-
Notifications
You must be signed in to change notification settings - Fork 255
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Docs][SIEM]Threat hunting ehancements #1039
[Docs][SIEM]Threat hunting ehancements #1039
Conversation
docs/en/siem/siem-ui.asciidoc
Outdated
@@ -8,7 +8,31 @@ environment, and you can use the interactive UI to drill down into areas of | |||
interest. | |||
|
|||
The *{kibana-ref}/kuery-query.html[{kib} Query Language (KQL)]* bar is available | |||
throughout the {siem-app} for searching and filtering. | |||
throughout the {siem-app} for searching and filtering. You can also click and | |||
swipe histograms, which updates the global time filter. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You can also click and swipe histograms, which updates the global time filter.
Would you be willing to consider describing this behavior ("brush selection" is the obscure technical term for it), like the following suggestion?
When histograms contain peaks or a time range containing interesting data, click on the chart, and while holding down the mouse or trackpad button, drag over the time range to select it, which updates the global time filter.
Consider including a still screenshot like the one above to illustrate the selection process.
Do we support animated gifs in docs? If so, perhaps we could include something like the following?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated the text to describe what to do instead of how to do it, and the screenshot. I think it's ok now.
Technically, we can add gif animations. I need to check with other writers if it's ok to do so. Personally, I find them a bit distracting in docs.
docs/en/siem/siem-ui.asciidoc
Outdated
image::images/siem-click-swipe.png[] | ||
|
||
TIP: All {siem-soln} histograms and graphs contain an **Inspect** button, so | ||
you can examine data sources throughout the app. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
so you can examine data sources throughout the app.
Consider replacing "data sources" with "queries", e.g.:
so you can view the Elasticsearch queries that provide data for graphs throughout the app.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for documenting these enhancements @benskelker!
LGTM 🚀
* threat hunting ehancements * fixes typo * minor edits * corrections
* threat hunting ehancements * fixes typo * minor edits * corrections
Documents threat hunting UI interactions.
Preview
Resolves: #1026