Skip to content

Commit fb64b56

Browse files
Merge branch 'main' into issue-5441-the-notes-expansion
2 parents 9419d92 + e673098 commit fb64b56

File tree

10 files changed

+66
-4
lines changed

10 files changed

+66
-4
lines changed

docs/detections/alerts-view-details.asciidoc

Lines changed: 23 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,10 +124,32 @@ image::images/visualizations-section-rp.png[Visualizations section of the Overvi
124124

125125
Click **Visualizations** to display the following previews:
126126

127-
* **Session view preview**: Shows a preview of <<session-view,session view>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
127+
* **Session viewer preview**: Shows a preview of <<session-view,Session View>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
128128

129129
* **Analyzer preview**: Shows a preview of the <<visual-event-analyzer,visual analyzer graph>>. The preview displays up to three levels of the analyzed event's ancestors and up to three levels of the event's descendants and children. The ellipses symbol (**`...`**) indicates the event has more ancestors and descendants to examine. Click **Analyzer preview** to open the **Event Analyzer** tab in Timeline.
130130

131+
[discrete]
132+
[[expanded-visualizations-view]]
133+
=== Expanded visualizations view
134+
135+
preview::[]
136+
137+
.Requirements
138+
[sidebar]
139+
--
140+
To use the **Visualize** tab, you must turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>>.
141+
--
142+
143+
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session viewer preview** or **Analyzer preview** from the right panel.
144+
145+
[role="screenshot"]
146+
image::images/visualize-tab-lp.png[Expanded view of visualization details, 80%]
147+
148+
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout.
149+
150+
[role="screenshot"]
151+
image::images/visualize-tab-lp-alert-details.gif[Examine alert details from event analyzer, 80%]
152+
131153
[discrete]
132154
[[insights-section]]
133155
== Insights
516 KB
Loading
285 KB
Loading

docs/detections/visual-event-analyzer.asciidoc

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,9 @@ Or
2929
+
3030
** `agent.type:"winlogbeat" and event.module: "sysmon" and process.entity_id : *`
3131

32-
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. Alternatively, open the alert details flyout, go to the Visualizations section, then click **Analyzer preview**. This opens the **Analyzer** tab in Timeline.
32+
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. The event analyzer is accessible from the **Hosts**, **Alerts**, and **Timelines** pages, as well as the alert details flyout.
33+
+
34+
TIP: Turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>> to access the event analyzer from the **Visualize** tab in the alert or event details flyout.
3335

3436
+
3537
[role="screenshot"]

docs/getting-started/advanced-setting.asciidoc

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,14 @@ The `securitySolution:enableAssetCriticality` setting determines whether asset c
113113

114114
Including data from cold and frozen {ref}/data-tiers.html[data tiers] in <<visual-event-analyzer, visual event analyzer>> queries may result in performance degradation. The `securitySolution:excludeColdAndFrozenTiersInAnalyzer` setting allows you to exclude this data from analyzer queries. This setting is turned off by default.
115115

116+
[discrete]
117+
[[visualizations-in-flyout]]
118+
== Access the event analyzer and Session View from the event or alert details flyout
119+
120+
preview::[]
121+
122+
The `securitySolution:enableVisualizationsInFlyout` setting allows you to access the event analyzer and Session View in the **Visualize** <<expanded-visualizations-view,tab>> on the alert or event details flyout. This setting is turned off by default.
123+
116124
[discrete]
117125
== Change the default search interval and data refresh time
118126

docs/serverless/alerts/view-alert-details.mdx

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,10 +124,28 @@ The Visualizations section is located on the **Overview** tab in the right panel
124124

125125
Click **Visualizations** to display the following previews:
126126

127-
* **Session view preview**: Shows a preview of <DocLink slug="/serverless/security/session-view">session view</DocLink> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
127+
* **Session view preview**: Shows a preview of <DocLink slug="/serverless/security/session-view">Session View</DocLink> data. Click **Session viewer preview** to open the **Session View** tab in Timeline.
128128

129129
* **Analyzer preview**: Shows a preview of the <DocLink slug="/serverless/security/visual-event-analyzer">visual analyzer graph</DocLink>. The preview displays up to three levels of the analyzed event's ancestors and up to three levels of the event's descendants and children. The ellipses symbol (**`...`**) indicates the event has more ancestors and descendants to examine. Click **Analyzer preview** to open the **Event Analyzer** tab in Timeline.
130130

131+
<div id="expanded-visualizations-view"></div>
132+
133+
### Expanded visualizations view
134+
135+
<DocCallOut template="technical_preview" />
136+
137+
<DocCallOut title="Requirements">
138+
To use the **Visualize** tab, you must turn on the `securitySolution:enableVisualizationsInFlyout` <DocLink slug="/serverless/security/advanced-settings" section="visualizations-in-flyout" >advanced setting</DocLink>.
139+
</DocCallOut>
140+
141+
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session view preview** or **Analyzer preview** from the right panel.
142+
143+
<DocImage size="xl" url="../images/view-alert-details/-detections-visualize-tab-lp.png" alt="Expanded view of visualization details"/>
144+
145+
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout.
146+
147+
![Examine alert details from event analyzer](../images/view-alert-details/-detections-visualize-tab-lp-alert-details.gif)
148+
131149
<div id="insights-section"></div>
132150

133151
## Insights

docs/serverless/alerts/visual-event-analyzer.mdx

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,11 @@ To find events that can be visually analyzed:
3939

4040
* `agent.type:"winlogbeat" and event.module: "sysmon" and process.entity_id : *`
4141

42-
1. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer.
42+
1. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. The event analyzer is accessible from the Hosts, Alerts, and Timelines pages, as well as the alert details flyout.
43+
44+
<DocCallOut title="Tip">
45+
Turn on the `securitySolution:enableVisualizationsInFlyout` <DocLink slug="/serverless/security/advanced-settings" section="visualizations-in-flyout">advanced setting</DocLink> to access the event analyzer from the **Visualize** tab in the alert or event details flyout.
46+
</DocCallOut>
4347

4448
<DocImage size="xl" url="../images/visual-event-analyzer/-detections-analyze-event-button.png" alt="Shows analyze event option" />
4549

516 KB
Loading
285 KB
Loading

docs/serverless/settings/advanced-settings.mdx

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -140,6 +140,14 @@ The `securitySolution:maxUnassociatedNotes` field determines the maximum number
140140

141141
Including data from cold and frozen [data tiers](((ref))/data-tiers.html) in <DocLink slug="/serverless/security/visual-event-analyzer">visual event analyzer</DocLink> queries may result in performance degradation. The `securitySolution:excludeColdAndFrozenTiersInAnalyzer` setting allows you to exclude this data from analyzer queries. This setting is turned off by default.
142142

143+
<div id="visualizations-in-flyout"></div>
144+
145+
## Access the event analyzer and session view from the event or alert details flyout
146+
147+
<DocCallOut template="technical_preview" />
148+
149+
The `securitySolution:enableVisualizationsInFlyout` setting allows you to access the event analyzer and Session View in the **Visualize** <DocLink slug="/serverless/security/view-alert-details" section="expanded-visualizations-view">tab</DocLink> on the alert or event details flyout. This setting is turned off by default.
150+
143151
## Change the default search interval and data refresh time
144152

145153
These settings determine the default time interval and refresh rate ((elastic-sec))

0 commit comments

Comments
 (0)