Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[DOCS] Add session ID to highlighted fields section in alert details flyout #2067

Merged
merged 22 commits into from
Jun 24, 2022
Merged
Changes from 11 commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
9f1f8e8
First draft
nastasha-solomon Jun 13, 2022
6a7931b
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 13, 2022
fdd0dc0
Added image
nastasha-solomon Jun 16, 2022
4ee35cc
Update docs/detections/alerts-ui-manage.asciidoc
nastasha-solomon Jun 18, 2022
95aef06
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 18, 2022
0cc15dd
Update docs/detections/alerts-ui-manage.asciidoc
nastasha-solomon Jun 20, 2022
ea72b51
Re-took alert-details-flyout.png
nastasha-solomon Jun 21, 2022
f2ca2e7
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 22, 2022
730513a
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 22, 2022
caffcdb
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 22, 2022
0075039
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 22, 2022
a0cc2a5
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 22, 2022
716c8b3
Michael's suggestion
nastasha-solomon Jun 22, 2022
3b4b52c
One more edit from Michael
nastasha-solomon Jun 22, 2022
d305fd0
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 23, 2022
6868fc0
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 23, 2022
af23435
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 23, 2022
cdc1c6b
Typos
nastasha-solomon Jun 23, 2022
c9d852a
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 24, 2022
3130208
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 24, 2022
b0c330f
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 24, 2022
be32491
Merge branch 'main' into issue-2066-session-id
nastasha-solomon Jun 24, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/detections/alerts-ui-manage.asciidoc
Original file line number Diff line number Diff line change
@@ -109,6 +109,8 @@ The alert details flyout also lists the number and names of cases to which the a

The *Highlighted Fields* section displays the most relevant fields for the alert type. Use this section to inform your triage efforts as you investigate the alert.

NOTE: The *Session ID* field provides a unique ID for Linux sessions. To collect it and other session data, you must enable the *Include session data* setting on your {endpoint-cloud-sec} integration policy. Refer to <<enable-session-view, Enable Session View data>> for more information.
nastasha-solomon marked this conversation as resolved.
Show resolved Hide resolved

The *Alert prevalence* column shows the total number of alerts within the selected timeframe that have identical values. For example, an alert with an alert prevalence of 3 for the `host.name` field means three alerts with the same `host.name` value exist within the given timeframe. Alert prevalence data can help you investigate relationships with other alerts and gain more context about the event producing the alert.
janmonschke marked this conversation as resolved.
Show resolved Hide resolved

The *Enriched data* section displays available threat indicator matches and threat intelligence data. Click the info icon to learn more about what data is collected.
Binary file modified docs/detections/images/alert-details-flyout.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.