Skip to content

Commit 6084b21

Browse files
authored
Merge branch 'main' into 5606-cspm-agentless-onboard-beta
2 parents 952df1f + 3c6e809 commit 6084b21

22 files changed

+88
-60
lines changed

.mergify.yml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,19 @@ pull_request_rules:
1313
git merge upstream/{{base}}
1414
git push upstream {{head}}
1515
```
16+
- name: backport patches to main branch
17+
conditions:
18+
- merged
19+
- label=backport-main
20+
actions:
21+
backport:
22+
assignees:
23+
- "{{ author }}"
24+
labels:
25+
- "backport"
26+
branches:
27+
- "main"
28+
title: "[{{ destination_branch }}] {{ title }} (backport #{{ number }})"
1629
- name: backport patches to 8.17 branch
1730
conditions:
1831
- merged

docs/advanced-entity-analytics/api/asset-criticality-api-overview.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,4 +8,4 @@
88
For the most up-to-date API details, refer to {api-kibana}/group/endpoint-security-entity-analytics-api[Entity Analytics APIs].
99
--
1010

11-
You can manage <<asset-criticality, asset criticality>> records through the API. To use this API, you must first turn on the `securitySolution:enableAssetCriticality` <<enable-asset-criticality, advanced setting>>.
11+
You can manage <<asset-criticality, asset criticality>> records through the API.

docs/advanced-entity-analytics/asset-criticality.asciidoc

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,7 @@
44
.Requirements
55
[sidebar]
66
--
7-
To view and assign asset criticality, you must:
8-
9-
* Have the appropriate user role.
10-
* Turn on the `securitySolution:enableAssetCriticality` <<enable-asset-criticality, advanced setting>>.
11-
12-
For more information, refer to <<ers-requirements, Entity risk scoring prerequisites>>.
7+
To view and assign asset criticality, you must have the appropriate user role. For more information, refer to <<ers-requirements, Entity risk scoring prerequisites>>.
138
--
149

1510
The asset criticality feature allows you to classify your organization's entities based on various operational factors that are important to your organization. Through this classification, you can improve your threat detection capabilities by focusing your alert triage, threat-hunting, and investigation activities on high-impact entities.

docs/advanced-entity-analytics/entity-risk-scoring.asciidoc

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -30,11 +30,7 @@ Entity risk scores are determined by the following risk inputs:
3030

3131
The resulting entity risk scores are stored in the `risk-score.risk-score-<space-id>` data stream alias.
3232

33-
[NOTE]
34-
======
35-
* Entities without any alerts, or with only `Closed` alerts, are not assigned a risk score.
36-
* To use asset criticality, you must enable the `securitySolution:enableAssetCriticality` <<enable-asset-criticality, advanced setting>>.
37-
======
33+
NOTE: Entities without any alerts, or with only `Closed` alerts, are not assigned a risk score.
3834

3935
[discrete]
4036
[[how-is-risk-score-calculated]]

docs/advanced-entity-analytics/ers-req.asciidoc

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,8 +45,6 @@ The risk scoring engine uses an internal user role to score all hosts and users,
4545
[discrete]
4646
== Asset criticality
4747

48-
To use the asset criticality feature, turn on the `securitySolution:enableAssetCriticality` <<enable-asset-criticality, advanced setting>>.
49-
5048
[discrete]
5149
=== Privileges
5250

docs/detections/alerts-view-details.asciidoc

Lines changed: 23 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,10 +124,32 @@ image::images/visualizations-section-rp.png[Visualizations section of the Overvi
124124

125125
Click **Visualizations** to display the following previews:
126126

127-
* **Session view preview**: Shows a preview of <<session-view,session view>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
127+
* **Session viewer preview**: Shows a preview of <<session-view,Session View>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
128128

129129
* **Analyzer preview**: Shows a preview of the <<visual-event-analyzer,visual analyzer graph>>. The preview displays up to three levels of the analyzed event's ancestors and up to three levels of the event's descendants and children. The ellipses symbol (**`...`**) indicates the event has more ancestors and descendants to examine. Click **Analyzer preview** to open the **Event Analyzer** tab in Timeline.
130130

131+
[discrete]
132+
[[expanded-visualizations-view]]
133+
=== Expanded visualizations view
134+
135+
preview::[]
136+
137+
.Requirements
138+
[sidebar]
139+
--
140+
To use the **Visualize** tab, you must turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>>.
141+
--
142+
143+
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session viewer preview** or **Analyzer preview** from the right panel.
144+
145+
[role="screenshot"]
146+
image::images/visualize-tab-lp.png[Expanded view of visualization details, 80%]
147+
148+
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout.
149+
150+
[role="screenshot"]
151+
image::images/visualize-tab-lp-alert-details.gif[Examine alert details from event analyzer, 80%]
152+
131153
[discrete]
132154
[[insights-section]]
133155
== Insights
516 KB
Loading
285 KB
Loading

docs/detections/visual-event-analyzer.asciidoc

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,9 @@ Or
2929
+
3030
** `agent.type:"winlogbeat" and event.module: "sysmon" and process.entity_id : *`
3131

32-
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. Alternatively, open the alert details flyout, go to the Visualizations section, then click **Analyzer preview**. This opens the **Analyzer** tab in Timeline.
32+
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. The event analyzer is accessible from the **Hosts**, **Alerts**, and **Timelines** pages, as well as the alert details flyout.
33+
+
34+
TIP: Turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>> to access the event analyzer from the **Visualize** tab in the alert or event details flyout.
3335

3436
+
3537
[role="screenshot"]

docs/getting-started/advanced-setting.asciidoc

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -102,17 +102,20 @@ Security *Overview* page.
102102
* `securitySolution:newsFeedUrl`: The URL from which the security news feed content is
103103
retrieved.
104104

105-
[discrete]
106-
[[enable-asset-criticality]]
107-
== Enable asset criticality workflows
108-
The `securitySolution:enableAssetCriticality` setting determines whether asset criticality is included as a risk input to entity risk scoring. This setting is turned off by default. Turn it on to enable asset criticality workflows and to use asset criticality as part of entity risk scoring.
109-
110105
[discrete]
111106
[[exclude-cold-frozen-tiers]]
112107
== Exclude cold and frozen tier data from analyzer queries
113108

114109
Including data from cold and frozen {ref}/data-tiers.html[data tiers] in <<visual-event-analyzer, visual event analyzer>> queries may result in performance degradation. The `securitySolution:excludeColdAndFrozenTiersInAnalyzer` setting allows you to exclude this data from analyzer queries. This setting is turned off by default.
115110

111+
[discrete]
112+
[[visualizations-in-flyout]]
113+
== Access the event analyzer and Session View from the event or alert details flyout
114+
115+
preview::[]
116+
117+
The `securitySolution:enableVisualizationsInFlyout` setting allows you to access the event analyzer and Session View in the **Visualize** <<expanded-visualizations-view,tab>> on the alert or event details flyout. This setting is turned off by default.
118+
116119
[discrete]
117120
== Change the default search interval and data refresh time
118121

0 commit comments

Comments
 (0)