Skip to content

Commit f82f93b

Browse files
Adds more images and content
1 parent dd26581 commit f82f93b

File tree

13 files changed

+52
-28
lines changed

13 files changed

+52
-28
lines changed

docs/detections/alerts-view-details.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -294,7 +294,7 @@ image::images/response-action-rp.png[Response section of the Overview tab, 50%]
294294
[[expanded-notes-view]]
295295
== Notes tab
296296

297-
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
297+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes or delete existing ones.
298298

299299
TIP: Go to the **Notes** <<manage-notes,page>> to find notes that were added to other alerts.
300300

File renamed without changes.

docs/events/add-manage-notes.asciidoc

Lines changed: 25 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -7,34 +7,48 @@ Incorporate notes into your investigative workflows to coordinate responses, con
77
[[add-notes-documents]]
88
== Add notes to alerts and events
99

10-
From the Alerts or Events tables, click the image:images/add-note-icon.png[Add note,15,15] icon to create a new note for an alert or event. Alternatively, use the **Notes** tab in the left panel of the event or alert details flyout, or click the **Add note** image:images/add-note.png[Add note,15,15] icon in the right panel (only available for alerts).
10+
. Go to the Alerts or Events tables:
11+
** **Alerts table:** Find **Alerts** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field].
12+
** **Events table:** Find **Explore** in the main menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Hosts**, **Users**, **Network**. Scroll down to find the Events table.
13+
. Click the **Add note** icon (image:images/create-note-icon.png[Add note,15,15]). The **Notes** tab in the alert or events details flyout opens.
14+
. Enter a note, then click **Add note**.
15+
+
16+
[role="screenshot"]
17+
image::images/create-new-note.png[Creating a new note]
18+
19+
Alerts and events with notes have a notification marker on the **Add note** icon (image:images/create-note-icon.png[Add note,15,15]). Hover over the icon to view the total number of notes attached to the alert or event.
1120

12-
NOTE: Notes that you add to alerts or events in Timeline are automatically attached to the current Timeline. Deselecting the **Attach to current Timeline** option ensures thats notes are added to the alert or event only.
21+
[role="screenshot"]
22+
image::images/notes-notification.png[Notes notification marker on Alerts page]
1323

1424
[discrete]
1525
[[add-notes-timelines]]
1626
== Add notes to Timelines
1727

1828
From Timeline, go to the **Notes** tab to create a new note for the entire Timeline. If you haven't saved the Timeline yet, save it, then go back to the **Notes** tab to create the note.
1929

30+
NOTE: Notes that you add to alerts or events in Timeline are automatically attached to the Timeline. Deselect the **Attach to current Timeline** option to only add the note to the alert or event.
31+
2032
[discrete]
2133
[[manage-notes]]
2234
== Find and manage notes
2335

2436
//Security solution view nav: Investigations -> Notes
2537
//Classic nav view: Manage -> Investigations -> Notes
2638

27-
The **Notes** page allows you to view and interact with all existing notes. From the table, you can:
39+
The **Notes** page allows you to view and interact with all existing notes. To access the page, find **Investigations** in the main menu or look for “Investigations” using the {kibana-ref}/introduction, then go to **Notes**.
2840

29-
* Search for specific notes or filter notes by:
30-
** The user who created them
31-
** The type of object that they're attached to (notes can be attached to alerts, events, Timelines, or nothing)
41+
[role="screenshot"]
42+
image::images/notes-management-page.png[Notes management page]
43+
44+
From the Notes table, you can:
45+
46+
* Search for specific notes or filter them by:
47+
** The user who created the notes
48+
** The type of object that notes are attached to (notes can be attached to alerts, events, Timelines, or nothing)
3249
* Examine the contents of a note by clicking on the text in the **Note content** column
3350
* Delete individual or multiple notes
34-
* Preview the alert or event that a note is attached to
51+
* Examine the alert or event that a note is attached to
3552
* Open the note in Timeline (this option is only available for alerts or events with notes attached to a saved Timeline)
3653

37-
[role="screenshot"]
38-
image::images/notes-management-page.png[Notes management page, 80%]
39-
40-
TIP: You can also manage notes for individual alerts, events, and Timelines from the **Notes** tab in the event or alert details flyout or Timeline.
54+
TIP: You can also manage notes for individual alerts, events, and Timelines from the **Notes** tab in the details flyout or Timeline.
2.6 KB
Loading
282 KB
Loading
848 Bytes
Loading
151 KB
Loading

docs/getting-started/advanced-setting.asciidoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -178,7 +178,7 @@ The `securitySolution:alertTags` field determines which options display in the a
178178

179179
[discrete]
180180
[[max-notes-alerts-events]]
181-
== Set the maximum notes limit for alerts or events
181+
== Set the maximum notes limit for alerts and events
182182

183183
The `securitySolution:maxUnassociatedNotes` field determines the maximum number of <<add-manage-notes,notes>> that you can attach to alerts and events. The maximum limit and default value is 1000.
184184

docs/serverless/alerts/view-alert-details.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -283,7 +283,7 @@ The **Response** section is located on the **Overview** tab in the right panel.
283283

284284
## Notes tab
285285

286-
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes to the alert or delete existing ones.
286+
The **Notes** tab (located in the left panel) shows all notes attached to the alert, in addition to the user who created them and when they were created. Use the tab to add new notes or delete existing ones.
287287

288288
<DocCallOut title="Tip">
289289
Go to the **Notes** <DocLink slug="/serverless/security/add-manage-notes" section="manage-notes">page</DocLink> to find notes that were added to other alerts.
282 KB
Loading

0 commit comments

Comments
 (0)