Skip to content
Merged
Show file tree
Hide file tree
Changes from 3 commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
e7f4131
updates "Ingest data to Elastic Security"
nastasha-solomon Feb 19, 2025
4a1c055
Re-add missing ref
nastasha-solomon Feb 19, 2025
fe039f3
Data views and Elastic Security
nastasha-solomon Feb 19, 2025
3df2924
Update solutions/security/get-started/data-views-elastic-security.md
nastasha-solomon Feb 19, 2025
e4633ea
First pass at advanced setting page
nastasha-solomon Feb 19, 2025
8261d2f
Merge branch 'rip-serverless-files-pt1' of https://github.com/elastic…
nastasha-solomon Feb 19, 2025
0a1162c
Applies deployment info
nastasha-solomon Feb 20, 2025
49d7f4e
Aligns more content
nastasha-solomon Feb 20, 2025
e4e6b17
Update to toc
nastasha-solomon Feb 20, 2025
7a6bd2e
Removes comments
nastasha-solomon Feb 20, 2025
73754a6
Updates relative path
nastasha-solomon Feb 20, 2025
749a037
Fix shared attribute and URL
nastasha-solomon Feb 20, 2025
5620267
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 20, 2025
4c46875
Update raw-migrated-files/toc.yml
nastasha-solomon Feb 21, 2025
ebe499b
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 21, 2025
ef86e86
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 21, 2025
b400393
Adjusted wording
nastasha-solomon Feb 21, 2025
0aad399
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 23, 2025
d8c81ce
Minor styling fixes
nastasha-solomon Feb 23, 2025
850b985
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 24, 2025
e662574
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 26, 2025
89fb0ea
a fie on you ye wretched toc refs!
nastasha-solomon Feb 26, 2025
16c2bcb
unwelcoming you from the toc party
nastasha-solomon Feb 26, 2025
41af8a7
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 26, 2025
d7a5529
Update solutions/security/get-started/ingest-data-to-elastic-security.md
nastasha-solomon Feb 27, 2025
fac5489
Update solutions/security/get-started/data-views-elastic-security.md
nastasha-solomon Feb 27, 2025
12e6aeb
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 27, 2025
4d017da
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 27, 2025
48636b5
Merge branch 'main' into rip-serverless-files-pt1
nastasha-solomon Feb 27, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file removed images/security-dataview-filter-example copy.gif
Binary file not shown.
Binary file not shown.
Binary file not shown.

This file was deleted.

114 changes: 0 additions & 114 deletions raw-migrated-files/docs-content/serverless/security-ingest-data.md

This file was deleted.

4 changes: 1 addition & 3 deletions raw-migrated-files/toc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -379,7 +379,6 @@ toc:
- file: docs-content/serverless/security-cspm.md
- file: docs-content/serverless/security-dashboards-overview.md
- file: docs-content/serverless/security-data-quality-dash.md
- file: docs-content/serverless/security-data-views-in-sec.md
- file: docs-content/serverless/security-detection-engine-overview.md
- file: docs-content/serverless/security-detection-entity-dashboard.md
- file: docs-content/serverless/security-detection-response-dashboard.md
Expand All @@ -393,7 +392,6 @@ toc:
- file: docs-content/serverless/security-get-started-with-kspm.md
- file: docs-content/serverless/security-host-isolation-exceptions.md
- file: docs-content/serverless/security-hosts-overview.md
- file: docs-content/serverless/security-ingest-data.md
- file: docs-content/serverless/security-install-edr.md
- file: docs-content/serverless/security-install-endpoint-manually.md
- file: docs-content/serverless/security-interactive-investigation-guides.md
Expand All @@ -418,9 +416,9 @@ toc:
- file: docs-content/serverless/security-query-alert-indices.md
- file: docs-content/serverless/security-query-operating-systems.md
- file: docs-content/serverless/security-reduce-notifications-alerts.md
- file: docs-content/serverless/security-requirements-overview.md
- file: docs-content/serverless/security-response-actions-config.md
- file: docs-content/serverless/security-response-actions-history.md
- file: docs-content/serverless/security-requirements-overview.md
- file: docs-content/serverless/security-response-actions.md
- file: docs-content/serverless/security-rule-monitoring-dashboard.md
- file: docs-content/serverless/security-rules-coverage.md
Expand Down
19 changes: 5 additions & 14 deletions solutions/security/get-started/data-views-elastic-security.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,7 @@
- https://www.elastic.co/guide/en/serverless/current/security-data-views-in-sec.html
---

# Data views and Elastic Security

% What needs to be done: Lift-and-shift

% Use migrated content from existing pages that map to this page:

% - [x] ./raw-migrated-files/security-docs/security/data-views-in-sec.md
% - [ ] ./raw-migrated-files/docs-content/serverless/security-data-views-in-sec.md

% Internal links rely on the following IDs being on this page (e.g. as a heading ID, paragraph ID, etc):

$$$default-data-view-security$$$
# {{data-sources-ca[]}} and {{elastic-sec}} [security-data-views-in-sec]

Check failure on line 7 in solutions/security/get-started/data-views-elastic-security.md

View workflow job for this annotation

GitHub Actions / preview / build

Substitution key {data-sources-ca[]} is undefined

{{data-sources-cap}} determine what data displays on {{elastic-sec}} pages with event or alert data. {{data-sources-cap}} are defined by the index patterns they include. Only data from {{es}} [indices](/manage-data/data-store/index-basics.md), [data streams](/manage-data/data-store/index-types/data-streams.md), or [index aliases](https://www.elastic.co/guide/en/elasticsearch/reference/current/alias.html) specified in the active {{data-source}} will appear.

Expand All @@ -25,7 +14,7 @@



## Switch to another {{data-source}} [_switch_to_another_data_source]
## Switch to another {{data-source}} [security-data-views-in-sec-switch-to-another-data-source]

You can tell which {{data-source}} is active by clicking the **{{data-source-cap}}** menu at the upper right of {{elastic-sec}} pages that display event or alert data, such as Overview, Alerts, Timelines, or Hosts. To switch to another {{data-source}}, click **Choose {{data-source}}**, select one of the options, and click **Save**.

Expand All @@ -34,7 +23,7 @@
:::


## Create or modify a {{data-source}} [_create_or_modify_a_data_source]
## Create or modify a {{data-source}} [security-data-views-in-sec-create-or-modify-a-data-source]

To learn how to modify the default **Security Default Data View**, refer to [Update default {{elastic-sec}} indices](/solutions/security/get-started/configure-advanced-settings.md#update-sec-indices).

Expand All @@ -60,6 +49,8 @@

The first time a user visits {{elastic-sec}} within a given {{kib}} [space](/deploy-manage/manage-spaces.md), the default {{data-source}} generates in that space and becomes active.

% Needs annotation to show that it's only applicable to ESS

::::{note}
Your {{kib}} space must have **Data View Management** [feature visibility](/deploy-manage/manage-spaces.md#spaces-control-feature-visibility) setting enabled for the default {{data-source}} to generate and become active in your space.
::::
Expand Down
Loading
Loading