-
Couldn't load subscription status.
- Fork 205
[Serverless][8.16] Notes docs #6006
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 42 commits
Commits
Show all changes
46 commits
Select commit
Hold shift + click to select a range
03a8046
First draft
nastasha-solomon 0aa216c
First draft
nastasha-solomon 6fc6d18
Updates titles
nastasha-solomon 2d6d74a
Fixes toc and introduces images
nastasha-solomon 71fb03c
Fixes serverless toc
nastasha-solomon 593ea89
Adds missing image
nastasha-solomon dd26581
Typo
nastasha-solomon f82f93b
Adds more images and content
nastasha-solomon 89651a9
Removes kib ref
nastasha-solomon 351c2e8
Removed extra kib ref
nastasha-solomon e0ae798
Adjusted image name
nastasha-solomon 9382d5f
Completed ref link
nastasha-solomon 9387e8e
Adds ref to adv setting
nastasha-solomon e000d2d
Removed unnecessary ref
nastasha-solomon 68be868
Missing s
nastasha-solomon 3bcc01d
More minor adjustments
nastasha-solomon e0b5889
first draft of flyout changes
nastasha-solomon 8c71270
Fix image size
nastasha-solomon 8d0d4a1
Moves image over even more
nastasha-solomon 929f000
Update docs/events/add-manage-notes.asciidoc
nastasha-solomon ffdc178
Incorporates dev input - ESS
nastasha-solomon 85f195d
Serverless changes
nastasha-solomon 0b61863
removed extra space
nastasha-solomon 65ebc3f
fixes serverless doc bugs
nastasha-solomon 7491580
One more small fix
nastasha-solomon c93167f
Missing s
nastasha-solomon 9419d92
Adds missing image
nastasha-solomon fb64b56
Merge branch 'main' into issue-5441-the-notes-expansion
nastasha-solomon e6d9950
Update docs/events/add-manage-notes.asciidoc
nastasha-solomon b438eae
Revision round two
nastasha-solomon 7f46dd3
Added image ext
nastasha-solomon 3e69dc7
Adds nav instructions
nastasha-solomon 85c2d5e
Fixes styling
nastasha-solomon 2ae0fe5
Removed extra s
nastasha-solomon d6ddc83
Removed tab
nastasha-solomon d119a45
Merge branch 'main' into issue-5441-the-notes-expansion
nastasha-solomon 7a2f1aa
Removing asset criticality adv setting again
nastasha-solomon dd155b7
Removes comment for now
nastasha-solomon c2f73ea
Update docs/events/add-manage-notes.asciidoc
nastasha-solomon 15b3216
Update docs/events/add-manage-notes.asciidoc
nastasha-solomon b0a8782
Adds icon names to Serverless docs
nastasha-solomon 0609473
Merge branch 'main' into issue-5441-the-notes-expansion
nastasha-solomon 5b59c4d
Merge branch 'main' into issue-5441-the-notes-expansion
colleenmcginnis 3caa173
Merge branch 'main' into issue-5441-the-notes-expansion
colleenmcginnis d4d797e
update serverless asciidoc file instead of mdx file
colleenmcginnis a85e22c
trigger checks
colleenmcginnis File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| [[add-manage-notes]] | ||
| = Notes | ||
|
|
||
| Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page. | ||
|
|
||
| NOTE: Configure the `securitySolution:maxUnassociatedNotes` <<max-notes-alerts-events,advanced setting>> to specify the maximum number of notes that you can attach to alerts and events. | ||
|
|
||
| [discrete] | ||
| [[notes-alerts-events]] | ||
| == View and add notes to alerts and events | ||
|
|
||
| Open the alert or event details flyout to access the **Notes** tab, where you can view existing notes and add new ones. To quickly open the tab, click the **Add note** action (image:images/create-note-icon.png[Add note action,15,15]) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it. | ||
|
|
||
| After notes are created, the **Add note** icon displays a notification dot. In the details flyout for alerts, the alert summary in the right panel also shows how many notes are attached to the alert. | ||
|
|
||
| [role="screenshot"] | ||
nastasha-solomon marked this conversation as resolved.
