You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):
17
-
18
-
$$$default-data-view-security$$$
7
+
# {{data-sources-ca[]}} and {{elastic-sec}} [security-data-views-in-sec]
19
8
20
9
{{data-sources-cap}} determine what data displays on {{elastic-sec}} pages with event or alert data. {{data-sources-cap}} are defined by the index patterns they include. Only data from {{es}} [indices](/manage-data/data-store/index-basics.md), [data streams](/manage-data/data-store/index-types/data-streams.md), or [index aliases](https://www.elastic.co/guide/en/elasticsearch/reference/current/alias.html) specified in the active {{data-source}} will appear.
21
10
@@ -25,7 +14,7 @@ Custom indices are not included in the [default {{data-source}}](/solutions/secu
25
14
26
15
27
16
28
-
## Switch to another {{data-source}} [_switch_to_another_data_source]
17
+
## Switch to another {{data-source}} [security-data-views-in-sec-switch-to-another-data-source]
29
18
30
19
You can tell which {{data-source}} is active by clicking the **{{data-source-cap}}** menu at the upper right of {{elastic-sec}} pages that display event or alert data, such as Overview, Alerts, Timelines, or Hosts. To switch to another {{data-source}}, click **Choose {{data-source}}**, select one of the options, and click **Save**.
31
20
@@ -34,7 +23,7 @@ You can tell which {{data-source}} is active by clicking the **{{data-source-cap
34
23
:::
35
24
36
25
37
-
## Create or modify a {{data-source}} [_create_or_modify_a_data_source]
26
+
## Create or modify a {{data-source}} [security-data-views-in-sec-create-or-modify-a-data-source]
38
27
39
28
To learn how to modify the default **Security Default Data View**, refer to [Update default {{elastic-sec}} indices](/solutions/security/get-started/configure-advanced-settings.md#update-sec-indices).
40
29
@@ -60,6 +49,8 @@ The default {{data-source}} is defined by the `securitySolution:defaultIndex` se
60
49
61
50
The first time a user visits {{elastic-sec}} within a given {{kib}} [space](/deploy-manage/manage-spaces.md), the default {{data-source}} generates in that space and becomes active.
62
51
52
+
% Needs annotation to show that it's only applicable to ESS
53
+
63
54
::::{note}
64
55
Your {{kib}} space must have **Data View Management**[feature visibility](/deploy-manage/manage-spaces.md#spaces-control-feature-visibility) setting enabled for the default {{data-source}} to generate and become active in your space.
0 commit comments