to view the data and on the DOM and notice that one value has only one space in it:
> 
> DOM:
> \<img width="763" alt="Screen Shot 2021-07-16 at 11 29 02 AM" src="https://user-images.githubusercontent.com/1151048/125988298-2d6249c6-dfac-41bf-bc8a-01bbd7938cd6.png"\>
> 
> Page where if you copy and paste this value somewhere else it will now only contain one space instead of two.
> \<img width="895" alt="Screen Shot 2021-07-16 at 11 36 29 AM" src="https://user-images.githubusercontent.com/1151048/125988269-cb832fb5-3cd5-4f89-b98d-afaf7a886c49.png"\>
> 
> 
> 
> \*\*Kibana version:\*\*
> 7.13.0+
> 
> \*\*Elasticsearch version:\*\*
> 7.13.0+
> 
> 
> \*\*Expected behavior:\*\*
> 
> \*\*Screenshots (if relevant):\*\*
> 
> \*\*Errors in browser console (if relevant):\*\*
> 
> \*\*Provide logs and/or server output (if relevant):\*\*
> 
> \*\*Any additional context:\*\*

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2021, 5:40pm UTC](https://discuss.elastic.co/t/double-whitespace-in-exceptions-fields-value/277909/3 "2021-08-13T17:40:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
