-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Request][Serverless][8.16] Visualizations in alert flyout - technical preview + advanced setting #5963
base: main
Are you sure you want to change the base?
[Request][Serverless][8.16] Visualizations in alert flyout - technical preview + advanced setting #5963
Changes from all commits
42ea290
5c92779
775dfae
1c6f95f
df4673a
67cdc39
19445db
3808331
21530ab
7bd378d
0ccbe1d
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
|
@@ -124,10 +124,32 @@ image::images/visualizations-section-rp.png[Visualizations section of the Overvi | |||||
|
||||||
Click **Visualizations** to display the following previews: | ||||||
|
||||||
* **Session view preview**: Shows a preview of <<session-view,session view>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline. | ||||||
* **Session view preview**: Shows a preview of <<session-view,Session View>> data. Click **Session viewer preview** to open the **Session View** tab in Timeline. | ||||||
|
||||||
* **Analyzer preview**: Shows a preview of the <<visual-event-analyzer,visual analyzer graph>>. The preview displays up to three levels of the analyzed event's ancestors and up to three levels of the event's descendants and children. The ellipses symbol (**`...`**) indicates the event has more ancestors and descendants to examine. Click **Analyzer preview** to open the **Event Analyzer** tab in Timeline. | ||||||
|
||||||
[discrete] | ||||||
[[expanded-visualizations-view]] | ||||||
=== Expanded visualizations view | ||||||
|
||||||
preview:[] | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This ⬆️ renders as the inline
Suggested change
|
||||||
|
||||||
.Requirements | ||||||
[sidebar] | ||||||
-- | ||||||
To use the **Visualize** tab, you must turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>>. | ||||||
-- | ||||||
|
||||||
The **Visualize** tab allows you to maintain the context of the Alerts table, while providing a more detailed view of alerts that you're investigating in the event analyzer or Session View. To open the tab, click **Session view preview** or **Analyzer preview** from the right panel. | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Same question about Session view/viewer preview |
||||||
|
||||||
[role="screenshot"] | ||||||
image::images/visualize-tab-lp.png[Expanded view of visualization details, 80%] | ||||||
|
||||||
As you examine the alert's related processes, you can also preview the alerts and events which are associated with those processes. Then, if you want to learn more about a particular alert or event, you can click **Show full alert details** to open the full details flyout. | ||||||
|
||||||
[role="screenshot"] | ||||||
image::images/visualize-tab-lp-alert-details.gif[Examine alert details from event analyzer, 80%] | ||||||
|
||||||
[discrete] | ||||||
[[insights-section]] | ||||||
== Insights | ||||||
|
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
|
@@ -29,7 +29,9 @@ Or | |||||
+ | ||||||
** `agent.type:"winlogbeat" and event.module: "sysmon" and process.entity_id : *` | ||||||
|
||||||
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. Alternatively, open the alert details flyout, go to the Visualizations section, then click **Analyzer preview**. This opens the **Analyzer** tab in Timeline. | ||||||
. Events that can be visually analyzed are denoted by a cubical **Analyze event** icon. Select this option to open the event in the visual analyzer. The event analyzer is accessible from the Hosts, Alerts, and Timelines pages, as well as the alert details flyout. | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
+ | ||||||
TIP: Turn on the `securitySolution:enableVisualizationsInFlyout` <<visualizations-in-flyout,advanced setting>> to access the event analyzer from the **Visualize** tab in the alert or event details flyout. | ||||||
|
||||||
+ | ||||||
[role="screenshot"] | ||||||
|
Original file line number | Diff line number | Diff line change | ||||
---|---|---|---|---|---|---|
|
@@ -113,6 +113,14 @@ The `securitySolution:enableAssetCriticality` setting determines whether asset c | |||||
|
||||||
Including data from cold and frozen {ref}/data-tiers.html[data tiers] in <<visual-event-analyzer, visual event analyzer>> queries may result in performance degradation. The `securitySolution:excludeColdAndFrozenTiersInAnalyzer` setting allows you to exclude this data from analyzer queries. This setting is turned off by default. | ||||||
|
||||||
[discrete] | ||||||
[[visualizations-in-flyout]] | ||||||
== Access the event analyzer and session view from the event or alert details flyout | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
|
||||||
preview:[] | ||||||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Suggested change
|
||||||
|
||||||
The `securitySolution:enableVisualizationsInFlyout` setting allows you to access the event analyzer and Session View in the **Visualize** tab on the alert or event details flyout. This setting is turned off by default. | ||||||
|
||||||
[discrete] | ||||||
== Change the default search interval and data refresh time | ||||||
|
||||||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should this say Session viewer preview?