Skip to content

Conversation

@natasha-moore-elastic
Copy link
Contributor

@natasha-moore-elastic natasha-moore-elastic commented Oct 21, 2025

@github-actions
Copy link

github-actions bot commented Oct 21, 2025

@natasha-moore-elastic natasha-moore-elastic marked this pull request as ready for review October 21, 2025 13:27
@natasha-moore-elastic natasha-moore-elastic requested review from a team as code owners October 21, 2025 13:27
Copy link
Contributor

@nastasha-solomon nastasha-solomon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm!

Copy link
Contributor

@benironside benironside left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, just left a few minor suggestions for your consideration :)

Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
:::

This only allows you to add index patterns that match indices that currently contain data (other index patterns are unavailable). Note that any changes made are saved in the current browser window and won’t persist if you open a new tab.
{applies_to}`stack: removed 9.2` {applies_to}`serverless: removed` You can also temporarily modify the active {{data-source}} from the **{{data-source-cap}}** menu by clicking **Advanced options**, then adding or removing index patterns. This only allows you to add index patterns that match indices that currently contain data (other index patterns are unavailable). Note that any changes you make are saved in the browser and won’t persist if you open a new tab.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just confirming this is saying it was removed in 9.2?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's correct :)

## View and refine Timeline results [refine-timeline-results]

You can select whether Timeline displays detection alerts and other raw events, or just alerts. By default, Timeline displays both raw events and alerts. To hide raw events and display alerts only, click **Data view** to the left of the KQL query bar, then select **Show only detection alerts**.
You can select whether Timeline displays detection alerts and other raw events, or just alerts. By default, Timeline displays both raw events and alerts. To hide raw events and display alerts only:

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏾

@michaelolo24
Copy link

Thanks for updating all the screenshots!

@natasha-moore-elastic natasha-moore-elastic enabled auto-merge (squash) October 23, 2025 14:23
@natasha-moore-elastic natasha-moore-elastic merged commit 8d18a47 into main Oct 23, 2025
7 of 8 checks passed
@natasha-moore-elastic natasha-moore-elastic deleted the issue-410-dataview branch October 23, 2025 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants