Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] CTI enhancements to the alert details pane #773

Closed
nastasha-solomon opened this issue Jun 28, 2021 · 2 comments
Closed

[DOCS] CTI enhancements to the alert details pane #773

nastasha-solomon opened this issue Jun 28, 2021 · 2 comments
Assignees
Labels
Team: Docs Team: Security Platform Includes Cyber Threat Intelligence (CTI) team v7.14.0

Comments

@nastasha-solomon
Copy link
Contributor

nastasha-solomon commented Jun 28, 2021

The following enhancements to the Summary and Threat Intel tabs need to be documented in the Manage detection alerts topic.

  • The Summary tab used to have two separate sections: one displayed a compilation of alert details, and the other showed threat indicator data. In 7.14, those two sections have been combined into the alert summary section, which displays Indicator Match Enrichment (IME) data and Investigation Time Match (ITM) data. Refer to this comment for more details about IME and ITM data on this tab and the Threat Intel tab.
  • ITM data on the Summary tab is usually placed at the bottom of the alert summary section on the Summary tab and appended with text describing the indicator match source.
  • The Threat Intel tab now has descriptive headers that follow this structure: which field matched (matched.field), the value matched (matched.atomic), and the provider of the indicator. See the third screenshot at [Security Solution][CTI] Investigation time enrichment UI kibana#103383 for an example.
  • Users can click on the magnifying glass icon on the Threat Intel tab to inspect the query used to pull in ITM data. More information about the query and fields is here.
@nastasha-solomon nastasha-solomon added Team: Docs v7.14.0 Team: Security Platform Includes Cyber Threat Intelligence (CTI) team labels Jun 28, 2021
@nastasha-solomon nastasha-solomon self-assigned this Jun 28, 2021
@rylnd
Copy link
Contributor

rylnd commented Jul 6, 2021

@nastasha-solomon I added some documentation-focused comments on the linked issue.

@nastasha-solomon nastasha-solomon changed the title [DOCS] Enhancements to the alert details pane [DOCS] CTI enhancements to the alert details pane Jul 13, 2021
@nastasha-solomon
Copy link
Contributor Author

Merged #808.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: Docs Team: Security Platform Includes Cyber Threat Intelligence (CTI) team v7.14.0
Projects
None yet
Development

No branches or pull requests

2 participants