Skip to content

Commit b438eae

Browse files
Revision round two
1 parent e6d9950 commit b438eae

14 files changed

+29
-54
lines changed

docs/detections/alerts-ui-manage.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -150,7 +150,7 @@ From the Alerts table or the alert details flyout, you can:
150150
* <<alerts-run-osquery, Run Osquery against an alert>>
151151
* <<signals-to-timelines>>
152152
* <<visual-event-analyzer,Visually analyze an alert's process relationships>>
153-
* <<add-notes-documents,Add notes to alerts>>
153+
* <<notes-alerts-events,Add notes to alerts>>
154154

155155
[float]
156156
[[detection-alert-status]]

docs/events/add-manage-notes.asciidoc

Lines changed: 12 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -1,49 +1,33 @@
11
[[add-manage-notes]]
22
= Notes
33

4-
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timeline and manage them from the **Notes** page.
4+
Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page.
55

66
NOTE: Configure the `securitySolution:maxUnassociatedNotes` <<max-notes-alerts-events,advanced setting>> to specify the maximum number of notes that you can attach to alerts and events.
77

88
[discrete]
9-
[[add-notes-documents]]
10-
== Add notes to alerts and events
9+
[[notes-alerts-events]]
10+
== View and notes to alerts and events
1111

12-
Open the alert or event details flyout to access the **Notes** tab, where you can add notes to alerts and events. To quickly open the tab, use the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it.
12+
Open the alert or event details flyout to access the **Notes** tab, where you can view existing notes and add new ones. To quickly open the tab, click the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it.
1313

14-
[role="screenshot"]
15-
image::images/create-new-note.png[Creating a new note]
16-
17-
In the alert details flyout, the new note displays on the **Notes** tab. The alert's summary also updates and shows how many notes are attached to the alert. In the event details flyout, the new note displays on the **Notes** tab only.
18-
19-
[role="screenshot"]
20-
image::images/new-note-added-flyout.png[New note added to an alert]
21-
22-
[discrete]
23-
[[find-documents-with-notes]]
24-
=== Find alerts and events with notes
25-
26-
To find alerts and events with notes, use the <<manage-notes,**Notes** page>>. Alternatively, go to the Alerts or Events tables, and look for alerts and events with a notification dot over the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]). Click the action to open the **Notes** tab, which displays all notes that are attached to the alert or event.
14+
After notes are created, the **Add note** icon displays a notification dot. In the details flyout for alerts, the summary in the right panel also shows how many notes are attached to the alert.
2715

2816
[role="screenshot"]
29-
image::images/notes-notification.png[Notes notification dot on Alerts page]
17+
image::images/new-note-alert-event.png[New note added to an alert]
3018

3119
[discrete]
32-
[[add-notes-timelines]]
33-
== Add notes to Timelines
20+
[[notes-timelines]]
21+
== View and add notes to Timelines
3422

3523
IMPORTANT: You can only add notes to saved Timelines.
3624

37-
There are two ways to add notes to a saved Timeline:
25+
Open the **Notes** Timeline tab, where you can view existing notes for the Timeline and add new ones. Alternatively, use the details flyout for alerts and events that you're investigating from Timeline. Notes added this way are automatically attached to the alert or event and the Timeline unless you deselect the **Attach to current Timeline** option.
3826

39-
* Open the Timeline, go to the **Notes** tab, and create a new note.
40-
* Open the details flyout for alerts and events that you're investigating from Timeline, and create a new note. Be aware that notes are automatically attached to the Timeline unless you deselect the **Attach to current Timeline** option.
27+
After notes are created, the **Notes** Timelines tab displays the total number of notes attached to the Timelines.
4128

42-
[discrete]
43-
[[find-timelines-with-notes]]
44-
=== Find Timelines with notes
45-
46-
To find Timelines with notes, use the <<manage-notes,**Notes** page>>. Alternatively, go to the **Timelines** page (find **Timelines** in the main navigation or look for “Timelines” using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field]), open the appropriate Timeline, and click the **Notes** tab. The tab displays all notes that are attached to the Timeline.
29+
[role="screenshot"]
30+
image::images/new-note-timeline-tab.png[New note added to a Timeline]
4731

4832
[discrete]
4933
[[manage-notes]]
-284 KB
Binary file not shown.
-245 KB
Binary file not shown.
607 KB
Loading
210 KB
Loading
-151 KB
Binary file not shown.

docs/serverless/alerts/alerts-ui-manage.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,7 @@ From the Alerts table or the alert details flyout, you can:
148148
* <DocLink slug="/serverless/security/alerts-run-osquery">Run Osquery against an alert</DocLink>
149149
* <DocLink slug="/serverless/security/alerts-manage" section="view-alerts-in-timeline">View alerts in Timeline</DocLink>
150150
* <DocLink slug="/serverless/security/visual-event-analyzer">Visually analyze an alert's process relationships</DocLink>
151-
* <DocLink slug="/serverless/security/add-manage-notes" section="add-notes-document">Add notes to alerts</DocLink>
151+
* <DocLink slug="/serverless/security/add-manage-notes" section="notes-alerts-events">Add notes to alerts</DocLink>
152152

153153
<div id="detection-alert-status"></div>
154154

-284 KB
Binary file not shown.
-245 KB
Binary file not shown.

0 commit comments

Comments
 (0)