Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions docs/detections/alerts-visualizations.asciidoc
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
Visualize and group detection alerts by specific parameters in the visualization section of the Alerts page.

[role="screenshot"]
image::images/alert-page-visualizations.png[Alerts page with visualizations section highlighted]
image::images/alert-page.png[Alerts page with visualizations section]

Use the left buttons to select a view type (*Summary*, *Trend*, *Counts*, or *Treemap*), and use the right menus to select the ECS fields to use for grouping:

Expand Down Expand Up @@ -33,7 +33,7 @@ On the Alerts page, the summary visualization displays by default and shows how
* *Alerts by name*: How many alerts each detection rule created.
* *Top alerts by*: Percentage of alerts with a specified field value: `host.name` (default), `user.name`, `source.ip`, or `destination.ip`.

You can hover and click on elements within the summarysuch as severity levels, rule names, and host namesto add filters with those values to the Alerts page.
You can interact with elements within the summarysuch as severity levels, rule names, and host namesto add filters with those values to the Alerts page.

[role="screenshot"]
image::images/alerts-viz-summary.png[Summary visualization for alerts]
Expand Down
Binary file not shown.
Binary file modified docs/detections/images/alert-page.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/detections/images/alerts-viz-summary.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.