Skip to content

Commit 6ce0de5

Browse files
Adds size configs
1 parent 5078b7f commit 6ce0de5

File tree

6 files changed

+30
-30
lines changed

6 files changed

+30
-30
lines changed

docs/events/timeline-ui-overview.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ Many types of events automatically appear in preconfigured views that provide re
5858
contextual information, called *Event renderers*. All event renderers are turned off by default. To turn them on, use the **Event renderers** toggle at the top of the results pane. To only turn on specific event renderers, click the gear (image:images/customize-event-renderers.png[The customize event renderer button,20,20]) icon next to the toggle, and select the ones you want enabled. Close the **Customize event renderers** pane when you're done. Your changes are automatically applied to Timeline.
5959

6060
[role="screenshot"]
61-
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted]
61+
image::images/timeline-ui-renderer.png[example timeline with the event renderer highlighted, 70%]
6262

6363
The example above displays the Flow event renderer, which highlights the movement of
6464
data between its source and destination. If you see a particular part of the rendered event that

docs/serverless/alerts/view-alert-details.asciidoc

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ preview:[]
1313
To learn more about an alert, click the **View details** button from the Alerts table. This opens the alert details flyout, which helps you understand and manage the alert.
1414

1515
[role="screenshot"]
16-
image::images/view-alert-details/-detections-open-alert-details-flyout.gif[Expandable flyout]
16+
image::images/view-alert-details/-detections-open-alert-details-flyout.gif[Expandable flyout, 90%]
1717

1818
Use the alert details flyout to begin an investigation, open a case, or plan a response. Click **Take action** at the bottom of the flyout to find more options for interacting with the alert.
1919

@@ -30,12 +30,12 @@ The alert details flyout has a right panel, a preview panel, and a left panel. E
3030
The right panel provides an overview of the alert. Expand any of the collapsed sections to learn more about the alert. You can also hover over fields on the **Overview** and **Table** tabs to display available <<inline-actions,inline actions>>.
3131

3232
[role="screenshot"]
33-
image::images/view-alert-details/-detections-alert-details-flyout-right-panel.png[Right panel of the alert details flyout]
33+
image::images/view-alert-details/-detections-alert-details-flyout-right-panel.png[Right panel of the alert details flyout, 65%]
3434

3535
From the right panel, you can also:
3636

3737
* Click **Expand details** to open the <<left-panel,left panel>>, which shows more information about sections in the right panel.
38-
* Click the **Chat** icon (image:images/icons/discuss.svg[Chat]) to access the <<security-ai-assistant>>.
38+
* Click the **Chat** icon (image:images/view-alert-details/ai-assistant-chat.png[AI assistant chat icon,15,15]) to access the <<security-ai-assistant>>.
3939
* Click the **Share alert** icon (image:images/icons/share.svg[Share alert]) to get a shareable alert URL. We _do not_ recommend copying the URL from your browser's address bar, which can lead to inconsistent results if you've set up filters or relative time ranges for the Alerts page.
4040
+
4141
[NOTE]
@@ -64,7 +64,7 @@ If you've enabled grouping on the Alerts page, the alert details flyout won't op
6464
Some areas in the flyout provide previews when you click on them. For example, clicking **Show rule summary** in the rule description displays a preview of the rule's details. To close the preview, click **Back** or **x**.
6565

6666
[role="screenshot"]
67-
image::images/view-alert-details/-detections-alert-details-flyout-preview-panel.gif[Preview panel of the alert details flyout]
67+
image::images/view-alert-details/-detections-alert-details-flyout-preview-panel.gif[Preview panel of the alert details flyout, 65%]
6868

6969
[discrete]
7070
[[left-panel]]
@@ -75,7 +75,7 @@ The left panel provides an expanded view of what's shown in the right panel. To
7575
* Click **Expand details** at the top of the right panel.
7676
+
7777
[role="screenshot"]
78-
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout]
78+
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout, 45%]
7979
* Click one of the section titles on the **Overview** tab within the right panel.
8080
+
8181
[role="screenshot"]
@@ -88,7 +88,7 @@ image:images/view-alert-details/-detections-alert-details-flyout-left-panel.png[
8888
The About section is located on the **Overview** tab in the right panel. It provides a brief description of the rule that's related to the alert and an explanation of what generated the alert.
8989

9090
[role="screenshot"]
91-
image::images/view-alert-details/-detections-about-section-rp.png[About section of the Overview tab]
91+
image::images/view-alert-details/-detections-about-section-rp.png[About section of the Overview tab, 65%]
9292

9393
The About section has the following information:
9494

@@ -109,7 +109,7 @@ The event renderer only displays if an event renderer exists for the alert type.
109109
The Investigation section is located on the **Overview** tab in the right panel. It offers a couple of ways to begin investigating the alert.
110110

111111
[role="screenshot"]
112-
image::images/view-alert-details/-detections-investigation-section-rp.png[Investigation section of the Overview tab]
112+
image::images/view-alert-details/-detections-investigation-section-rp.png[Investigation section of the Overview tab, 65%]
113113

114114
The Investigation section provides the following information:
115115

@@ -128,7 +128,7 @@ Add an <<add-ig-actions-rule,investigation guide>> to a rule when creating a new
128128
The Visualizations section is located on the **Overview** tab in the right panel. It offers a glimpse of the processes that led up to the alert and occurred after it.
129129

130130
[role="screenshot"]
131-
image::images/view-alert-details/-detections-visualizations-section-rp.png[Visualizations section of the Overview tab]
131+
image::images/view-alert-details/-detections-visualizations-section-rp.png[Visualizations section of the Overview tab, 65%]
132132

133133
Click **Visualizations** to display the following previews:
134134

@@ -150,7 +150,7 @@ To use the **Visualize** tab, you must turn on the `securitySolution:enableVisua
150150
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session view preview** or **Analyzer preview** from the right panel.
151151

152152
[role="screenshot"]
153-
image::images/view-alert-details/-detections-visualize-tab-lp.png[Expanded view of visualization details]
153+
image::images/view-alert-details/-detections-visualize-tab-lp.png[Expanded view of visualization details, 80%]
154154

155155
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout.
156156

@@ -164,7 +164,7 @@ image::images/view-alert-details/-detections-visualize-tab-lp-alert-details.gif[
164164
The Insights section is located on the **Overview** tab in the right panel. It offers different perspectives from which you can assess the alert. Click **Insights** to display overviews for <<entities-overview,related entities>>, <<threat-intelligence-overview,threat intelligence>>, <<correlations-overview,correlated data>>, and <<prevalence-overview,host and user prevalence>>.
165165

166166
[role="screenshot"]
167-
image::images/view-alert-details/-detections-insights-section-rp.png[Insights section of the Overview tab]
167+
image::images/view-alert-details/-detections-insights-section-rp.png[Insights section of the Overview tab, 65%]
168168

169169
[discrete]
170170
[[entities-overview]]
@@ -173,7 +173,7 @@ image::images/view-alert-details/-detections-insights-section-rp.png[Insights se
173173
The Entities overview provides high-level details about the user and host that are related to the alert. Host and user risk classifications are also available if you have the Security Analytics Complete <<elasticsearch-manage-project,project feature>>.
174174

175175
[role="screenshot"]
176-
image::images/view-alert-details/-detections-entities-overview.png[Overview of the entity details section in the right panel]
176+
image::images/view-alert-details/-detections-entities-overview.png[Overview of the entity details section in the right panel, 60%]
177177

178178
[discrete]
179179
[[expanded-entities-view]]
@@ -182,7 +182,7 @@ image::images/view-alert-details/-detections-entities-overview.png[Overview of t
182182
From the right panel, click **Entities** to open a detailed view of the host and user associated with the alert. The expanded view also includes risk scores and classifications (if you have the Security Analytics Complete <<elasticsearch-manage-project,project feature>>) and activity on related hosts and users.
183183

184184
[role="screenshot"]
185-
image::images/view-alert-details/-detections-expanded-entities-view.png[Expanded view of entity details]
185+
image::images/view-alert-details/-detections-expanded-entities-view.png[Expanded view of entity details, 70%]
186186

187187
[discrete]
188188
[[threat-intelligence-overview]]
@@ -191,7 +191,7 @@ image::images/view-alert-details/-detections-expanded-entities-view.png[Expanded
191191
The Threat intelligence overview shows matched indicators, which provide threat intelligence relevant to the alert.
192192

193193
[role="screenshot"]
194-
image::images/view-alert-details/-detections-threat-intelligence-overview.png[Overview of threat intelligence on the alert]
194+
image::images/view-alert-details/-detections-threat-intelligence-overview.png[Overview of threat intelligence on the alert, 70%]
195195

196196
The Threat intelligence overview provides the following information:
197197

@@ -210,7 +210,7 @@ The expanded threat intelligence view queries indices specified in the `security
210210
====
211211

212212
[role="screenshot"]
213-
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert]
213+
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 70%]
214214

215215
The expanded Threat intelligence view shows individual indicators within the alert document. You can expand and collapse indicator details by clicking the arrow button at the end of the indicator label. Each indicator is labeled with values from the `matched.field` and `matched.atomic` fields and displays the threat intelligence provider.
216216

@@ -249,7 +249,7 @@ When searching for threat intelligence, {elastic-sec} queries the alert document
249249
The Correlations overview shows how an alert is related to other alerts and offers ways to investigate related alerts. Use this information to quickly find patterns between alerts and then take action.
250250

251251
[role="screenshot"]
252-
image::images/view-alert-details/-detections-correlations-overview.png[Overview of available correlation data]
252+
image::images/view-alert-details/-detections-correlations-overview.png[Overview of available correlation data, 60%]
253253

254254
The Correlations overview provides the following information:
255255

@@ -266,7 +266,7 @@ The Correlations overview provides the following information:
266266
From the right panel, click **Correlations** to open the expanded Correlations view within the left panel.
267267

268268
[role="screenshot"]
269-
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data]
269+
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data, 65%]
270270

271271
In the expanded view, corelation data is organized into several tables:
272272

@@ -312,7 +312,7 @@ The expanded Prevalence view provides the following details:
312312
The **Response** section is located on the **Overview** tab in the right panel. It shows <<security-rules-create,response actions>> that were added to the rule associated with the alert. Click **Response** to display the response action's results in the left panel.
313313

314314
[role="screenshot"]
315-
image::images/view-alert-details/-detections-response-action-rp.png[Response section of the Overview tab]
315+
image::images/view-alert-details/-detections-response-action-rp.png[Response section of the Overview tab, 50%]
316316

317317
[discrete]
318318
[[expanded-notes-view]]
@@ -325,4 +325,4 @@ The **Notes** tab (located in the left panel) shows all notes attached to the al
325325
Go to the **Notes** <<manage-notes,page>> to find notes that were added to other alerts.
326326
====
327327

328-
image::images/view-alert-details/-detections-notes-tab-lp.png[Notes tab in the left panel]
328+
image::images/view-alert-details/-detections-notes-tab-lp.png[Notes tab in the left panel, 70%]
1.03 KB
Loading

docs/serverless/investigate/timeline-templates-ui.asciidoc

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -55,17 +55,17 @@ Regular Timeline filter::
5555
Clicking **Convert to template field** changes the filter to a template filter:
5656
+
5757
[role="screenshot"]
58-
image::images/timeline-templates-ui/-events-template-filter-value.png[]
58+
image::images/timeline-templates-ui/-events-template-filter-value.png[width=30%]
5959

