UX Debt: Alert Histogram #82570
Labels
Feature:Detection Rules
Security Solution rules and Detection Engine
impact:medium
Addressing this issue will have a medium level of impact on the quality/strength of our product.
needs design
Team:Detections and Resp
Security Detection Response Team
Team: SecuritySolution
Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc.
UX Debt
UX Debt from #55753
It looks like the signals histogram currently displays each individual risk score in the legend. The original wireframes showed the risk scores grouped in ranges, attributed to a keyword. With the discussions we had regarding severity versus risk score, it probably no longer makes sense to attribute them to a keyword, but I think the grouping of risk score ranges still makes sense (and can potentially be easier to understand for situations with lots of signals). In short, could we use the following ranges? Applies to rule details page as well. (Needs disscussion)
0–24
25–49
50–74
75–100
For most cases, a random selection of EUI visualization colors is probably fine. However, in certain specific circumstances (such as signal.rule.risk_score and signal.rule.severity), it would make sense to use visualization colors that represent a positive-to-negative spectrum. For example, my original wireframes are using green ($euiColorVis0), yellow ($euiColorVis5), orange ($euiColorVis7) and red ($euiColorVis9). Would that be possible to do for these two stack dimensions?
The text was updated successfully, but these errors were encountered: