Skip to content

Commit 2d6d74a

Browse files
Fixes toc and introduces images
1 parent 6fc6d18 commit 2d6d74a

File tree

13 files changed

+81
-40
lines changed

13 files changed

+81
-40
lines changed

docs/detections/alerts-view-details.asciidoc

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -290,3 +290,13 @@ The **Response** section is located on the **Overview** tab in the right panel.
290290
image::images/response-action-rp.png[Response section of the Overview tab, 50%]
291291

292292

293+
[discrete]
294+
[[expanded-notes-view]]
295+
== Notes tab
296+
297+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
298+
299+
TIP: Go to the **Notes** <<manage-notes,page>> to find notes that were added to other alerts.
300+
301+
[role="screenshot"]
302+
image::images/notes-tab-lp.png[Notes tab in the left panel, 70%]
137 KB
Loading

docs/events/add-manage-notes.asciidoc

Lines changed: 25 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -3,31 +3,38 @@
33

44
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
55

6-
== Add notes
6+
[discrete]
7+
[[add-notes-documents]]
8+
== Add notes to alerts and events
79

8-
To add a note to an alert:
10+
From the Alerts or Events tables, click the image:images/add-note-icon.png[Add note,15,15] icon to create a new note for an alert or event. Alternatively, use the **Notes** tab in the left panel of the event or alert details flyout, or click the **Add note** image:images/add-note.png[Add note,15,15] icon in the right panel (only available for alerts).
911

10-
. Find **Alerts** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field].
11-
. Scroll down to the Alerts table, go to the alert you want to add a note to, then click the notes icon. The **Notes** tab in the alert details flyout opens.
12-
. Enter a note into the text box, then click **Add note**.
12+
NOTE: Notes that you add to alerts or events in Timeline are automatically attached to the current Timeline. Deselecting the **Attach to current Timeline** option ensures thats notes are added to the alert or event only.
1313

14-
To add a note to an event:
14+
[discrete]
15+
[[add-notes-timelines]]
16+
== Create notes for Timelines
1517

16-
. Find **Explore** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Hosts**, **Users**, **Network**.
17-
. Scroll down to the **Events** tab, go to the event you want to add a note to, then click the notes icon. The **Notes** tab in the events details flyout opens.
18-
. Enter a note into the text box, then click **Add note**.
18+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
1919

20-
To add a note to a saved Timeline:
20+
[discrete]
21+
[[manage-notes]]
22+
== Find and manage notes
2123

22-
. Do one of the following:
23-
** Find **Timeline** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then click a Timeline's title.
24-
** Go to the Timeline bar, click the image:images/add-new-timeline-button.png[Click the add new button,20,20] button, then click **Open Timeline**. Click a Timeline's title to open it.
25-
. Go to the **Notes** tab.
26-
. Enter a note into the text box, then click **Add note**.
24+
//Security solution view nav: Investigations -> Notes
25+
//Classic nav view: Manage -> Investigations -> Notes
2726

28-
== Manage notes
29-
30-
To manage notes....
27+
The **Notes** page allows you to view and interact with all existing notes. From the table, you can:
3128

29+
* Search for specific notes or filter notes by:
30+
** The user who created them
31+
** The type of object that they're attached to (notes can be attached to alerts, events, Timelines, or nothing)
32+
* Examine the contents of a note by clicking on the text in the **Note content** column
33+
* Delete individual or multiple notes
34+
* Preview the alert or event that a note is attached to
35+
* Open the note in Timeline (this option is only available for alerts or events with notes attached to a saved Timeline)
3236

37+
[role="screenshot"]
38+
image::images/notes-management-page.png[Notes management page, 80%]
3339

40+
TIP: You can also manage notes for individual alerts, events, and Timelines from the **Notes** tab in the event or alert details flyout or Timeline.
848 Bytes
Loading

docs/events/timeline-ui-overview.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@ You can also modify a Timeline's display in other ways:
7272
* Copy a column name or values to a clipboard
7373
* Change how the name, value, and description of a field are displayed in Timeline
7474
* View the Timeline in full screen mode
75-
* Add or delete notes on alerts, events, or Timeline
75+
* Add or delete <<add-manage-notes,notes>> attached to alerts, events, or Timeline
7676
* Pin interesting events to the Timeline
7777

7878
[discrete]

docs/getting-started/advanced-setting.asciidoc

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -178,9 +178,9 @@ The `securitySolution:alertTags` field determines which options display in the a
178178

179179
[discrete]
180180
[[max-notes-alerts-events]]
181-
== Specify the maximum number of notes for alerts or events
181+
== Set the maximum notes limit for alerts or events
182182

183-
The `securitySolution:maxUnassociatedNotes` field determines the maximum number of notes that you can attach to an alert or event. The maximum limit and default value is 1000.
183+
The `securitySolution:maxUnassociatedNotes` field determines the maximum number of <<add-manage-notes,notes>> that you can attach to alerts and events. The maximum limit and default value is 1000.
184184

185185
[discrete]
186186
[[exclude-cold-frozen-data-rule-executions]]

docs/serverless/alerts/view-alert-details.mdx

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -278,3 +278,15 @@ The expanded Prevalence view provides the following details:
278278
The **Response** section is located on the **Overview** tab in the right panel. It shows <DocLink slug="/serverless/security/rules-create">response actions</DocLink> that were added to the rule associated with the alert. Click **Response** to display the response action's results in the left panel.
279279

280280
<DocImage size="l" url="../images/view-alert-details/-detections-response-action-rp.png" alt="Response section of the Overview tab"/>
281+
282+
<div id="expanded-notes-view"></div>
283+
284+
## Notes tab
285+
286+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
287+
288+
<DocCallOut title="Tip">
289+
Go to the **Notes** <DocLink slug="/serverless/security/add-manage-notes" section="manage-notes">page</DocLink> to find notes that were added to other alerts.
290+
</DocCallOut>
291+
292+
<DocImage size="l" url="../images/view-alert-details/-detections-notes-tab-lp.png" alt="Notes tab in the left panel"/>
147 KB
Loading
137 KB
Loading

docs/serverless/investigate/add-manage-notes.mdx

Lines changed: 27 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -10,31 +10,42 @@ tags: ["serverless","security","how-to","manage"]
1010

1111
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
1212

13-
## Add notes
13+
<div id="add-notes-documents"></div>
1414

15-
To add a note to an alert:
15+
## Add notes to alerts and events
1616

17-
1. Find **Alerts** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search).
18-
1. Scroll down to the Alerts table, go to the alert you want to add a note to, then click the notes icon. The **Notes** tab in the alert details flyout opens.
19-
1. Enter a note into the text box, then click **Add note**.
17+
From the Alerts or Events tables, click the **Add note** (<DocIcon type="editorComment" title="The icon that lets you to add a new note" />) icon to create a new note for an alert or event. Alternatively, use the **Notes** tab in the left panel of the event or alert details flyout, or click the **Add note** (<DocIcon type="plusInCircle" title="The icon that lets you to add a new note" />) icon in the right panel (only available for alerts).
2018

21-
To add a note to an event:
19+
<DocCallOut title="Note">
20+
Notes that you add to alerts or events in Timeline are automatically attached to the current Timeline. Deselecting the **Attach to current Timeline** option ensures thats notes are added to the alert or event only.
21+
</DocCallOut>
2222

23-
1. Find **Explore** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search), then go to **Hosts**, **Users**, **Network**.
24-
1. Scroll down to the **Events** tab, go to the event you want to add a note to, then click the notes icon. The **Notes** tab in the events details flyout opens.
25-
1. Enter a note into the text box, then click **Add note**.
23+
<div id="add-notes-timelines"></div>
2624

27-
To add a note to a saved Timeline:
25+
## Create notes for Timelines
2826

29-
1. Do one of the following:
30-
* Find **Timeline** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search), then click a Timeline's title.
31-
* Go to the Timeline bar, click the image:images/add-new-timeline-button.png[Click the add new button,20,20] button, then click **Open Timeline**. Click a Timeline's title to open it.
32-
1. Go to the **Notes** tab.
33-
1. Enter a note into the text box, then click **Add note**.
27+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
28+
29+
<div id="manage-notes"></div>
3430

3531
## Manage notes
3632

37-
To manage notes....
33+
{/* Security solution view nav: Investigations -> Notes */}
34+
35+
The **Notes** page allows you to view and interact with all existing notes. From the table, you can:
36+
* Search for specific notes or filter notes by:
37+
* The user who created them
38+
* The type of object that they're attached to (notes can be attached to alerts, events, Timelines, or nothing)
39+
* Examine the contents of a note by clicking on the text in the **Note content** column
40+
* Delete individual or multiple notes
41+
* Preview the alert or event that a note is attached to
42+
* Open the note in Timeline (this option is only available for alerts or events with notes attached to a saved Timeline)
43+
44+
<DocImage size="l" url="../images/notes/-notes-management-page.png" alt="Notes management page"/>
45+
46+
<DocCallOut title="Tip">
47+
You can manage notes for individual alerts, events, and Timelines from the **Notes** tab in the event or alert details flyout or Timeline.
48+
</DocCallOut>
3849

3950

4051

0 commit comments

Comments
 (0)