You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/detections/alerts-view-details.asciidoc
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -67,13 +67,13 @@ The left panel provides an expanded view of what's shown in the right panel. To
67
67
+
68
68
69
69
[role="screenshot"]
70
-
image::images/expand-details-button.png[Expand details button at the top of the alert details flyout, 45%]
70
+
image::images/expand-details-button.png[Expand details button at the top of the alert details flyout, 65%]
71
71
72
72
* Click one of the section titles on the **Overview** tab within the right panel.
73
73
+
74
74
75
75
[role="screenshot"]
76
-
image::images/alert-details-flyout-left-panel.png[Left panel of the alert details flyout, 45%]
76
+
image::images/alert-details-flyout-left-panel.png[Left panel of the alert details flyout, 65%]
77
77
78
78
[discrete]
79
79
[[about-section]]
@@ -201,7 +201,7 @@ From the right panel, click **Threat intelligence** to open the expanded Threat
201
201
NOTE: The expanded threat intelligence view queries indices specified in the `securitySolution:defaultThreatIndex` advanced setting. Refer to <<update-threat-intel-indices, Update default Elastic Security threat intelligence indices>> to learn more about threat intelligence indices.
202
202
203
203
[role="screenshot"]
204
-
image::images/expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 70%]
204
+
image::images/expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 80%]
205
205
206
206
The expanded Threat intelligence view shows individual indicators within the alert document. You can expand and collapse indicator details by clicking the arrow button at the end of the indicator label. Each indicator is labeled with values from the `matched.field` and `matched.atomic` fields and displays the threat intelligence provider.
207
207
@@ -256,7 +256,7 @@ NOTE: To access data about alerts related by process ancestry, you must have a h
256
256
From the right panel, click **Correlations** to open the expanded Correlations view within the left panel.
257
257
258
258
[role="screenshot"]
259
-
image::images/expanded-correlations-view.png[Expanded view of correlation data, 65%]
259
+
image::images/expanded-correlations-view.png[Expanded view of correlation data, 75%]
260
260
261
261
In the expanded view, corelation data is organized into several tables:
Copy file name to clipboardExpand all lines: docs/serverless/alerts/view-alert-details.asciidoc
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -75,11 +75,11 @@ The left panel provides an expanded view of what's shown in the right panel. To
75
75
* Click **Expand details** at the top of the right panel.
76
76
+
77
77
[role="screenshot"]
78
-
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout, 45%]
78
+
image:images/view-alert-details/-detections-expand-details-button.png[Expand details button at the top of the alert details flyout, 65%]
79
79
* Click one of the section titles on the **Overview** tab within the right panel.
80
80
+
81
81
[role="screenshot"]
82
-
image:images/view-alert-details/-detections-alert-details-flyout-left-panel.png[Left panel of the alert details flyout]
82
+
image:images/view-alert-details/-detections-alert-details-flyout-left-panel.png[Left panel of the alert details flyout, 65%]
83
83
84
84
[discrete]
85
85
[[about-section]]
@@ -210,7 +210,7 @@ The expanded threat intelligence view queries indices specified in the `security
210
210
====
211
211
212
212
[role="screenshot"]
213
-
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 70%]
213
+
image::images/view-alert-details/-detections-expanded-threat-intelligence-view.png[Expanded view of threat intelligence on the alert, 80%]
214
214
215
215
The expanded Threat intelligence view shows individual indicators within the alert document. You can expand and collapse indicator details by clicking the arrow button at the end of the indicator label. Each indicator is labeled with values from the `matched.field` and `matched.atomic` fields and displays the threat intelligence provider.
216
216
@@ -266,7 +266,7 @@ The Correlations overview provides the following information:
266
266
From the right panel, click **Correlations** to open the expanded Correlations view within the left panel.
267
267
268
268
[role="screenshot"]
269
-
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data, 65%]
269
+
image::images/view-alert-details/-detections-expanded-correlations-view.png[Expanded view of correlation data, 75%]
270
270
271
271
In the expanded view, corelation data is organized into several tables:
Copy file name to clipboardExpand all lines: docs/serverless/rules/interactive-investigation-guides.asciidoc
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ preview:[]
9
9
Detection rule investigation guides suggest steps for triaging, analyzing, and responding to potential security issues. For custom rules, you can create an interactive investigation guide that includes buttons for launching runtime queries in <<security-timelines-ui,Timeline>>, using alert data and hard-coded literal values. This allows you to start detailed Timeline investigations directly from an alert using relevant data.
10
10
11
11
[role="screenshot"]
12
-
image::images/interactive-investigation-guides/-detections-ig-alert-flyout.png[Alert details flyout with interactive investigation guide]
12
+
image::images/interactive-investigation-guides/-detections-ig-alert-flyout.png[Alert details flyout with interactive investigation guide,400]
13
13
14
14
Under the Investigation section, click **Show investigation guide** to open the **Investigation** tab in the left panel of the alert details flyout.
0 commit comments