Skip to content
Notifications
Clear all

Help: Upgraded and now half our custom attributes are missing.

1 Posts
1 Users
0 Reactions
3 Views
(@cloud_ops_learner_2)
Reputable Member
Joined: 1 month ago
Posts: 163
Topic starter   [#7444]

Hey everyone, hoping someone else has run into this and can point me in the right direction! 😅

We just upgraded our ThreatConnect instance to the latest version (I won't specify the exact version here, but it's a recent major one). The upgrade itself seemed to go smoothly, but now when we browse to certain indicator types or groups, about half of the custom attributes we've defined over the years are just... gone. They're not appearing in the UI for adding values, and existing data in those fields seems inaccessible. Our playbooks that reference those attributes are failing too.

Here's what we've checked so far:
* The custom attributes are still listed in the **System > Custom Attributes** settings page. So they weren't deleted.
* This is affecting a mix of attribute types (Text, Number, URL).
* It seems tied to specific **Indicator Types** and **Groups**. For example, all our custom "Campaign" attributes are fine, but many on "Adversary" are missing.
* No errors in the logs during upgrade that seemed related to attributes.

I'm wondering if there's a known issue with attribute migration during upgrades, or maybe a new permission or setting we missed? We rely heavily on these for automation and tagging.

Has anyone else hit this? Any ideas on how to *restore* the attribute association to the indicator/group types without having to recreate them all? Recreating would mean losing all the historical data stored in them, which is a big concern.

Any pointers would be hugely appreciated! I can provide more specific details if needed.

~CloudOps


Infrastructure as code is the only way


   
Quote