Skip to content

[Enhancement]: Add docs for data view on Alerts page #4653

Description

@e40pud

Description

We need to extend documentation about data view selection on Alerts page. Looks like we would need to add a new section here.

A user asks whether it is possible to update "Security Data View" which is used on "Alerts" page to add remote alerts’ indices. Right now, we show only .alerts-security.alerts-default and customer wants to have .alerts-security.alerts-default, remote-cluster:.alerts-security.alerts-default index patterns, to see alerts from remote clusters as well.

UPDATED:
It is not possible to change data view for the Alerts page and the data view for the page bound to .alerts-security.alerts-default index pattern.
Would be nice to add a docs note about that.

298594598-cd4af9e1-4d9a-4ebe-99af-bee4f81507e9-2

Related links / assets

No response

Which documentation set needs improvement?

ESS and serverless

Software version

This functionality was introduced in 8.0, so ideally we would add these new docs 8.0+ or any possible version starting from 8.0.

Collaborators

PM:
Designer:
Developer:
Others (if applicable):

Timeline / deliverables

If we can add these docs in 8.13 that would be awesome.

Metadata

Metadata

Assignees

Type

No type

Fields

No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions