-
Notifications
You must be signed in to change notification settings - Fork 206
Closed
Labels
Feature: Entity AnalyticsFeatures or enhancements for any of the Entity pagesFeatures or enhancements for any of the Entity pagesTeam: Threat HuntingFormerly Data VisibilityFormerly Data Visibilityv8.5.0
Description
Related docs meta: #2477
PR: https://github.com/elastic/security-team/issues/4162
Dev: Kristof-Pierre C., Explore team
Affects Host, Network, and User details pages
- Removes the Unique IP KPI from the Host details page
On all detail pages:
- Place this component (
AlertCountByRuleByStatus) next toAlertByStatuscomponent - Click the
View Alertsbutton on theAlertByStatuscomponent will open up a timeline filtered by the current host and an additional field:event.type: signal
The left component (Alert By Status) will be titled Alerts by Severity. The new component on the right will be titled Alerts by rule.
Global filters should apply to both components.
NOTE: If a user does not have Alert permissions, the card won't display.
Metadata
Metadata
Assignees
Labels
Feature: Entity AnalyticsFeatures or enhancements for any of the Entity pagesFeatures or enhancements for any of the Entity pagesTeam: Threat HuntingFormerly Data VisibilityFormerly Data Visibilityv8.5.0
