You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/events/timeline-ui-overview.asciidoc
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,7 +58,7 @@ Many types of events automatically appear in preconfigured views that provide re
58
58
contextual information, called *Event renderers*. All event renderers are turned off by default. To turn them on, use the **Event renderers** toggle at the top of the results pane. To only turn on specific event renderers, click the gear (image:images/customize-event-renderers.png[The customize event renderer button,20,20]) icon next to the toggle, and select the ones you want enabled. Close the **Customize event renderers** pane when you're done. Your changes are automatically applied to Timeline.
59
59
60
60
[role="screenshot"]
61
-
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted]
61
+
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted, 70%]
62
62
63
63
The example above displays the Flow event renderer, which highlights the movement of
64
64
data between its source and destination. If you see a particular part of the rendered event that
Copy file name to clipboardExpand all lines: docs/serverless/alerts/view-alert-details.asciidoc
+18-18Lines changed: 18 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ preview:[]
13
13
To learn more about an alert, click the **View details** button from the Alerts table. This opens the alert details flyout, which helps you understand and manage the alert.
Use the alert details flyout to begin an investigation, open a case, or plan a response. Click **Take action** at the bottom of the flyout to find more options for interacting with the alert.
19
19
@@ -30,12 +30,12 @@ The alert details flyout has a right panel, a preview panel, and a left panel. E
30
30
The right panel provides an overview of the alert. Expand any of the collapsed sections to learn more about the alert. You can also hover over fields on the **Overview** and **Table** tabs to display available <<inline-actions,inline actions>>.
31
31
32
32
[role="screenshot"]
33
-
image::images/view-alert-details/-detections-alert-details-flyout-right-panel.png[Right panel of the alert details flyout]
33
+
image::images/view-alert-details/-detections-alert-details-flyout-right-panel.png[Right panel of the alert details flyout, 65%]
34
34
35
35
From the right panel, you can also:
36
36
37
37
* Click **Expand details** to open the <<left-panel,left panel>>, which shows more information about sections in the right panel.
38
-
* Click the **Chat** icon (image:images/icons/discuss.svg[Chat]) to access the <<security-ai-assistant>>.
38
+
* Click the **Chat** icon (image:images/view-alert-details/ai-assistant-chat.png[AI assistant chat icon,15,15]) to access the <<security-ai-assistant>>.
39
39
* Click the **Share alert** icon (image:images/icons/share.svg[Share alert]) to get a shareable alert URL. We _do not_ recommend copying the URL from your browser's address bar, which can lead to inconsistent results if you've set up filters or relative time ranges for the Alerts page.
40
40
+
41
41
[NOTE]
@@ -64,7 +64,7 @@ If you've enabled grouping on the Alerts page, the alert details flyout won't op
64
64
Some areas in the flyout provide previews when you click on them. For example, clicking **Show rule summary** in the rule description displays a preview of the rule's details. To close the preview, click **Back** or **x**.
65
65
66
66
[role="screenshot"]
67
-
image::images/view-alert-details/-detections-alert-details-flyout-preview-panel.gif[Preview panel of the alert details flyout]
67
+
image::images/view-alert-details/-detections-alert-details-flyout-preview-panel.gif[Preview panel of the alert details flyout, 65%]
68
68
69
69
[discrete]
70
70
[[left-panel]]
@@ -75,7 +75,7 @@ The left panel provides an expanded view of what's shown in the right panel. To
75
75
* Click **Expand details** at the top of the right panel.
76
76
+
77
77
[role="screenshot"]
78
-
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout]
78
+
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout, 45%]
79
79
* Click one of the section titles on the **Overview** tab within the right panel.
The About section is located on the **Overview** tab in the right panel. It provides a brief description of the rule that's related to the alert and an explanation of what generated the alert.
89
89
90
90
[role="screenshot"]
91
-
image::images/view-alert-details/-detections-about-section-rp.png[About section of the Overview tab]
91
+
image::images/view-alert-details/-detections-about-section-rp.png[About section of the Overview tab, 65%]
92
92
93
93
The About section has the following information:
94
94
@@ -109,7 +109,7 @@ The event renderer only displays if an event renderer exists for the alert type.
109
109
The Investigation section is located on the **Overview** tab in the right panel. It offers a couple of ways to begin investigating the alert.
110
110
111
111
[role="screenshot"]
112
-
image::images/view-alert-details/-detections-investigation-section-rp.png[Investigation section of the Overview tab]
112
+
image::images/view-alert-details/-detections-investigation-section-rp.png[Investigation section of the Overview tab, 65%]
113
113
114
114
The Investigation section provides the following information:
115
115
@@ -128,7 +128,7 @@ Add an <<add-ig-actions-rule,investigation guide>> to a rule when creating a new
128
128
The Visualizations section is located on the **Overview** tab in the right panel. It offers a glimpse of the processes that led up to the alert and occurred after it.
129
129
130
130
[role="screenshot"]
131
-
image::images/view-alert-details/-detections-visualizations-section-rp.png[Visualizations section of the Overview tab]
131
+
image::images/view-alert-details/-detections-visualizations-section-rp.png[Visualizations section of the Overview tab, 65%]
132
132
133
133
Click **Visualizations** to display the following previews:
134
134
@@ -150,7 +150,7 @@ To use the **Visualize** tab, you must turn on the `securitySolution:enableVisua
150
150
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session view preview** or **Analyzer preview** from the right panel.
151
151
152
152
[role="screenshot"]
153
-
image::images/view-alert-details/-detections-visualize-tab-lp.png[Expanded view of visualization details]
153
+
image::images/view-alert-details/-detections-visualize-tab-lp.png[Expanded view of visualization details, 80%]
154
154
155
155
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout.
The Insights section is located on the **Overview** tab in the right panel. It offers different perspectives from which you can assess the alert. Click **Insights** to display overviews for <<entities-overview,related entities>>, <<threat-intelligence-overview,threat intelligence>>, <<correlations-overview,correlated data>>, and <<prevalence-overview,host and user prevalence>>.
165
165
166
166
[role="screenshot"]
167
-
image::images/view-alert-details/-detections-insights-section-rp.png[Insights section of the Overview tab]
167
+
image::images/view-alert-details/-detections-insights-section-rp.png[Insights section of the Overview tab, 65%]
168
168
169
169
[discrete]
170
170
[[entities-overview]]
@@ -173,7 +173,7 @@ image::images/view-alert-details/-detections-insights-section-rp.png[Insights se
173
173
The Entities overview provides high-level details about the user and host that are related to the alert. Host and user risk classifications are also available if you have the Security Analytics Complete <<elasticsearch-manage-project,project feature>>.
174
174
175
175
[role="screenshot"]
176
-
image::images/view-alert-details/-detections-entities-overview.png[Overview of the entity details section in the right panel]
176
+
image::images/view-alert-details/-detections-entities-overview.png[Overview of the entity details section in the right panel, 60%]
177
177
178
178
[discrete]
179
179
[[expanded-entities-view]]
@@ -182,7 +182,7 @@ image::images/view-alert-details/-detections-entities-overview.png[Overview of t
182
182
From the right panel, click **Entities** to open a detailed view of the host and user associated with the alert. The expanded view also includes risk scores and classifications (if you have the Security Analytics Complete <<elasticsearch-manage-project,project feature>>) and activity on related hosts and users.
183
183
184
184
[role="screenshot"]
185
-
image::images/view-alert-details/-detections-expanded-entities-view.png[Expanded view of entity details]
185
+
image::images/view-alert-details/-detections-expanded-entities-view.png[Expanded view of entity details, 70%]
The Threat intelligence overview shows matched indicators, which provide threat intelligence relevant to the alert.
192
192
193
193
[role="screenshot"]
194
-
image::images/view-alert-details/-detections-threat-intelligence-overview.png[Overview of threat intelligence on the alert]
194
+
image::images/view-alert-details/-detections-threat-intelligence-overview.png[Overview of threat intelligence on the alert, 70%]
195
195
196
196
The Threat intelligence overview provides the following information:
197
197
@@ -210,7 +210,7 @@ The expanded threat intelligence view queries indices specified in the `security
210
210
====
211
211
212
212
[role="screenshot"]
213
-
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert]
213
+
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 70%]
214
214
215
215
The expanded Threat intelligence view shows individual indicators within the alert document. You can expand and collapse indicator details by clicking the arrow button at the end of the indicator label. Each indicator is labeled with values from the `matched.field` and `matched.atomic` fields and displays the threat intelligence provider.
216
216
@@ -249,7 +249,7 @@ When searching for threat intelligence, {elastic-sec} queries the alert document
249
249
The Correlations overview shows how an alert is related to other alerts and offers ways to investigate related alerts. Use this information to quickly find patterns between alerts and then take action.
250
250
251
251
[role="screenshot"]
252
-
image::images/view-alert-details/-detections-correlations-overview.png[Overview of available correlation data]
252
+
image::images/view-alert-details/-detections-correlations-overview.png[Overview of available correlation data, 60%]
253
253
254
254
The Correlations overview provides the following information:
255
255
@@ -266,7 +266,7 @@ The Correlations overview provides the following information:
266
266
From the right panel, click **Correlations** to open the expanded Correlations view within the left panel.
267
267
268
268
[role="screenshot"]
269
-
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data]
269
+
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data, 65%]
270
270
271
271
In the expanded view, corelation data is organized into several tables:
272
272
@@ -312,7 +312,7 @@ The expanded Prevalence view provides the following details:
312
312
The **Response** section is located on the **Overview** tab in the right panel. It shows <<security-rules-create,response actions>> that were added to the rule associated with the alert. Click **Response** to display the response action's results in the left panel.
313
313
314
314
[role="screenshot"]
315
-
image::images/view-alert-details/-detections-response-action-rp.png[Response section of the Overview tab]
315
+
image::images/view-alert-details/-detections-response-action-rp.png[Response section of the Overview tab, 50%]
316
316
317
317
[discrete]
318
318
[[expanded-notes-view]]
@@ -325,4 +325,4 @@ The **Notes** tab (located in the left panel) shows all notes attached to the al
325
325
Go to the **Notes** <<manage-notes,page>> to find notes that were added to other alerts.
326
326
====
327
327
328
-
image::images/view-alert-details/-detections-notes-tab-lp.png[Notes tab in the left panel]
328
+
image::images/view-alert-details/-detections-notes-tab-lp.png[Notes tab in the left panel, 70%]
Copy file name to clipboardExpand all lines: docs/serverless/investigate/timelines-ui.asciidoc
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -66,7 +66,7 @@ Many types of events automatically appear in preconfigured views that provide re
66
66
contextual information, called **Event Renderers**. All event renderers are turned off by default. To turn them on, use the **Event renderers** toggle at the top of the results pane. To only turn on specific event renderers, click the gear (image:images/icons/gear.svg[The customize event renderer button]) icon next to the toggle, and select the ones you want enabled. Close the **Customize event renderers** pane when you're done. Your changes are automatically applied to Timeline.
67
67
68
68
[role="screenshot"]
69
-
image::images/timelines-ui/-events-timeline-ui-renderer.png[example timeline with the event renderer highlighted]
69
+
image::images/timelines-ui/-events-timeline-ui-renderer.png[example timeline with the event renderer highlighted, 70%]
70
70
71
71
The example above displays the Flow event renderer, which highlights the movement of
72
72
data between its source and destination. If you see a particular part of the rendered event that
@@ -112,34 +112,34 @@ Collapse the query builder and provide more space for Timeline results by clicki
112
112
Click a filter to access additional operations such as **Add filter**, **Clear all**, **Load saved query**, and more:
Copy file name to clipboardExpand all lines: docs/serverless/osquery/invest-guide-run-osquery.asciidoc
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,7 +47,7 @@ Overwriting the query's default timeout period allows you to support queries tha
47
47
====
48
48
+
49
49
[role="screenshot"]
50
-
image:images/invest-guide-run-osquery/-osquery-setup-osquery-investigation-guide.png[Shows results from running a query from an investigation guide]
50
+
image:images/invest-guide-run-osquery/-osquery-setup-osquery-investigation-guide.png[width=70%][height=70%][Shows results from running a query from an investigation guide]
51
51
. Click **Save changes** to add the query to the rule's investigation guide.
52
52
53
53
[discrete]
@@ -74,4 +74,4 @@ Refer to <<security-examine-osquery-results,Examine Osquery results>> for more i
74
74
. Click **Save for later** to save the query for future use (optional).
75
75
+
76
76
[role="screenshot"]
77
-
image:images/invest-guide-run-osquery/-osquery-run-query-investigation-guide.png[Shows results from running a query from an investigation guide]
77
+
image:images/invest-guide-run-osquery/-osquery-run-query-investigation-guide.png[width=80%][height=80%][Shows results from running a query from an investigation guide]
0 commit comments