Show resolved
Hide resolved
|
||
| image::images/new-note-alert-event.png[New note added to an alert] | ||
|
|
||
| [discrete] | ||
| [[notes-timelines]] | ||
| == View and add notes to Timelines | ||
|
|
||
| IMPORTANT: You can only add notes to saved Timelines. | ||
|
|
||
| Open the **Notes** Timeline tab, where you can view existing notes for the Timeline and add new ones. Alternatively, use the details flyout for alerts and events that you're investigating from Timeline. Be aware that notes added this way are automatically attached to the alert or event and the Timeline unless you deselect the **Attach to current Timeline** option. | ||
|
|
||
| After notes are created, the **Notes** Timeline tab displays the total number of notes attached to the Timeline. | ||
|
|
||
| [role="screenshot"] | ||
| image::images/new-note-timeline-tab.png[New note added to a Timeline] | ||
|
|
||
| [discrete] | ||
| [[manage-notes]] | ||
| == Manage all notes | ||
|
|
||
| Use the **Notes** page to view and interact with all existing notes. To access the page, navigate to *Investigations* in the main navigation menu or by using the {kibana-ref}/introduction.html#kibana-navigation-search[global search field], then go to **Notes**. From the **Notes** page, you can: | ||
|
|
||
| * Search for specific notes | ||
| * Filter notes by the user who created them or by the object they're attached to (notes can be attached to alerts, events, or Timelines) | ||
| * Examine the contents of a note (click the text in the **Note content** column) | ||
| * Delete one or more notes | ||
| * Examine the alert or event that a note is attached to (click the **Expand alert/event details** image:images/notes-page-document-details.png[Preview alert or event action,15,15] icon) | ||
| * Open the Timeline that the note is attached to (click the **Open saved timeline** image:images/notes-page-timeline-details.png[Open Timeline action,15,15] icon) | ||
|
|
||
| [role="screenshot"] | ||
| image::images/notes-management-page.png[Notes management page] | ||
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added
BIN
+137 KB
docs/serverless/images/view-alert-details/-detections-notes-tab-lp.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,54 @@ | ||
| --- | ||
| slug: /serverless/security/add-manage-notes | ||
| title: Notes | ||
| description: Create and manage notes for alerts, events, and Timeline. | ||
| tags: ["serverless","security","how-to","manage"] | ||
| --- | ||
|
|
||
| <DocBadge template="technical preview" /> | ||
| <div id="add-manage-notes"></div> | ||
|
|
||
| Incorporate notes into your investigative workflows to coordinate responses, conduct threat hunting, and share investigative findings. You can attach notes to alerts, events, and Timelines and manage them from the **Notes** page. | ||
|
|
||
| <DocCallOut title="Note"> | ||
| Configure the `securitySolution:maxUnassociatedNotes` <DocLink slug="/serverless/security/advanced-settings" section="max-notes-alerts-events">advanced settings</DocLink> to specify the maximum number of notes that you can attach to alerts and events. | ||
| </DocCallOut> | ||
|
|
||
| <div id="notes-alerts-events"></div> | ||
|
|
||
| ## View and add notes to alerts and events | ||
|
|
||
| Open the alert or event details flyout to access the **Notes** tab, where you can view existing notes and add new ones. To quickly open the tab, click the **Add note** action (<DocIcon type="editorComment" title="The action that lets you to add a new note" />) in the Alerts or Events table. Then, enter a note into the text box, and click **Add note** to create it. | ||
|
|
||
| After notes are created, the **Add note** icon displays a notification dot. In the details flyout for alerts, the alert summary in the right panel also shows how many notes are attached to the alert. | ||
|
|
||
| <DocImage size="xl" url="../images/notes/-notes-new-note-alert-event.png" alt="New note added to an alert"/> | ||
|
|
||
| <div id="notes-timelines"></div> | ||
|
|
||
| ## View and add notes to Timelines | ||
|
|
||
| <DocCallOut title="Important" color="warning"> | ||
| You can only add notes to saved Timelines. | ||
| </DocCallOut> | ||
|
|
||
| Open the **Notes** Timeline tab, where you can view existing notes for the Timeline and add new ones. Alternatively, use the details flyout for alerts and events that you're investigating from Timeline. Be aware that notes added this way are automatically attached to the alert or event and the Timeline unless you deselect the **Attach to current Timeline** option. | ||
|
|
||
| After notes are created, the **Notes** Timeline tab displays the total number of notes attached to the Timeline. | ||
|
|
||
| <DocImage size="xl" url="../images/notes/-notes-new-note-timeline-tab.png" alt="New note added to a Timeline"/> | ||
|
|
||
| <div id="manage-notes"></div> | ||
|
|
||
| ## Manage notes | ||
|
|
||
| Use the **Notes** page to view and interact with all existing notes. To access the page, navigate to **Investigations** in the main navigation menu or by using the global search field, then go to **Notes**. From the **Notes** page, you can: | ||
|
|
||
| * Search for specific notes | ||
| * Filter notes by the user who created them or by the object they're attached to (notes can be attached to alerts, events, or Timelines) | ||
| * Examine the contents of a note (select the text in the **Note content** column) | ||
| * Delete one or more notes | ||
| * Examine the alert or event that a note is attached to (click the **Expand alert/event details** <DocIcon type="expand" title="Preview alert or event details action" /> icon) | ||
| * Open the Timeline that the note is attached to (click the **Open saved timeline** <DocIcon type="timelineWithArrow" title="Preview alert or event details action" /> icon) | ||
|
|
||
| <DocImage size="xl" url="../images/notes/-notes-management-page.png" alt="Notes management page"/> |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.