-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Docs]7.7 SIEM doc updates #63951
[Docs]7.7 SIEM doc updates #63951
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -50,6 +50,22 @@ or the Detections API. | |
[role="screenshot"] | ||
image::siem/images/detections-ui.png[] | ||
|
||
[float] | ||
[[cases-ui]] | ||
=== Cases (Beta) | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. suggest removing Beta from the title and using this in the first line: beta:[] Cases are used to open... That way, you will get a definition of what it means for a feature to be in beta. If you do that, you'll also have to make the change for Detections earlier in the page. If you keep beta in the title, we use beta (lower case b) |
||
|
||
Cases are used to open and track security issues directly in the {siem-app}. | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We try to avoid using the word app in the Kibana docs and use the name alone, in this case, SIEM. |
||
They list the original reporter and all users who contribute to a case | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. They > Cases ? |
||
(`participants`). Case comments support markdown syntax, and allow linking to | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. markdown > Markdown |
||
saved Timelines. Additionally, you can send cases to external systems from | ||
within the {siem-app} (currently ServiceNow). | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. should also replace {siem-app} here with SIEM. |
||
|
||
For information about opening, updating, and closing cases, see | ||
{siem-guide}/cases-overview.html[Cases] in the SIEM Guide. | ||
|
||
[role="screenshot"] | ||
image::siem/images/cases-ui.png[] | ||
|
||
[float] | ||
[[timelines-ui]] | ||
=== Timeline | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
IP address's reputation > the reputation of an IP address?