You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The following enhancements to the Summary and Threat Intel tabs need to be documented in the Manage detection alerts topic.
The Summary tab used to have two separate sections: one displayed a compilation of alert details, and the other showed threat indicator data. In 7.14, those two sections have been combined into the alert summary section, which displays Indicator Match Enrichment (IME) data and Investigation Time Match (ITM) data. Refer to this comment for more details about IME and ITM data on this tab and the Threat Intel tab.
ITM data on the Summary tab is usually placed at the bottom of the alert summary section on the Summary tab and appended with text describing the indicator match source.
The Threat Intel tab now has descriptive headers that follow this structure: which field matched (matched.field), the value matched (matched.atomic), and the provider of the indicator. See the third screenshot at [Security Solution][CTI] Investigation time enrichment UI kibana#103383 for an example.
Users can click on the magnifying glass icon on the Threat Intel tab to inspect the query used to pull in ITM data. More information about the query and fields is here.
The text was updated successfully, but these errors were encountered:
The following enhancements to the Summary and Threat Intel tabs need to be documented in the Manage detection alerts topic.
matched.field
), the value matched (matched.atomic
), and the provider of the indicator. See the third screenshot at [Security Solution][CTI] Investigation time enrichment UI kibana#103383 for an example.The text was updated successfully, but these errors were encountered: