Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security Solution] Add Alerts Details into Session Details View #126065

Closed
5 of 8 tasks
Tracked by #126054
qcorporation opened this issue Feb 21, 2022 · 0 comments
Closed
5 of 8 tasks
Tracked by #126054

[Security Solution] Add Alerts Details into Session Details View #126065

qcorporation opened this issue Feb 21, 2022 · 0 comments
Assignees
Labels
Feature: Session View Team: AWP: Platform Adaptive Workload Protection Platform team from Security Solution v8.2.0

Comments

@qcorporation
Copy link

qcorporation commented Feb 21, 2022

Background

The session details view will embed alerts within the entries. Alerts will be tagged with an "Alert" tag which can be expanded to display additional information.
Navigating from the alerts page by selecting an alert to investigate, the session details page must differentiate that Alert from the other alerts embedded within the view.

Alerts that have missing process entry information, e.g. a disjointed tree, should be labelled as missing context and hung from the session leader

Take Action button will allow the user to perform actions like creating a case, adding to an existing case, closing an alert, etc.

Tasks

  • Populate the session details view with all alerts within the session
  • Tag alerts within the view
  • Highlight the alert if the alert is selected for investigation, e.g. from the Alerts page
  • Show additional details via an expandable view when user clicks on the alerts tag
  • Give the ability to perform actions on the alert

Testing

  • The session viewer details loads all alerts from the Elasticsearch alert index for that session
  • Actions performed on that alert persist within the database and are automatically updated within Kibana
  • Alerts details show the exact information of that alert
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature: Session View Team: AWP: Platform Adaptive Workload Protection Platform team from Security Solution v8.2.0
Projects
None yet
Development

No branches or pull requests

2 participants