You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/detections/alerts-view-details.asciidoc
+10Lines changed: 10 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -290,3 +290,13 @@ The **Response** section is located on the **Overview** tab in the right panel.
290
290
image::images/response-action-rp.png[Response section of the Overview tab, 50%]
291
291
292
292
293
+
[discrete]
294
+
[[expanded-notes-view]]
295
+
== Notes tab
296
+
297
+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
298
+
299
+
TIP: Go to the **Notes** <<manage-notes,page>> to find notes that were added to other alerts.
300
+
301
+
[role="screenshot"]
302
+
image::images/notes-tab-lp.png[Notes tab in the left panel, 70%]
Copy file name to clipboardExpand all lines: docs/events/add-manage-notes.asciidoc
+25-18Lines changed: 25 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,31 +3,38 @@
3
3
4
4
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
5
5
6
-
== Add notes
6
+
[discrete]
7
+
[[add-notes-documents]]
8
+
== Add notes to alerts and events
7
9
8
-
To add a note to an alert:
10
+
From the Alerts or Events tables, click the image:images/add-note-icon.png[Add note,15,15] icon to create a new note for an alert or event. Alternatively, use the **Notes** tab in the left panel of the event or alert details flyout, or click the **Add note** image:images/add-note.png[Add note,15,15] icon in the right panel (only available for alerts).
9
11
10
-
. Find **Alerts** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field].
11
-
. Scroll down to the Alerts table, go to the alert you want to add a note to, then click the notes icon. The **Notes** tab in the alert details flyout opens.
12
-
. Enter a note into the text box, then click **Add note**.
12
+
NOTE: Notes that you add to alerts or events in Timeline are automatically attached to the current Timeline. Deselecting the **Attach to current Timeline** option ensures thats notes are added to the alert or event only.
13
13
14
-
To add a note to an event:
14
+
[discrete]
15
+
[[add-notes-timelines]]
16
+
== Create notes for Timelines
15
17
16
-
. Find **Explore** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Hosts**, **Users**, **Network**.
17
-
. Scroll down to the **Events** tab, go to the event you want to add a note to, then click the notes icon. The **Notes** tab in the events details flyout opens.
18
-
. Enter a note into the text box, then click **Add note**.
18
+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
19
19
20
-
To add a note to a saved Timeline:
20
+
[discrete]
21
+
[[manage-notes]]
22
+
== Find and manage notes
21
23
22
-
. Do one of the following:
23
-
** Find **Timeline** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then click a Timeline's title.
24
-
** Go to the Timeline bar, click the image:images/add-new-timeline-button.png[Click the add new button,20,20] button, then click **Open Timeline**. Click a Timeline's title to open it.
25
-
. Go to the **Notes** tab.
26
-
. Enter a note into the text box, then click **Add note**.
Copy file name to clipboardExpand all lines: docs/getting-started/advanced-setting.asciidoc
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -178,9 +178,9 @@ The `securitySolution:alertTags` field determines which options display in the a
178
178
179
179
[discrete]
180
180
[[max-notes-alerts-events]]
181
-
== Specify the maximum number of notes for alerts or events
181
+
== Set the maximum notes limit for alerts or events
182
182
183
-
The `securitySolution:maxUnassociatedNotes` field determines the maximum number of notes that you can attach to an alert or event. The maximum limit and default value is 1000.
183
+
The `securitySolution:maxUnassociatedNotes` field determines the maximum number of <<add-manage-notes,notes>> that you can attach to alerts and events. The maximum limit and default value is 1000.
Copy file name to clipboardExpand all lines: docs/serverless/alerts/view-alert-details.mdx
+12Lines changed: 12 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -278,3 +278,15 @@ The expanded Prevalence view provides the following details:
278
278
The **Response** section is located on the **Overview** tab in the right panel. It shows <DocLinkslug="/serverless/security/rules-create">response actions</DocLink> that were added to the rule associated with the alert. Click **Response** to display the response action's results in the left panel.
279
279
280
280
<DocImagesize="l"url="../images/view-alert-details/-detections-response-action-rp.png"alt="Response section of the Overview tab"/>
281
+
282
+
<divid="expanded-notes-view"></div>
283
+
284
+
## Notes tab
285
+
286
+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
287
+
288
+
<DocCallOuttitle="Tip">
289
+
Go to the **Notes** <DocLinkslug="/serverless/security/add-manage-notes"section="manage-notes">page</DocLink> to find notes that were added to other alerts.
290
+
</DocCallOut>
291
+
292
+
<DocImagesize="l"url="../images/view-alert-details/-detections-notes-tab-lp.png"alt="Notes tab in the left panel"/>
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
12
12
13
-
## Add notes
13
+
<divid="add-notes-documents"></div>
14
14
15
-
To add a note to an alert:
15
+
## Add notes to alerts and events
16
16
17
-
1. Find **Alerts** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search).
18
-
1. Scroll down to the Alerts table, go to the alert you want to add a note to, then click the notes icon. The **Notes** tab in the alert details flyout opens.
19
-
1. Enter a note into the text box, then click **Add note**.
17
+
From the Alerts or Events tables, click the **Add note** (<DocIcontype="editorComment"title="The icon that lets you to add a new note" />) icon to create a new note for an alert or event. Alternatively, use the **Notes** tab in the left panel of the event or alert details flyout, or click the **Add note** (<DocIcontype="plusInCircle"title="The icon that lets you to add a new note" />) icon in the right panel (only available for alerts).
20
18
21
-
To add a note to an event:
19
+
<DocCallOuttitle="Note">
20
+
Notes that you add to alerts or events in Timeline are automatically attached to the current Timeline. Deselecting the **Attach to current Timeline** option ensures thats notes are added to the alert or event only.
21
+
</DocCallOut>
22
22
23
-
1. Find **Explore** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search), then go to **Hosts**, **Users**, **Network**.
24
-
1. Scroll down to the **Events** tab, go to the event you want to add a note to, then click the notes icon. The **Notes** tab in the events details flyout opens.
25
-
1. Enter a note into the text box, then click **Add note**.
23
+
<divid="add-notes-timelines"></div>
26
24
27
-
To add a note to a saved Timeline:
25
+
## Create notes for Timelines
28
26
29
-
1. Do one of the following:
30
-
* Find **Timeline** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search), then click a Timeline's title.
31
-
* Go to the Timeline bar, click the image:images/add-new-timeline-button.png[Click the add new button,20,20] button, then click **Open Timeline**. Click a Timeline's title to open it.
32
-
1. Go to the **Notes** tab.
33
-
1. Enter a note into the text box, then click **Add note**.
27
+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
0 commit comments