Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Enhancement]: Add docs for data view on Alerts page #4653

Closed
e40pud opened this issue Jan 23, 2024 · 0 comments
Closed

[Enhancement]: Add docs for data view on Alerts page #4653

e40pud opened this issue Jan 23, 2024 · 0 comments
Assignees
Labels
enhancement New feature or request v8.12.0 v8.13.0

Comments

@e40pud
Copy link
Contributor

e40pud commented Jan 23, 2024

Description

We need to extend documentation about data view selection on Alerts page. Looks like we would need to add a new section here.

A user asks whether it is possible to update "Security Data View" which is used on "Alerts" page to add remote alerts’ indices. Right now, we show only .alerts-security.alerts-default and customer wants to have .alerts-security.alerts-default, remote-cluster:.alerts-security.alerts-default index patterns, to see alerts from remote clusters as well.

UPDATED:
It is not possible to change data view for the Alerts page and the data view for the page bound to .alerts-security.alerts-default index pattern.
Would be nice to add a docs note about that.

298594598-cd4af9e1-4d9a-4ebe-99af-bee4f81507e9-2

Related links / assets

No response

Which documentation set needs improvement?

ESS and serverless

Software version

This functionality was introduced in 8.0, so ideally we would add these new docs 8.0+ or any possible version starting from 8.0.

Collaborators

PM:
Designer:
Developer:
Others (if applicable):

Timeline / deliverables

If we can add these docs in 8.13 that would be awesome.

@e40pud e40pud added the enhancement New feature or request label Jan 23, 2024
@benironside benironside self-assigned this Jan 26, 2024
stefnestor added a commit to stefnestor/security-docs that referenced this issue Jul 5, 2024
👋 howdy, team! 

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) elastic#4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?
joepeeples added a commit that referenced this issue Jul 17, 2024
* (Doc+) Alerts UI cannot be CCS 

👋 howdy, team! 

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) #4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?

* feedback

Co-authored-by: Joe Peeples <[email protected]>

---------

Co-authored-by: Joe Peeples <[email protected]>
mergify bot pushed a commit that referenced this issue Jul 17, 2024
* (Doc+) Alerts UI cannot be CCS

👋 howdy, team!

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) #4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?

* feedback

Co-authored-by: Joe Peeples <[email protected]>

---------

Co-authored-by: Joe Peeples <[email protected]>
(cherry picked from commit 5c199b0)
mergify bot pushed a commit that referenced this issue Jul 17, 2024
* (Doc+) Alerts UI cannot be CCS

👋 howdy, team!

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) #4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?

* feedback

Co-authored-by: Joe Peeples <[email protected]>

---------

Co-authored-by: Joe Peeples <[email protected]>
(cherry picked from commit 5c199b0)
joepeeples pushed a commit that referenced this issue Jul 17, 2024
* (Doc+) Alerts UI cannot be CCS

👋 howdy, team!

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) #4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?

* feedback

Co-authored-by: Joe Peeples <[email protected]>

---------

Co-authored-by: Joe Peeples <[email protected]>
(cherry picked from commit 5c199b0)

Co-authored-by: Stef Nestor <[email protected]>
joepeeples pushed a commit that referenced this issue Jul 17, 2024
* (Doc+) Alerts UI cannot be CCS

👋 howdy, team!

Playing forward a couple ballpark Githubs (kindly see their sub-internal-links) #4653 , elastic/kibana#172534 , can we expand [this doc's](https://www.elastic.co/guide/en/security/master/data-views-in-sec.html#_create_or_modify_a_data_view) note to more heavily indicate even CCS is not possible on the Alerts UI?

* feedback

Co-authored-by: Joe Peeples <[email protected]>

---------

Co-authored-by: Joe Peeples <[email protected]>
(cherry picked from commit 5c199b0)

Co-authored-by: Stef Nestor <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request v8.12.0 v8.13.0
Projects
None yet
Development

No branches or pull requests

2 participants