-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Feature: AlertsFeature: Host Risk ScoreFeature: User Risk ScoreTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Security PlatformIncludes Cyber Threat Intelligence (CTI) teamIncludes Cyber Threat Intelligence (CTI) teamv8.5.0
Description
Related: #2477
PR (has video demo): elastic/kibana#139478
Description
As part of the host/user risk score, all alerts which have a match by host.name or user.name will be enriched with risk.* fields while creating.
For platinum users:
- Alert table will have 2 more fields
host.risk.calculated_levelanduser.risk.calculated_levelby default. User can addhost.risk.calculated_score_normanduser.risk.calculated_score_normto the table
For alert flyout:
For user and host risk score enrichments:
- Real-time enrichment will be shown as
Current host risk classificationorCurrent user risk classification - If real-time enrichment is different from the enrichment at ingest time we also show a row with
Original host risk classification
Metadata
Metadata
Assignees
Labels
Feature: AlertsFeature: Host Risk ScoreFeature: User Risk ScoreTeam: Detections/ResponseDetections and ResponseDetections and ResponseTeam: Security PlatformIncludes Cyber Threat Intelligence (CTI) teamIncludes Cyber Threat Intelligence (CTI) teamv8.5.0