You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/events/add-manage-notes.asciidoc
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,22 +1,22 @@
1
1
[[add-manage-notes]]
2
2
= Notes
3
3
4
-
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
4
+
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts and events, and leave notes on saved Timelines. Then, use the **Notes** page to find and manage notes.
5
5
6
6
[discrete]
7
7
[[add-notes-documents]]
8
8
== Add notes to alerts and events
9
9
10
10
. Go to the Alerts or Events tables:
11
11
** **Alerts table:** Find **Alerts** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field].
12
-
** **Events table:** Find **Explore** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Hosts**, **Users**, **Network**. Scroll down to find the Events table.
12
+
** **Events table:** Find **Explore** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Hosts**, **Users**, **Network**. Scroll down and select the **Events** tab to view the Events table.
13
13
. Click the **Add note** icon (image:images/create-note-icon.png[Add note,15,15]). The **Notes** tab in the alert or events details flyout opens.
14
14
. Enter a note, then click **Add note**.
15
15
+
16
16
[role="screenshot"]
17
17
image::images/create-new-note.png[Creating a new note]
18
18
19
-
Alerts and events with notes have a notification marker on the **Add note** icon (image:images/create-note-icon.png[Add note,15,15]). Hover over the icon to view the total number of notes attached to the alert or event.
19
+
A notification marker displays on alerts and events with notes. Hover over the **Add note** icon (image:images/create-note-icon.png[Add note,15,15])to see how many notes are attached to the alert or event.
20
20
21
21
[role="screenshot"]
22
22
image::images/notes-notification.png[Notes notification marker on Alerts page]
@@ -25,7 +25,7 @@ image::images/notes-notification.png[Notes notification marker on Alerts page]
25
25
[[add-notes-timelines]]
26
26
== Add notes to Timelines
27
27
28
-
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
28
+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then return to the **Notes** tab and create the note.
29
29
30
30
NOTE: Notes that you add to alerts or events in Timeline are automatically attached to the Timeline. Deselect the **Attach to current Timeline** option to only add the note to the alert or event.
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to individual alerts and events, and leave notes on saved Timelines. You can then manage notes from the **Notes** page, or from individual alerts, events, or Timelines.
11
+
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts and events, and leave notes on saved Timelines. Then, use the **Notes** page to find and manage notes.
12
12
13
13
<divid="add-notes-documents"></div>
14
14
15
15
## Add notes to alerts and events
16
16
17
17
1. Go to the Alerts or Events tables:
18
-
***Alerts table:**Find**Alerts** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search).
19
-
***Events table:** Find **Explore** in the main menu or by using the [global search field](((kibana-ref))/introduction.html#kibana-navigation-search), then go to **Hosts**, **Users**, **Network**. Scroll downto find the Events table.
18
+
***Alerts table:**Click**Alerts** in the main menu.
19
+
***Events table:** Find **Explore** in the main menu, then go to **Hosts**, **Users**, **Network**. Scroll down, and select the **Events** tab to view the Events table.
20
20
1. Click the **Add note** icon (<DocIcontype="editorComment"title="The icon that lets you to add a new note" />). The **Notes** tab in the alert or events details flyout opens.
21
21
1. Enter a note, then click **Add note**.
22
22
23
23
<DocImagesize="xl"url="../images/notes/-notes-create-new-note.png"alt="Creating a new note"/>
24
24
25
-
Alerts and events with notes have a notification marker on the **Add note** icon (<DocIcontype="editorComment"title="The icon that lets you to add a new note" />). Hover over the icon to view the total number of notes attached to the alert or event.
25
+
A notification marker displays on alerts and events with notes. Hover over the **Add note** icon (<DocIcontype="editorComment"title="The icon that lets you to add a new note" />)to see how many notes are attached to the alert or event.
26
26
27
27
<DocImagesize="xl"url="../images/notes/-notes-notification.png"alt="Notes notification marker on Alerts page"/>
28
28
29
29
<divid="add-notes-timelines"></div>
30
30
31
31
## Add notes to Timelines
32
32
33
-
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
33
+
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then return to the **Notes** tab and create the note.
34
34
35
35
<DocCallOuttitle="Note">
36
36
Notes that you add to alerts or events in Timeline are automatically attached to the Timeline. Deselect the **Attach to current Timeline** option to only add the note to the alert or event.
0 commit comments