-
Notifications
You must be signed in to change notification settings - Fork 191
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Documents how to change the default security index #4695
Conversation
A documentation preview will be available soon.
Request a new doc build by commenting
If your PR continues to fail for an unknown reason, the doc build pipeline may be broken. Elastic employees can check the pipeline status here. |
@benironside sorry, I did not really clarify well what docs we want to add. I updated the original ticket and added UPDATED section there:
Let me know if you have questions about it. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for putting this together!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks great! Thanks, @benironside!
|
||
image::images/dataview-filter-example.gif[video showing how to filter the active data view] | ||
|
||
This only allows you to add index patterns that match indices that currently contain data (other index patterns are unavailable). Note that any changes made are saved in the current browser window and won't persist if you open a new tab. | ||
|
||
To permanently modify a {data-source}, delete an existing {data-source} or create a new one, you need the required permissions. | ||
To learn more, refer to {apm-app-ref}/data-views.html[{kib} {data-sources-cap}]. | ||
NOTE: You cannot update the data view for the Alerts page. It always shows data from `.alerts-security.alerts-default`. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@e40pud can we tweak the UI copy so it aligns with this note? The current copy could be interpreted as: you must go elsewhere to update the data view for the Alerts page.
If it's still possible to change the copy, I'd suggest this:
You can't modify the data view for the Alerts page.
If that version is too blunt and overly formal, here's a slightly softer version:
This page's data view can't be adjusted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is not bound to Alerts page only. Same happens on rule details page. Also, there is another similar message that we show on the timeline. So, general message looks better to me.
Screen.Recording.2024-01-31.at.16.47.22.mov
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah, interesting. Thanks for pointing out these other areas @e40pud -- I wasn't aware of them. Would it be ok if we continued this conversation in https://github.com/elastic/security-docs/issues/4718 so that we're not blocking this doc issue from being closed and merged?
Co-authored-by: Nastasha Solomon <[email protected]>
Co-authored-by: Nastasha Solomon <[email protected]>
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8)
* First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4731) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4726) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
…4695) (#4721) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4730) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4729) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4722) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4728) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4727) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4725) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4724) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4723) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit 225f3c8) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
Serverless follow up to #4695
* Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx
* Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx
…kport #5582) (#5586) * (Doc+) Alerts UI cannot be CCS [serverless] + bonus fixes (#5582) * Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx * Delete docs/serverless directory and its contents --------- Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…kport #5582) (#5585) * (Doc+) Alerts UI cannot be CCS [serverless] + bonus fixes (#5582) * Add admonition to serverless Serverless follow up to #5513 * Update serverless to match ESS Serverless follow up to #4695 * Fix URL variable/attribute Should use `kibana-ref` instead of apm-app-ref since this has nothing to do with APM * No-op change to trigger build (i hope) (cherry picked from commit 9e7d734) # Conflicts: # docs/serverless/explore/data-views-in-sec.mdx * Delete docs/serverless directory and its contents --------- Co-authored-by: Joe Peeples <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
) (#4729) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4727) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
) (#4730) * Documents how to change the default security index (#4695) * First draft * incorporates feedback * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> * Update docs/getting-started/data-views-in-sec.asciidoc Co-authored-by: Nastasha Solomon <[email protected]> --------- Co-authored-by: Nastasha Solomon <[email protected]> (cherry picked from commit eb7373e) # Conflicts: # docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc * Update docs/getting-started/data-views-in-sec.asciidoc --------- Co-authored-by: Benjamin Ironside Goldstein <[email protected]>
First pass at fixing #4653.
@e40pud please let me know what you think, if we should add any more info and if this addresses the need. Thanks!