6060
Template filter::
6161
+
6262
[role="screenshot"]
63-
image:images/timeline-templates-ui/-events-timeline-template-filter.png[]
63+
image:images/timeline-templates-ui/-events-timeline-template-filter.png[width=30%]
6464
+
6565
When you <<man-templates-ui,convert a template to a Timeline>>, template filters with placeholders are disabled:
6666
+
6767
[role="screenshot"]
68-
image::images/timeline-templates-ui/-events-invalid-filter.png[]
68+
image::images/timeline-templates-ui/-events-invalid-filter.png[width=30%]
6969
+
7070
To enable the filter, either specify a value or change it to a field's existing filter (refer to <<pivot,Edit existing filters>>).
7171

docs/serverless/investigate/timelines-ui.asciidoc

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ Many types of events automatically appear in preconfigured views that provide re
6666
contextual information, called **Event Renderers**. All event renderers are turned off by default. To turn them on, use the **Event renderers** toggle at the top of the results pane. To only turn on specific event renderers, click the gear (image:images/icons/gear.svg[The customize event renderer button]) icon next to the toggle, and select the ones you want enabled. Close the **Customize event renderers** pane when you're done. Your changes are automatically applied to Timeline.
6767

6868
[role="screenshot"]
69-
image::images/timelines-ui/-events-timeline-ui-renderer.png[example timeline with the event renderer highlighted]
69+
image::images/timelines-ui/-events-timeline-ui-renderer.png[example timeline with the event renderer highlighted, 70%]
7070

7171
The example above displays the Flow event renderer, which highlights the movement of
7272
data between its source and destination. If you see a particular part of the rendered event that
@@ -112,34 +112,34 @@ Collapse the query builder and provide more space for Timeline results by clicki
112112
Click a filter to access additional operations such as **Add filter**, **Clear all**, **Load saved query**, and more:
113113

114114
[role="screenshot"]
115-
image::images/timelines-ui/-events-timeline-ui-filter-options.png[]
115+
image::images/timelines-ui/-events-timeline-ui-filter-options.png[width=30%]
116116

117117
Here are examples of various types of filters:
118118

119119
Field with value::
120120
Filters for events with the specified field value:
121121
+
122122
[role="screenshot"]
123-
image::images/timelines-ui/-events-timeline-filter-value.png[]
123+
image::images/timelines-ui/-events-timeline-filter-value.png[width=30%]
124124

125125
Field exists::
126126
Filters for events containing the specified field:
127127
+
128128
[role="screenshot"]
129-
image::images/timelines-ui/-events-timeline-field-exists.png[]
129+
image::images/timelines-ui/-events-timeline-field-exists.png[width=30%]
130130

131131
Exclude results::
132132
Filters for events that do not contain the specified field value
133133
(`field with value` filter) or the specified field (`field exists` filter):
134134
+
135135
[role="screenshot"]
136-
image::images/timelines-ui/-events-timeline-filter-exclude.png[]
136+
image::images/timelines-ui/-events-timeline-filter-exclude.png[width=30%]
137137

138138
Temporarily disable::
139139
The filter is not used in the query until it is enabled again:
140140
+
141141
[role="screenshot"]
142-
image::images/timelines-ui/-events-timeline-disable-filter.png[]
142+
image::images/timelines-ui/-events-timeline-disable-filter.png[width=30%]
143143

144144
Filter for field present::
145145
Converts a `field with value` filter to a `field exists` filter.

docs/serverless/osquery/invest-guide-run-osquery.asciidoc

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ Overwriting the query's default timeout period allows you to support queries tha
4747
====
4848
+
4949
[role="screenshot"]
50-
image:images/invest-guide-run-osquery/-osquery-setup-osquery-investigation-guide.png[Shows results from running a query from an investigation guide]
50+
image:images/invest-guide-run-osquery/-osquery-setup-osquery-investigation-guide.png[width=70%][height=70%][Shows results from running a query from an investigation guide]
5151
. Click **Save changes** to add the query to the rule's investigation guide.
5252

5353
[discrete]
@@ -74,4 +74,4 @@ Refer to <<security-examine-osquery-results,Examine Osquery results>> for more i
7474
. Click **Save for later** to save the query for future use (optional).
7575
+
7676
[role="screenshot"]
77-
image:images/invest-guide-run-osquery/-osquery-run-query-investigation-guide.png[Shows results from running a query from an investigation guide]
77+
image:images/invest-guide-run-osquery/-osquery-run-query-investigation-guide.png[width=80%][height=80%][Shows results from running a query from an investigation guide]

0 commit comments

Comments
 (0)