|
1 | 1 | [[add-manage-notes]] |
2 | 2 | = Notes |
3 | 3 |
|
4 | | -Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timeline and manage them from the **Notes** page. |
| 4 | +Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page. |
5 | 5 |
|
6 | 6 | NOTE: Configure the `securitySolution:maxUnassociatedNotes` <<max-notes-alerts-events,advanced setting>> to specify the maximum number of notes that you can attach to alerts and events. |
7 | 7 |
|
8 | 8 | [discrete] |
9 | | -[[add-notes-documents]] |
10 | | -== Add notes to alerts and events |
| 9 | +[[notes-alerts-events]] |
| 10 | +== View and notes to alerts and events |
11 | 11 |
|
12 | | -Open the alert or event details flyout to access the **Notes** tab, where you can add notes to alerts and events. To quickly open the tab, use the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it. |
| 12 | +Open the alert or event details flyout to access the **Notes** tab, where you can view existing notes and add new ones. To quickly open the tab, click the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it. |
13 | 13 |
|
14 | | -[role="screenshot"] |
15 | | -image::images/create-new-note.png[Creating a new note] |
16 | | - |
17 | | -In the alert details flyout, the new note displays on the **Notes** tab. The alert's summary also updates and shows how many notes are attached to the alert. In the event details flyout, the new note displays on the **Notes** tab only. |
18 | | - |
19 | | -[role="screenshot"] |
20 | | -image::images/new-note-added-flyout.png[New note added to an alert] |
21 | | - |
22 | | -[discrete] |
23 | | -[[find-documents-with-notes]] |
24 | | -=== Find alerts and events with notes |
25 | | - |
26 | | -To find alerts and events with notes, use the <<manage-notes,**Notes** page>>. Alternatively, go to the Alerts or Events tables, and look for alerts and events with a notification dot over the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]). Click the action to open the **Notes** tab, which displays all notes that are attached to the alert or event. |
| 14 | +After notes are created, the **Add note** icon displays a notification dot. In the details flyout for alerts, the summary in the right panel also shows how many notes are attached to the alert. |
27 | 15 |
|
28 | 16 | [role="screenshot"] |
29 | | -image::images/notes-notification.png[Notes notification dot on Alerts page] |
| 17 | +image::images/new-note-alert-event.png[New note added to an alert] |
30 | 18 |
|
31 | 19 | [discrete] |
32 | | -[[add-notes-timelines]] |
33 | | -== Add notes to Timelines |
| 20 | +[[notes-timelines]] |
| 21 | +== View and add notes to Timelines |
34 | 22 |
|
35 | 23 | IMPORTANT: You can only add notes to saved Timelines. |
36 | 24 |
|
37 | | -There are two ways to add notes to a saved Timeline: |
| 25 | +Open the **Notes** Timeline tab, where you can view existing notes for the Timeline and add new ones. Alternatively, use the details flyout for alerts and events that you're investigating from Timeline. Notes added this way are automatically attached to the alert or event and the Timeline unless you deselect the **Attach to current Timeline** option. |
38 | 26 |
|
39 | | -* Open the Timeline, go to the **Notes** tab, and create a new note. |
40 | | -* Open the details flyout for alerts and events that you're investigating from Timeline, and create a new note. Be aware that notes are automatically attached to the Timeline unless you deselect the **Attach to current Timeline** option. |
| 27 | +After notes are created, the **Notes** Timelines tab displays the total number of notes attached to the Timelines. |
41 | 28 |
|
42 | | -[discrete] |
43 | | -[[find-timelines-with-notes]] |
44 | | -=== Find Timelines with notes |
45 | | - |
46 | | -To find Timelines with notes, use the <<manage-notes,**Notes** page>>. Alternatively, go to the **Timelines** page (find **Timelines** in the main navigation or look for “Timelines” using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field]), open the appropriate Timeline, and click the **Notes** tab. The tab displays all notes that are attached to the Timeline. |
| 29 | +[role="screenshot"] |
| 30 | +image::images/new-note-timeline-tab.png[New note added to a Timeline] |
47 | 31 |
|
48 | 32 | [discrete] |
49 | 33 | [[manage-notes]] |
|
0 commit comments