Skip to content

[DOCS] Host and user risk score alert enrichments #2480

@nkhristinin

Description

@nkhristinin

Related: #2477
PR (has video demo): elastic/kibana#139478

Description

As part of the host/user risk score, all alerts which have a match by host.name or user.name will be enriched with risk.* fields while creating.

For platinum users:

  • Alert table will have 2 more fields host.risk.calculated_level and user.risk.calculated_level by default. User can add host.risk.calculated_score_norm and user.risk.calculated_score_norm to the table

For alert flyout:
For user and host risk score enrichments:

  • Real-time enrichment will be shown as Current host risk classification or Current user risk classification
  • If real-time enrichment is different from the enrichment at ingest time we also show a row with Original host risk classification

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions