Documents how to change the default security index#4695
Conversation
|
A documentation preview will be available soon.
Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
|
@benironside sorry, I did not really clarify well what docs we want to add. I updated the original ticket and added UPDATED section there:
Let me know if you have questions about it. |
e40pud
left a comment
There was a problem hiding this comment.
Thanks for putting this together!
nastasha-solomon
left a comment
There was a problem hiding this comment.
Looks great! Thanks, @benironside!
|
|
||
| To permanently modify a {data-source}, delete an existing {data-source} or create a new one, you need the required permissions. | ||
| To learn more, refer to {apm-app-ref}/data-views.html[{kib} {data-sources-cap}]. | ||
| NOTE: You cannot update the data view for the Alerts page. It always shows data from `.alerts-security.alerts-default`. |
There was a problem hiding this comment.
@e40pud can we tweak the UI copy so it aligns with this note? The current copy could be interpreted as: you must go elsewhere to update the data view for the Alerts page.
If it's still possible to change the copy, I'd suggest this:
You can't modify the data view for the Alerts page.
If that version is too blunt and overly formal, here's a slightly softer version:
This page's data view can't be adjusted.
There was a problem hiding this comment.
It is not bound to Alerts page only. Same happens on rule details page. Also, there is another similar message that we show on the timeline. So, general message looks better to me.
Screen.Recording.2024-01-31.at.16.47.22.mov
There was a problem hiding this comment.
Ah, interesting. Thanks for pointing out these other areas @e40pud -- I wasn't aware of them. Would it be ok if we continued this conversation in https://github.com/elastic/security-docs/issues/4718 so that we're not blocking this doc issue from being closed and merged?
Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com>
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8)
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4731) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4726) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
…4695) (#4721) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4730) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4729) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4722) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4728) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4727) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4725) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4724) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4723) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
Serverless follow up to #4695
* Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx
* Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx
…kport #5582) (#5586) * (Doc+) Alerts UI cannot be CCS [serverless] + bonus fixes (#5582) * Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx * Delete docs/serverless directory and its contents --------- Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…kport #5582) (#5585) * (Doc+) Alerts UI cannot be CCS [serverless] + bonus fixes (#5582) * Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx * Delete docs/serverless directory and its contents --------- Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
) (#4729) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4727) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
) (#4730) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> --------- Co-authored-by: Nastasha Solomon <79124755+nastasha-solomon@users.noreply.github.com> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <91905639+benironside@users.noreply.github.com>
First pass at fixing #4653.
@e40pud please let me know what you think, if we should add any more info and if this addresses the need. Thanks!